Hackers are exploiting vulnerabilities in the XWiki template system to deploy unauthorized Monero (XMR) mining software on compromised computers. Using scripts like x640, x521, and x522, they install and run the mining program (tcrond) through c3pool.org, while disabling other mining software on the affected machines. A similar vulnerability has been identified in DELMIA Apriso, allowing remote code execution. To combat cryptojacking, users are advised to block related IP addresses, monitor network connections to c3pool.org, and remove any detected mining files.