Home › Resources › Cryptominers
Cryptominers
Malicious software that hijacks a device's computing power to mine cryptocurrency for an attacker.
Executive Summary
A cryptominer is malware that secretly uses an infected device's processor or graphics hardware to mine cryptocurrency, sending the proceeds to an attacker. This theft of computing resources, often called cryptojacking, quietly runs in the background, driving up power costs, slowing systems, and wearing out hardware. Because it aims to stay hidden rather than destroy data, it can persist for a long time before anyone notices.
What It Is
Cryptomining is the legitimate process of validating cryptocurrency transactions and earning coins in return, and it consumes large amounts of computing power. A cryptominer, sometimes called a coin miner or cryptojacker, is unauthorized software that performs this work on someone else's hardware without permission so the attacker collects the reward while the victim pays the cost. It can arrive as a standalone program dropped onto a server or laptop, or as a browser-based script that runs while a victim visits a compromised or malicious web page. Unlike ransomware or a wiper, a cryptominer usually does not want to be seen. Its goal is simple, steady, long-term theft of processing capacity, so it often throttles itself to avoid drawing attention.
Why It Matters
Cryptojacking turns your infrastructure into a profit engine for an attacker. On a laptop it may only mean a hot, sluggish machine and a shorter battery life, but at scale the damage compounds. In a cloud environment an attacker who compromises credentials or exposed services can spin up expensive compute and leave the organization with a large, unexpected bill. On business servers and industrial systems, sustained maximum load causes overheating, premature hardware failure, and degraded performance for real workloads. Just as important, a cryptominer is a signal: if an attacker can plant one, they had enough access to plant something far worse. Treating a miner as merely a nuisance can mean ignoring a real breach.
How It Works
Attackers gain a foothold through familiar routes: phishing, exploiting an unpatched vulnerability, weak or stolen credentials, malicious software supply chains, or exposed cloud services and container platforms. Once inside, they install the mining payload and connect it to a mining pool, a shared service that coordinates the work and distributes rewards to the attacker's wallet. The miner then consumes processor and graphics resources to solve the computations that earn coins. To stay hidden, it may limit its resource use, pause when a user is active, disguise its process name, and establish persistence so it survives reboots. Browser-based cryptojacking is simpler and needs no installation: a script embedded in a page mines only while the tab is open, which is why closing the page usually stops it.
Architecture Diagram
Visual Workflow
Common Attacks
- Phishing emails that deliver a coin miner as an attachment or link
- Exploitation of unpatched servers and exposed cloud or container services
- Compromised credentials used to run mining on cloud infrastructure
- Malicious browser scripts that mine while a page is open (drive-by cryptojacking)
- Trojanized software, plugins, or supply-chain packages that bundle a miner
Common Mistakes
- Dismissing a miner as a harmless nuisance instead of investigating the breach behind it
- Leaving cloud services, dashboards, and container platforms exposed to the internet
- Ignoring billing anomalies and unexpected spikes in cloud compute costs
- Not monitoring processor and graphics usage or setting alerts for sustained load
- Removing the payload but never closing the vulnerability that let it in
Best Practices
- Patch promptly and reduce the attack surface of internet-facing systems
- Enforce multi-factor authentication and least-privilege access on cloud accounts
- Monitor resource usage and cloud spend, and alert on unusual sustained load
- Use endpoint detection and response to catch mining behavior and persistence
- Restrict which software can run with application allowlisting where practical
- Use browser protections or extensions that block known mining scripts
Quick Checklist
- Baselines for normal processor, graphics, and cloud usage established
- Alerts configured for sustained high load and cloud billing spikes
- Internet-facing services patched and unnecessary ones removed
- MFA and least privilege enforced on cloud and admin accounts
- EDR deployed and tuned to flag mining behavior
- Incident process treats a miner as a possible sign of deeper compromise
Recommended Tools
Detects mining processes, persistence, and related malicious behavior
Flags unexpected compute spend that can indicate cryptojacking
Spots traffic to known mining pools and unusual outbound connections
Finds the unpatched weaknesses attackers use to plant miners
Industry Standards
Describes the technique cryptominers use to steal compute
Incident handling guidance for responding to a miner infection
Baseline safeguards that reduce exposure to cryptomining
Career Relevance
Cryptomining shows up daily for SOC analysts triaging resource and billing alerts, incident responders confirming whether a miner masks a larger breach, and security engineers hardening cloud and endpoint environments. Malware analysts study miner families to build detections, and cloud and GRC professionals weigh the cost and risk implications, all part of the audience AI-Governance-Jobs.com serves.
Interview Questions
- What is cryptojacking, and how does it differ from ransomware in intent?
- What signals would make you suspect a device or cloud account is mining cryptocurrency?
- Why should a discovered cryptominer be treated as a potential sign of a larger compromise?
- How does browser-based cryptojacking work, and how do you stop it?
- What controls best reduce the risk of cryptomining in a cloud environment?
Related Certifications
Further Reading
Key Takeaways
- A cryptominer steals a device's computing power to mine cryptocurrency for an attacker.
- Cryptojacking favors stealth and persistence over visible damage, so it often runs unnoticed.
- The clearest signs are sustained high resource use, overheating, and unexpected cloud spend.
- A miner is frequently evidence of a deeper breach, not just a standalone nuisance.
- Patching, MFA, least privilege, and resource monitoring are the strongest defenses.
FAQ
Is cryptomining always malicious?
No. Cryptomining is a legitimate part of how many cryptocurrencies work. It becomes malicious, and is called cryptojacking, only when it runs on someone's device or account without permission so an attacker collects the reward.
How can I tell if my computer is cryptojacked?
Watch for consistently high processor or graphics usage, a hot and noisy machine, sluggish performance, and shorter battery life, especially when you are not running demanding programs. In the cloud, unexplained jumps in compute cost are a strong warning sign.
Does closing my browser stop cryptojacking?
For browser-based cryptojacking, usually yes, because the mining script only runs while the page is open. If a miner was installed on the device itself, closing the browser will not stop it and the software must be removed.
Related Careers
Related certifications
CompTIA Security+GIAC GREMISC2 Certified in Cybersecurity (CC)Current openings
Suggested learning path
- Ground the basics with CS-001 Cybersecurity
- Study this sheet: Cryptominers
- Go deeper: Cybersecurity
- Go deeper: Ransomware
- Validate it: work toward CompTIA Security+
- Find the role: browse current openings