
A cryptominer (cryptojacker) uses victim’s compute resources (CPU, GPU) to mine cryptocurrency without consent. Unlike ransomware, the goal is stealthy, long-term resource theft rather than immediate disruption. Cloud cryptojacking can generate massive bills.
| Milestone | Year | Details |
|---|
| Bitcoin mining malware | 2011+ | Early CPU miners |
| Coinhive | 2017 | In-browser Monero miner; JavaScript |
| WannaMine | 2018 | Worm + miner; EternalBlue |
| Docker/K8s cryptojacking | 2018+ | Exposed APIs, misconfig |
| Cloud cryptojacking | 2019+ | AWS, GCP, Azure billing fraud |
| XMRig | 2017+ | Open-source Monero miner; abused |
| Type | Delivery | Target |
|---|
| Binary | Trojan, exploit | Endpoints, servers |
| Browser-based | Injected JS (Coinhive) | Website visitors |
| Container/Cloud | Exposed Docker/K8s API | Cloud instances |
| CI/CD | Compromised pipelines | Build runners |
| Supply Chain | npm/PyPI packages | Developers |
| Miner | Year | Coin | Notable |
|---|
| Coinhive | 2017 | XMR | In-browser JS; shut down 2019 |
| XMRig | 2017+ | XMR | Open source; widely abused |
| WannaMine | 2018 | XMR | Worm + miner; EternalBlue |
| Graboid | 2019 | XMR | Docker worm; API exposure |
| Kinsing | 2019+ | XMR | Container/cloud focus |
| TeamTNT | 2020+ | XMR | Cloud-focused group |
| Sysrv | 2021+ | XMR | K8s, Docker, SSH |
| Impact | Description |
|---|
| Compute Bill | $10K–$1M+/month on compromised cloud accounts |
| Performance | CPU throttling, application degradation |
| Security | Indicates broader compromise (creds, access) |
| Compliance | Unauthorised compute may violate contracts |
| Method | Indicators |
|---|
| CPU Monitoring | Sustained 80-100% CPU on idle systems |
| Network | Stratum protocol (port 3333, 4444, 5555, 7777) |
| Process | xmrig, cpuminer, minerd, random names |
| Container | Unknown images, privileged pods, hostPath mounts |
| Cloud Bills | Unexpected compute cost spikes |
| Memory Forensics | Volatility: hidden processes, injected code |
- ✅ Monitor CPU — Alert on sustained high usage
- ✅ Secure Docker/K8s APIs — Auth, TLS, no public exposure
- ✅ Image Scanning — Scan for miners in CI/CD
- ✅ Egress Filtering — Block stratum ports (3333, 4444, etc.)
- ✅ Runtime Security — Falco, Sysdig, Tetragon
- ✅ IAM Least Privilege — No admin keys in CI/CD
- ✅ CSPM — Cloud Security Posture Management
- ✅ Billing Alerts — Budget alerts on cloud spend
| Technique | ID | Description |
|---|
| Resource Hijacking | T1496 | Cryptomining |
| Container Administration | T1609 | Docker/K8s API abuse |
| Deploy Container | T1610 | Malicious containers |