Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Cryptojacking
Jun 25, 2026
5 Mins Read
Sep 13, 2026

What Is Cryptojacking?

Cryptojacking is the unauthorized use of a computer, server, cloud account, browser, mobile device, or other system to mine cryptocurrency. Attackers shift electricity, compute, and infrastructure costs to the victim while keeping the proceeds.

Cryptojacking may follow exploitation of an exposed service, stolen cloud credentials, a malicious container image, compromised software, or unwanted browser code. The miner is visible impact, but the access path may also support data theft, persistence, or other payloads.

Key Takeaways

  • Cryptojacking often signals a wider compromise, not only unauthorized resource use.
  • Cloud credentials, exposed orchestration services, vulnerable applications, and malicious images are common paths.
  • CPU or GPU spikes, new workloads, pool traffic, and unexpected spending are key signals.
  • Response must remove the miner, close initial access, rotate credentials, and check for other activity.
The main stages and decision points associated with cryptojacking.
The main stages and decision points associated with cryptojacking.

How Cryptojacking Works

Attackers deploy mining software configured with a wallet and mining pool. They may throttle consumption, pause during business hours, or disguise the process to avoid detection.

Cloud campaigns automate credential discovery and create virtual machines, containers, serverless tasks, or Kubernetes workloads. Browser mining consumes a visitor’s device while a page or extension is active.

Common Types and Techniques

  • Endpoint and server mining malware
  • Cloud and container resource hijacking
  • Browser or extension-based mining
  • Supply-chain and CI/CD cryptojacking

Security and Business Risks

  • Unexpected cloud, power, and cooling costs
  • Degraded production performance and shortened hardware life
  • Proof of unauthorized execution or administrative access
  • Potential data theft, backdoors, or additional payloads
Common cryptojacking risks paired with practical defensive controls.
Common cryptojacking risks paired with practical defensive controls.

Warning Signs and Detection

Monitor sustained CPU or GPU use, unfamiliar processes, new cloud instances, autoscaling, unusual container images, mining-pool traffic, and spending anomalies. Correlate resource use with identity and deployment activity.

Prevention and Response

Patch exposed services, enforce MFA and short-lived cloud credentials, restrict resource creation, scan images, protect build secrets, use quotas and budgets, and monitor unusual deployments. Investigate the initial access path, not only the miner.

How SOCRadar Can Help

SOCRadar combines external asset visibility, threat intelligence, Dark Web monitoring, vulnerability context, and indicator enrichment to help teams identify exposure and investigate activity connected to cryptojacking.

Explore SOCRadar Attack Surface Management or request a demo to strengthen threat-informed prevention and investigation.

Frequently Asked Questions

What Is Cryptojacking?

Cryptojacking is the unauthorized use of a computer, server, cloud account, browser, or mobile device to mine cryptocurrency. The attacker directs the victim’s electricity, compute capacity, and cloud spend toward their own wallet while keeping the proceeds. The miner is often just the visible part of a broader intrusion.

Why Do Attackers Deploy Miners Instead of Ransomware?

Mining monetizes access without interacting with the victim, sending extortion notes, or carrying ransomware-related overhead. Campaigns can run quietly at scale across many hosts or cloud accounts. In some incidents, a miner is also a foothold test, and the same access is later used for data theft or other payloads.

How Does Cryptojacking Reach Endpoints, Servers, and Cloud Environments?

Common paths include exploitation of exposed internet-facing services, stolen cloud credentials, malicious or trojanized container images, compromised software updates, and unwanted browser scripts or extensions. Once access is gained, attackers deploy mining software configured with their wallet and pool. The initial access path often matters more for response than the miner itself.

How Does Cloud Cryptojacking Work in Practice?

Attackers automate credential discovery and then create virtual machines, containers, serverless functions, or Kubernetes workloads for mining. They may throttle consumption, pause during business hours, or disguise process names to stay under monitoring thresholds. The clearest signal is frequently a sudden jump in cloud spending rather than an alert on any single host.

Does Cryptojacking Happen Through Web Browsers?

Yes. In-browser mining runs JavaScript while a visitor keeps a page open, and malicious or bundled extensions can mine continuously in the background. The site owner gains nothing, and the visitor pays with fan noise, battery drain, and slower performance. Blocking known mining domains and auditing browser extensions reduces this exposure.

What Are Reliable Warning Signs of Cryptojacking?

Useful indicators include:

  • Sustained CPU or GPU use without a matching business workload
  • New cloud instances, autoscaling changes, or unfamiliar container images
  • Long-lived encrypted connections or DNS lookups tied to mining pools
  • Cloud bills that grow faster than provisioning requests

Correlating resource signals with identity and deployment activity helps separate mining from legitimate heavy workloads.

Is Cryptojacking a Low-Severity Issue?

No. A miner proves that someone obtained unauthorized execution or administrative access to the host or account. Treating it as a nuisance risks missing persistence, stolen data, or a second payload left by the same actor. Severity should be driven by how access was gained, not by what the attacker chose to run.

What Should a Response to Cryptojacking Include?

Remove the miner, but also close the initial access path, rotate affected credentials and API keys, review active sessions and IAM permissions, and check for persistence or other payloads. In cloud incidents, examine billing records, deployment logs, and resource creation history to map everything the attacker started. Removing only the mining process leaves the underlying access intact.

Does Cryptojacking Damage Hardware or Production Performance?

Sustained mining raises power and cooling consumption, increases operating temperatures, accelerates component wear, and competes with legitimate workloads for capacity. On production servers this appears as latency, failed jobs, and shortened hardware lifespan. The financial impact is often largest in the cloud, where attacker-controlled workloads are billed directly to the victim.

How Can Organizations Prevent Cryptojacking?

Patch exposed services quickly, enforce phishing-resistant MFA and short-lived cloud credentials, restrict who can create compute resources, scan container images, protect build and CI/CD secrets, and apply quotas with budget alerts. Monitoring for unusual deployments catches activity that slips past individual controls. No single control closes every path, so layering identity, workload, and billing signals is what makes prevention durable.

How Can Teams Find Exposure Before Miners Deploy?

Close the entry points mining campaigns rely on. Continuously discovering internet-facing assets, exposed management services, and misconfigurations shrinks the attack paths used to deploy miners, and reviewing underground sources for leaked credentials tied to your domains helps catch stolen access before it is used. SOCRadar’s Attack Surface Management supports this kind of exposure tracking alongside vulnerability context for exposed services.