Key Takeaways
  • Cryptojacking lets attackers mine cryptocurrency using someone else’s devices, cloud instances, or servers.
  • Common cryptojacking paths include browser-based JavaScript mining, fake installers or malware droppers, exploitation of exposed servers and containers, compromised cloud credentials, supply-chain compromise, and botnet-driven mining.
  • Cryptojacking can be the attacker’s monetization goal itself, but in enterprise environments it should also be treated as evidence of compromise. The same access used to deploy a miner can be reused for ransomware, data theft, or lateral movement.
  • Group-IB Threat Intelligence Platform and Incident Response services help organizations detect mining infrastructure early and recover quickly when an incident occurs.

What Is Cryptojacking?

Cryptojacking occurs when attackers steal a victim’s device computing resources to mine cryptocurrency. Attackers use that power without incurring any associated costs. Victims are unknowingly tricked into spending their own resources without reaping any of the rewards. 

Cryptojacking has become a stealthy, lucrative form of cybercrime, allowing attackers to infiltrate thousands of devices at once. This under-the-radar operation generates a steady income stream with minimal risk. Unlike cyberthreats that steal data or demand ransoms, cryptojacking costs you through sluggish performance and higher electricity bills.

No alerts or ransom notes indicate something’s amiss. Instead, cryptomining malware cunningly embeds itself in your devices, evading detection as it mines cryptocurrency in the background. Often, the first hint of trouble comes when you notice your device lagging or your cloud bill rising unexpectedly. By then, the cryptomining operation may have been running for weeks. 

Cryptojacking vs. Legitimate Crypto Mining

The difference between cryptojacking and legitimate crypto mining comes down to consent. Legitimate mining runs on hardware the miner owns or has explicit permission to use, and it’s disclosed openly to anyone affected. Cryptojacking uses someone else’s computing power without their knowledge, and the proceeds go entirely to the attacker.

Legitimate mining Cryptojacking
Consent The miner owns the hardware or has explicit permission to use it. Runs without the device or account owner’s knowledge.
Disclosure Openly declared, often stated in terms of service or on-page notices. Hidden from the victim, typically using evasion techniques to avoid detection.
Who bears the cost The miner, who also keeps the proceeds. The victim, who covers the electricity or compute cost and sees none of the proceeds.
Legal status Legal in most jurisdictions when consent is given. Most jurisdictions treat it as unauthorized computer use, theft, or services.

Coinhive itself illustrates this line. It launched as a legitimate opt-in tool for site owners, and it became a cryptojacking vector only when attackers deployed the same script on compromised sites without visitor consent.

How Does a Cryptojacking Attack Work?

A cryptojacking attack works in three stages. 

  1. Gaining access. Attackers gain access, deploy the miner, and collect the proceeds. Access starts with a foothold through a malicious script, a dropper, or a compromised cloud credential. 
  2. Deploying the miner. They install mining software, such as XMRig, configured to mine cryptocurrencies like Monero. 
  3. Collecting the proceeds. The miner then runs in the background, consuming processing power around the clock, and sending the mined coins directly to the attacker’s wallet. 

This exact pattern shows up regularly in cloud-focused cryptojacking campaigns. Financially motivated groups use stolen credentials to access victim cloud accounts, escalate privileges to add attacker-controlled billing contacts, then spin up large compute resources to mine cryptocurrency through third-party mining pools

Signs of a Cryptojacking Attack

The clearest signs of a cryptojacking attack show up in performance and cost, not in a security alert. Common warning signs include the following.

  • Consistently high CPU or GPU usage even when the device is idle.
  • Overheating, unusual fan noise, or shortened battery life on laptops and phones.
  • Noticeably slower application performance across the board.
  • Unexplained spikes in cloud compute or electricity bills.
  • Unfamiliar processes or scheduled tasks running in the background.

Common Types of Cryptojacking

Cryptojacking splits into three types based on where the mining code executes. Browser-based mining runs inside a web page and requires no installation on the victim’s machine. 

Host-based mining writes a file to disk, so it survives reboots and keeps earning for the attacker around the clock. Memory-resident mining is the hardest to catch, since it loads into RAM and leaves no file for antivirus to scan. Where the code runs decides how long the mining lasts and which security tool has any chance of seeing it.

Browser-based cryptojacking

Browser-based cryptojacking runs a mining script inside an open browser tab and stops as soon as the tab closes. Attackers inject malicious JavaScript into compromised or malicious websites, and the script quietly uses the visitor’s CPU to mine cryptocurrency for as long as the page stays open.

This technique became widely known through Coinhive, a JavaScript miner launched in 2017 that site owners could embed as an alternative to ad revenue. Attackers quickly abused the same script on compromised sites without visitors’ knowledge or consent, and the service shut down in 2019 once abuse outpaced legitimate use.

Host-based cryptojacking

Group-IB analysts traced a host-based cryptojacking campaign to a popular online thesaurus with more than five million monthly visits. A hidden script served a fake browser update page, tricking visitors into downloading an archive disguised as a Chrome patch. 

The archive installed the XMRig miner, configured to mine Monero while evading antivirus detection. Group-IB Managed XDR Platform flagged the unusual archive naming pattern across customer environments, traced the infection to the thesaurus site, and confirmed the malicious script was removed.

Memory-resident cryptojacking

Memory-resident cryptojacking loads the miner into RAM and never writes it to disk, so file-based antivirus has nothing to scan. Group-IB’s investigation into a 2026 Monero cryptomining campaign, XMRig Covert Ops, found a customized XMRig implant that runs entirely in memory to evade file-based detection. 

The threat actor abused Linux authentication controls to move between low-privileged accounts undetected, spreading persistence across a large pool of compromised endpoints tracked under a single campaign identifier. 

Group-IB traced the implant to a specific campaign family and published indicators of compromise, including the malicious mining pool domain and file hashes, giving organizations a direct way to detect and block the activity.

Where Cryptojacking Shows Up in Enterprise Environments

Cryptojacking shows up wherever compute is cheap for the attacker and the defender isn’t watching closely. Cloud workloads and internal servers both qualify, and the location changes what an infection actually means. 

A miner on a laptop costs electricity. A miner on an internal production server means someone already got inside.

Cloud workloads and containers

Cloud cryptojacking targets virtual machines, containers, and Kubernetes clusters because cloud compute scales mining output at no hardware cost to the attacker. 

The Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in the Kestra workflow engine to its Known Exploited Vulnerabilities catalog after confirming attackers used it to gain Docker container access and deploy a cryptocurrency miner as one of four impact paths from a single exploited flaw. 

Cryptojacking is also a possible outcome of broader cloud jacking, where an attacker hijacks cloud accounts or infrastructure outright.

Servers and endpoints

Server and endpoint cryptojacking happens after an attacker has already gained a foothold inside a network. Miners are deployed across multiple machines to maximize output, often alongside other post-compromise activities like lateral movement. 

This form spreads internally, so it requires the same detection depth as any internal threat, not just endpoint antivirus checks.

Common Cryptojacking Techniques

Common cryptojacking techniques include malicious JavaScript mining, exploiting vulnerable systems, compromised credentials, supply chain compromise, and botnet-driven mining. Recognizing these techniques helps security teams close the specific gaps attackers exploit most often. 

Technique How it works
Malicious JavaScript mining A mining script is injected into a webpage’s code through a compromised plugin or ad network and runs automatically as long as the tab stays open.
Exploiting vulnerable systems Attackers scan for unpatched software, misconfigured servers, or open ports and deploy a miner before defenders find the gap.
Compromised credentials and accounts Weak or reused passwords on SSH and RDP services let attackers log in as a legitimate user and deploy a miner without tripping alerts.
Supply chain and third-party compromise A miner is delivered through a trusted dependency, plugin, or vendor package, bypassing the scrutiny applied to direct downloads.
Botnets for cryptocurrency mining Large numbers of compromised devices are coordinated into a distributed mining operation, multiplying output without targeting any single high-value system.

How to Detect and Prevent Cryptojacking

Detecting and preventing cryptojacking starts with visibility across devices, networks, and cloud environments, and closing access points since attackers count on activity going unnoticed for as long as possible.

Monitor system and network activity

  • Track CPU, GPU, and memory usage against a normal baseline. Built-in tools like Task Manager or cloud monitoring dashboards can surface sustained spikes without additional investment.
  • Analyze network traffic for outbound connections to known mining pools or unusual ports. Miners must report back to a pool or wallet address, creating a detectable footprint even when the process itself is hidden.
  • Watch for unsigned binaries or disguised process names, like the “chromium-patch-nightly” naming pattern Group-IB analysts uncovered during the thesaurus campaign. This kind of structured investigation is central to Threat Hunting, where analysts proactively search for indicators that automated tools miss.

A miner running on an internal server is itself a sign of compromise, not just a resource drain, since it means an attacker already has a foothold inside the network.  A Compromise Assessment can uncover this kind of hidden, longer-running activity that routine monitoring alone may miss.

Monitor cloud environments for cryptojacking activity

  • Cloud cryptojacking often shows up in billing and usage data rather than a security alert, so cloud-specific monitoring needs to look in different places than an on-premises detection stack. 
  • Watch for unexpected spikes in compute or storage billing, new virtual machines or containers spun up outside normal provisioning workflows, and unusual API calls tied to compute-scaling actions, especially from service accounts that don’t normally trigger them. 
  • Cloud providers typically offer usage and billing alerts that can help flag this kind of abnormal consumption early.

But usage monitoring alone catches a miner only after it’s already running, so closing the misconfigurations that let attackers in reduces how often it happens in the first place. Cloud Security Posture Management continuously audits cloud environments for exposed permissions and misconfigurations that cryptojacking campaigns typically exploit to gain access.

Use threat intelligence to identify mining infrastructure

Tracking known mining-pool addresses, wallet activity, and attacker infrastructure before a miner ever reaches your environment. Group-IB Threat Intelligence Platform monitors this infrastructure continuously, giving security teams early warning of the tools and addresses attackers are actively using.

Close common access points

  • Keep operating systems and software updated to remove the vulnerabilities attackers constantly scan for.
  • Secure credentials and privileged accounts with multi-factor authentication and regular rotation, since logging in as a legitimate user remains one of the most common ways cryptojacking campaigns begin.
  • Implement endpoint and network security controls, including browser script-blocking and endpoint detection tools, to catch miners at the point of execution.

Train employees to recognize security threats

Training employees to recognize security threats reduces the odds that a phishing email or malicious download becomes a miner’s entry point. Regular Penetration Testing that simulates real social engineering attempts helps organizations find these gaps before an attacker does.

What to Do After Detecting Cryptojacking

If you’ve detected a cryptojacking attack, prioritize containment before cleanup. Isolate the affected device or cloud instance, terminate the mining process, and rotate any exposed credentials. Then check for secondary payloads. 

Group-IB’s investigation into the thesaurus campaign found that cryptojacking loaders can double as a foothold for more damaging malware, including ransomware or wipers. Patch the entry vector and review logs for lateral movement. 

For incidents beyond in-house capacity, Group-IB Incident Response services provide 24/7 support to contain threats, investigate root cause, and restore operations.

How Group-IB Stops Cryptojacking Attacks

Group-IB helps organizations detect and prevent cryptojacking at each point where the attack can be interrupted, from the exposed asset used for entry to the persistence mechanism left behind after the miner is removed. The capabilities below follow that sequence. 

  • Block known mining infrastructure before it connects. Threat Intelligence tracks the infrastructure behind active campaigns, including the domains and command servers miners connect to, and pushes those indicators into SIEM and firewall tooling, and alerts on compromised credentials and initial access broker listings before an attacker can use them.

The platform also monitors dark web sources for compromised credentials and initial access broker listings. This matters for cryptojacking because brokers frequently sell the same foothold to a miner operator first and a ransomware affiliate later. 

  • Detect mining behavior across the whole environment. Managed XDR correlates endpoint and network telemetry with cloud events, flags miner process behavior without relying on signatures, and detects outbound mining pool traffic hidden behind DNS tunneling or encryption. When a suspicious archive or link appears, the built-i Malware Detonation Platform runs it in an isolated environment that mirrors the target system, extracts fresh indicators, and feeds them back into detection.
  • Find miners running unnoticed. Compromise Assessment hunts for miners that throttled below alert thresholds, persistence left after partial cleanup, and access an operator may have already resold. It also surfaces access paths an operator may have already resold. 

Digital forensics and incident response specialists run the assessment, and the output is a list of confirmed compromises with the entry vector for each, which the response section above depends on.

  • Contain and recover when an incident is confirmed. Group-IB Incident Response provides 24/7 support to contain the miner, remove persistence, identify the entry point, and check for secondary payloads.

Find out whether a miner is already running. Talk to Group-IB experts to strengthen cryptojacking protection across cloud and on-premises infrastructure.

FAQs

How do I know if my device has been cryptojacked?

arrow_drop_down

To know if your device has been cryptojacked, look for consistently high CPU or GPU usage, overheating, or a noticeable slowdown even when you are not running demanding applications. A recommended first step is to check Task Manager or Activity Monitor for unfamiliar processes. 

 

Can cryptojacking affect cloud servers?

arrow_drop_down

Yes, cryptojacking can affect cloud servers. Cloud cryptojacking is one of the most common forms of the attack because compromised cloud instances give attackers scalable compute power without the hardware cost.

 

How can organizations detect cryptojacking activity?

arrow_drop_down

Organizations can detect cryptojacking activity by monitoring resource usage, analyzing network traffic for mining-pool connections, and using threat intelligence to track known mining infrastructure before it reaches their environment.

 

What are the most common cryptocurrencies mined through cryptojacking?

arrow_drop_down

Common cryptocurrencies mined through cryptojacking are privacy coins, such as Monero. Monero is a common choice because its privacy features hide wallet and transaction details, making stolen proceeds harder to trace back to the attacker.

 

Does cryptojacking slow down a computer?

arrow_drop_down

Yes, cryptojackingslows a computer down. Mining is resource-intensive, so a cryptojacked device typically runs slower, overheats more easily, and drains the battery faster than usual.

 

Can cryptojacking damage hardware?

arrow_drop_down

Yes, cryptojacking can damage hardware. Sustained high CPU and GPU usage generates excess heat, which can shorten hardware lifespan over time, particularly on devices with poor cooling. But it rarely causes immediate physical damage on its own.

 

How does cryptojacking affect business operations and costs?

arrow_drop_down

Cryptojacking affects business operations and costs by driving up cloud compute costs, slowing internal systems, and serving as a stepping stone for more damaging attacks like ransomware, making early detection a direct cost-saving measure.

Group-IB: Fight
against cybercrime