Cryptojacking

Utilising a victims infrastructure to generate illicit crypto-funds

Introduction

Cryptocurrency has created a new opportunity for cybercriminals: instead of stealing cryptocurrency directly, attackers can steal something much more readily available — computing resources.

Cryptojacking is the unauthorised use of a computer, server, cloud environment or other device to perform cryptocurrency mining on behalf of an attacker.

The victim may never realise that their system has been compromised. There may be no obvious ransomware message, no stolen files and no visible malware. Instead, the attack quietly consumes CPU, GPU, electricity and network resources while generating cryptocurrency for the attacker.

What is Cryptojacking?

Cryptojacking occurs when an attacker compromises a device and uses its processing power to mine cryptocurrency without the owner’s knowledge or permission.

Cryptocurrency mining requires significant computational resources. Rather than purchasing their own hardware and paying the associated electricity and infrastructure costs, attackers can compromise thousands of systems and combine their processing power into a large mining operation.

A successful cryptojacking campaign can therefore turn victims’ computers into a distributed cryptocurrency-mining infrastructure.

The attack can target:

  • Desktop and laptop computers
  • Servers
  • Cloud infrastructure
  • Virtual machines
  • Containers
  • IoT devices
  • Network appliances
  • Mobile devices

How does cryptojacking work?

The basic attack follows a relatively simple process:

Compromise → Deploy Mining Software → Consume Resources → Mine Cryptocurrency → Send Rewards to Attacker

An attacker first needs access to the victim’s system. This can happen through a vulnerable application, stolen credentials, malicious software, phishing or an exposed cloud service.

Once access has been obtained, the attacker deploys cryptocurrency-mining software. The software then uses the victim’s CPU or GPU to perform the mathematical calculations required by the cryptocurrency mining process.

The resulting cryptocurrency is ultimately directed towards infrastructure or wallets controlled by the attacker.

The victim effectively provides the hardware, electricity and processing power, while the attacker receives the financial benefit.

How do attackers deploy cryptojacking malware?

Cryptojacking malware can be introduced through several different attack vectors.

Exploiting Vulnerable Systems

Attackers may exploit vulnerable internet-facing applications, operating systems or services to gain access to a machine.

Once compromised, mining software can be installed and configured to run automatically.

Compromised Credentials

Weak, reused or stolen credentials can provide attackers with access to servers, cloud platforms or administrative accounts.

This can be particularly dangerous in cloud environments, where compromised credentials may allow attackers to create or modify multiple computing resources.

Malicious Software

Mining software can be bundled with:

  • Trojans
  • Cracked software
  • Malicious downloads
  • Browser extensions
  • Untrusted applications

The victim may unknowingly install the miner themselves.

Container and Cloud Exploitation

Cloud environments are an attractive target because attackers can potentially abuse large amounts of computational capacity.

A compromised cloud account may allow an attacker to create virtual machines or containers specifically for cryptocurrency mining.

The resulting cloud bill may then be charged to the victim.

What does a cryptojacking attack look like?

Unlike many cyber attacks, cryptojacking may not immediately produce an obvious security alert. Instead, organisations may notice unusual system behaviour.

Common indicators include:

  • Unexpectedly high CPU or GPU utilisation
  • Servers running at consistently high utilisation
  • Increased electricity consumption
  • Unexplained cloud computing costs
  • Systems becoming unusually slow
  • Fans running continuously at high speed
  • Unexpected processes consuming significant resources
  • Unknown scheduled tasks or services
  • Unauthorised containers or virtual machines
  • Connections to known mining infrastructure

A particularly important warning sign is high resource utilisation that cannot be explained by legitimate business activity.

Cryptojacking in the Cloud

Cloud environments are particularly attractive to attackers because computing resources can be provisioned rapidly and at significant scale. An attacker who obtains cloud credentials may create additional virtual machines, containers or other resources and configure them to mine cryptocurrency.

This creates two costs for the victim:

  • Computational cost – The organisation’s infrastructure is being consumed by the attacker.
  • Financial cost – The organisation may receive a significantly increased cloud bill.

In a large-scale compromise, an attacker could potentially create many resources simultaneously, turning a stolen cloud account into a cryptocurrency-mining operation.

What is the impact of cryptojacking?

Cryptojacking is often described as a low-impact attack because it does not necessarily involve stealing or destroying data. However, the consequences can still be significant.

  • Performance Degradation – Mining consumes CPU and GPU resources, potentially reducing the performance of legitimate applications and services.
  • Increased Energy Consumption – Systems working continuously at high utilisation consume more electricity.
  • Increased Cloud Costs – Unauthorised cloud workloads can generate substantial additional infrastructure charges.
  • Hardware Wear – Continuous high utilisation can increase thermal stress and potentially reduce hardware lifespan.
  • Operational Disruption – Resources consumed by mining are resources unavailable to legitimate applications.
  • Security Risk – Most importantly, the presence of cryptojacking malware demonstrates that an attacker has already obtained some level of access to the environment.

The mining activity may therefore be a symptom of a wider compromise rather than the entire attack.

Cryptojacking and cryptomining malware

Cryptojacking should not be confused with legitimate cryptocurrency mining.

Legitimate mining is performed with the owner’s knowledge and authorisation. Cryptojacking is fundamentally different because the attacker uses someone else’s resources without permission.

The mining software may also contain additional malicious functionality, meaning that discovering a cryptocurrency miner should trigger an investigation into how it was installed and what other activity the attacker performed.

How can cryptojacking be detected?

Detection should focus on identifying unusual resource consumption and unexpected system activity.

Security teams should monitor:

  • CPU and GPU utilisation
  • Network connections
  • Running processes
  • Scheduled tasks
  • Services
  • Container deployments
  • Cloud resource creation
  • Cloud billing anomalies
  • Authentication activity
  • Endpoint security alerts

Network monitoring can also identify connections to known cryptocurrency-mining infrastructure or unusual persistent outbound connections.

In a cloud environment, unexpected creation of compute resources should be treated as a potentially significant security event.

How can cryptojacking be prevented?

Organisations can reduce the risk of cryptojacking through a combination of security controls.

  • Patch Vulnerable Systems – Regularly update operating systems, applications and internet-facing services.
  • Protect Credentials – Use strong authentication, MFA and appropriate access controls for administrative and cloud accounts.
  • Apply Least Privilege – Users and applications should only have the permissions they actually require.
  • Monitor Resource Usage – Unexpected CPU, GPU, memory or cloud-resource utilisation can provide an early warning.
  • Secure Cloud Environments – Monitor cloud accounts for unexpected virtual machines, containers, storage and other resources.
  • Use Endpoint Security – EDR and antivirus solutions can detect known mining malware and suspicious processes.
  • Monitor Network Traffic – Identify unusual connections to cryptocurrency-mining pools and related infrastructure.
  • Control Software Installation – Restrict the installation and execution of unauthorised software.

Conclusion

Cryptojacking demonstrates that attackers do not always need to steal data to make money. Instead, they can monetise access to an organisation’s infrastructure itself.

Cryptojacking is the unauthorised use of computing resources to mine cryptocurrency for an attacker.

  • A compromised server becomes a mining machine.
  • A compromised cloud account becomes a source of computing capacity.
  • A compromised laptop becomes another worker in a distributed mining operation.

The individual systems may only contribute a small amount of processing power, but when thousands of compromised systems are combined, the attacker can create a highly profitable operation.

If an attacker has installed a miner, investigate how they gained access in the first place – The cryptocurrency mining process may be only the visible part of a much larger compromise.