| Key Takeaways |
|
|
|
|
What Is Cryptojacking?
Cryptojacking occurs when attackers steal a victim’s device computing resources to mine cryptocurrency. Attackers use that power without incurring any associated costs. Victims are unknowingly tricked into spending their own resources without reaping any of the rewards.
Cryptojacking has become a stealthy, lucrative form of cybercrime, allowing attackers to infiltrate thousands of devices at once. This under-the-radar operation generates a steady income stream with minimal risk. Unlike cyberthreats that steal data or demand ransoms, cryptojacking costs you through sluggish performance and higher electricity bills.
No alerts or ransom notes indicate something’s amiss. Instead, cryptomining malware cunningly embeds itself in your devices, evading detection as it mines cryptocurrency in the background. Often, the first hint of trouble comes when you notice your device lagging or your cloud bill rising unexpectedly. By then, the cryptomining operation may have been running for weeks.
Cryptojacking vs. Legitimate Crypto Mining
The difference between cryptojacking and legitimate crypto mining comes down to consent. Legitimate mining runs on hardware the miner owns or has explicit permission to use, and it’s disclosed openly to anyone affected. Cryptojacking uses someone else’s computing power without their knowledge, and the proceeds go entirely to the attacker.
| Legitimate mining | Cryptojacking | |
| Consent | The miner owns the hardware or has explicit permission to use it. | Runs without the device or account owner’s knowledge. |
| Disclosure | Openly declared, often stated in terms of service or on-page notices. | Hidden from the victim, typically using evasion techniques to avoid detection. |
| Who bears the cost | The miner, who also keeps the proceeds. | The victim, who covers the electricity or compute cost and sees none of the proceeds. |
| Legal status | Legal in most jurisdictions when consent is given. | Most jurisdictions treat it as unauthorized computer use, theft, or services. |
Coinhive itself illustrates this line. It launched as a legitimate opt-in tool for site owners, and it became a cryptojacking vector only when attackers deployed the same script on compromised sites without visitor consent.
How Does a Cryptojacking Attack Work?
A cryptojacking attack works in three stages.
- Gaining access. Attackers gain access, deploy the miner, and collect the proceeds. Access starts with a foothold through a malicious script, a dropper, or a compromised cloud credential.
- Deploying the miner. They install mining software, such as XMRig, configured to mine cryptocurrencies like Monero.
- Collecting the proceeds. The miner then runs in the background, consuming processing power around the clock, and sending the mined coins directly to the attacker’s wallet.
This exact pattern shows up regularly in cloud-focused cryptojacking campaigns. Financially motivated groups use stolen credentials to access victim cloud accounts, escalate privileges to add attacker-controlled billing contacts, then spin up large compute resources to mine cryptocurrency through third-party mining pools
Signs of a Cryptojacking Attack
The clearest signs of a cryptojacking attack show up in performance and cost, not in a security alert. Common warning signs include the following.
- Consistently high CPU or GPU usage even when the device is idle.
- Overheating, unusual fan noise, or shortened battery life on laptops and phones.
- Noticeably slower application performance across the board.
- Unexplained spikes in cloud compute or electricity bills.
- Unfamiliar processes or scheduled tasks running in the background.
Common Types of Cryptojacking
Cryptojacking splits into three types based on where the mining code executes. Browser-based mining runs inside a web page and requires no installation on the victim’s machine.
Host-based mining writes a file to disk, so it survives reboots and keeps earning for the attacker around the clock. Memory-resident mining is the hardest to catch, since it loads into RAM and leaves no file for antivirus to scan. Where the code runs decides how long the mining lasts and which security tool has any chance of seeing it.
Browser-based cryptojacking
Browser-based cryptojacking runs a mining script inside an open browser tab and stops as soon as the tab closes. Attackers inject malicious JavaScript into compromised or malicious websites, and the script quietly uses the visitor’s CPU to mine cryptocurrency for as long as the page stays open.
This technique became widely known through Coinhive, a JavaScript miner launched in 2017 that site owners could embed as an alternative to ad revenue. Attackers quickly abused the same script on compromised sites without visitors’ knowledge or consent, and the service shut down in 2019 once abuse outpaced legitimate use.
Host-based cryptojacking
Group-IB analysts traced a host-based cryptojacking campaign to a popular online thesaurus with more than five million monthly visits. A hidden script served a fake browser update page, tricking visitors into downloading an archive disguised as a Chrome patch.
The archive installed the XMRig miner, configured to mine Monero while evading antivirus detection. Group-IB Managed XDR Platform flagged the unusual archive naming pattern across customer environments, traced the infection to the thesaurus site, and confirmed the malicious script was removed.
Memory-resident cryptojacking
Memory-resident cryptojacking loads the miner into RAM and never writes it to disk, so file-based antivirus has nothing to scan. Group-IB’s investigation into a 2026 Monero cryptomining campaign, XMRig Covert Ops, found a customized XMRig implant that runs entirely in memory to evade file-based detection.
The threat actor abused Linux authentication controls to move between low-privileged accounts undetected, spreading persistence across a large pool of compromised endpoints tracked under a single campaign identifier.
Group-IB traced the implant to a specific campaign family and published indicators of compromise, including the malicious mining pool domain and file hashes, giving organizations a direct way to detect and block the activity.
Where Cryptojacking Shows Up in Enterprise Environments
Cryptojacking shows up wherever compute is cheap for the attacker and the defender isn’t watching closely. Cloud workloads and internal servers both qualify, and the location changes what an infection actually means.
A miner on a laptop costs electricity. A miner on an internal production server means someone already got inside.
Cloud workloads and containers
Cloud cryptojacking targets virtual machines, containers, and Kubernetes clusters because cloud compute scales mining output at no hardware cost to the attacker.
The Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in the Kestra workflow engine to its Known Exploited Vulnerabilities catalog after confirming attackers used it to gain Docker container access and deploy a cryptocurrency miner as one of four impact paths from a single exploited flaw.
Cryptojacking is also a possible outcome of broader cloud jacking, where an attacker hijacks cloud accounts or infrastructure outright.
Servers and endpoints
Server and endpoint cryptojacking happens after an attacker has already gained a foothold inside a network. Miners are deployed across multiple machines to maximize output, often alongside other post-compromise activities like lateral movement.
This form spreads internally, so it requires the same detection depth as any internal threat, not just endpoint antivirus checks.
Common Cryptojacking Techniques
Common cryptojacking techniques include malicious JavaScript mining, exploiting vulnerable systems, compromised credentials, supply chain compromise, and botnet-driven mining. Recognizing these techniques helps security teams close the specific gaps attackers exploit most often.
| Technique | How it works |
| Malicious JavaScript mining | A mining script is injected into a webpage’s code through a compromised plugin or ad network and runs automatically as long as the tab stays open. |
| Exploiting vulnerable systems | Attackers scan for unpatched software, misconfigured servers, or open ports and deploy a miner before defenders find the gap. |
| Compromised credentials and accounts | Weak or reused passwords on SSH and RDP services let attackers log in as a legitimate user and deploy a miner without tripping alerts. |
| Supply chain and third-party compromise | A miner is delivered through a trusted dependency, plugin, or vendor package, bypassing the scrutiny applied to direct downloads. |
| Botnets for cryptocurrency mining | Large numbers of compromised devices are coordinated into a distributed mining operation, multiplying output without targeting any single high-value system. |
How to Detect and Prevent Cryptojacking
Detecting and preventing cryptojacking starts with visibility across devices, networks, and cloud environments, and closing access points since attackers count on activity going unnoticed for as long as possible.
Monitor system and network activity
- Track CPU, GPU, and memory usage against a normal baseline. Built-in tools like Task Manager or cloud monitoring dashboards can surface sustained spikes without additional investment.
- Analyze network traffic for outbound connections to known mining pools or unusual ports. Miners must report back to a pool or wallet address, creating a detectable footprint even when the process itself is hidden.
- Watch for unsigned binaries or disguised process names, like the “chromium-patch-nightly” naming pattern Group-IB analysts uncovered during the thesaurus campaign. This kind of structured investigation is central to Threat Hunting, where analysts proactively search for indicators that automated tools miss.
A miner running on an internal server is itself a sign of compromise, not just a resource drain, since it means an attacker already has a foothold inside the network. A Compromise Assessment can uncover this kind of hidden, longer-running activity that routine monitoring alone may miss.
Monitor cloud environments for cryptojacking activity
- Cloud cryptojacking often shows up in billing and usage data rather than a security alert, so cloud-specific monitoring needs to look in different places than an on-premises detection stack.
- Watch for unexpected spikes in compute or storage billing, new virtual machines or containers spun up outside normal provisioning workflows, and unusual API calls tied to compute-scaling actions, especially from service accounts that don’t normally trigger them.
- Cloud providers typically offer usage and billing alerts that can help flag this kind of abnormal consumption early.
But usage monitoring alone catches a miner only after it’s already running, so closing the misconfigurations that let attackers in reduces how often it happens in the first place. Cloud Security Posture Management continuously audits cloud environments for exposed permissions and misconfigurations that cryptojacking campaigns typically exploit to gain access.
Use threat intelligence to identify mining infrastructure
Tracking known mining-pool addresses, wallet activity, and attacker infrastructure before a miner ever reaches your environment. Group-IB Threat Intelligence Platform monitors this infrastructure continuously, giving security teams early warning of the tools and addresses attackers are actively using.
Close common access points
- Keep operating systems and software updated to remove the vulnerabilities attackers constantly scan for.
- Secure credentials and privileged accounts with multi-factor authentication and regular rotation, since logging in as a legitimate user remains one of the most common ways cryptojacking campaigns begin.
- Implement endpoint and network security controls, including browser script-blocking and endpoint detection tools, to catch miners at the point of execution.
Train employees to recognize security threats
Training employees to recognize security threats reduces the odds that a phishing email or malicious download becomes a miner’s entry point. Regular Penetration Testing that simulates real social engineering attempts helps organizations find these gaps before an attacker does.
What to Do After Detecting Cryptojacking
If you’ve detected a cryptojacking attack, prioritize containment before cleanup. Isolate the affected device or cloud instance, terminate the mining process, and rotate any exposed credentials. Then check for secondary payloads.
Group-IB’s investigation into the thesaurus campaign found that cryptojacking loaders can double as a foothold for more damaging malware, including ransomware or wipers. Patch the entry vector and review logs for lateral movement.
For incidents beyond in-house capacity, Group-IB Incident Response services provide 24/7 support to contain threats, investigate root cause, and restore operations.
How Group-IB Stops Cryptojacking Attacks
Group-IB helps organizations detect and prevent cryptojacking at each point where the attack can be interrupted, from the exposed asset used for entry to the persistence mechanism left behind after the miner is removed. The capabilities below follow that sequence.
- Block known mining infrastructure before it connects. Threat Intelligence tracks the infrastructure behind active campaigns, including the domains and command servers miners connect to, and pushes those indicators into SIEM and firewall tooling, and alerts on compromised credentials and initial access broker listings before an attacker can use them.
The platform also monitors dark web sources for compromised credentials and initial access broker listings. This matters for cryptojacking because brokers frequently sell the same foothold to a miner operator first and a ransomware affiliate later.
- Detect mining behavior across the whole environment. Managed XDR correlates endpoint and network telemetry with cloud events, flags miner process behavior without relying on signatures, and detects outbound mining pool traffic hidden behind DNS tunneling or encryption. When a suspicious archive or link appears, the built-i Malware Detonation Platform runs it in an isolated environment that mirrors the target system, extracts fresh indicators, and feeds them back into detection.
- Find miners running unnoticed. Compromise Assessment hunts for miners that throttled below alert thresholds, persistence left after partial cleanup, and access an operator may have already resold. It also surfaces access paths an operator may have already resold.
Digital forensics and incident response specialists run the assessment, and the output is a list of confirmed compromises with the entry vector for each, which the response section above depends on.
- Contain and recover when an incident is confirmed. Group-IB Incident Response provides 24/7 support to contain the miner, remove persistence, identify the entry point, and check for secondary payloads.
Find out whether a miner is already running. Talk to Group-IB experts to strengthen cryptojacking protection across cloud and on-premises infrastructure.
