Cryptojacking is a type of cyberattack where criminals secretly use someone else’s computer, server, or cloud resources to mine cryptocurrency.
Understanding crypto-jacking
According to IBM, “Hackers use cryptojacking code (a type of malware) to produce and collect valuable cryptocurrency without incurring any associated costs.” The attackers exploit their victims’ resources while keeping all the profits for themselves.
How does crypto-jacking work?
According to Microsoft Threat Intelligence, cryptojacking in cloud environments typically begins when attackers gain access to a legitimate cloud account using compromised credentials. These credentials can be obtained through phishing, leaked passwords, or compromised devices. If the stolen account does not have sufficient permissions, attackers may attempt to gain higher privileges.
Once inside, attackers can use the victim's cloud environment to create large amounts of computing resources, often targeting powerful systems that can mine cryptocurrency more efficiently. Microsoft describes this as attackers using compromised tenants to “provision significantly more compute and other additional resources.”
The attackers then install cryptocurrency-mining software on the newly created virtual machines and connect them to mining pools. Microsoft notes that attackers may target GPU-based resources because they can make cryptocurrency mining “magnitudes more effective than any CPU compute offering.”
This means the victim effectively pays for the computing power while the attacker receives the cryptocurrency generated from it. In attacks investigated by Microsoft, organizations incurred more than $300,000 in compute fees as a result of cryptojacking.
Common sources of crypto-jacking
According to IBM, cryptojacking can reach victims through several different attack vectors. These include phishing emails, misconfigured systems, compromised web applications, infected browser extensions, malicious JavaScript, insider threats, and cloud environments.
- Phishing emails: Attackers may send links or attachments that trick victims into downloading cryptocurrency-mining malware.
- Misconfigured systems: Publicly exposed virtual machines, servers, and containers can provide attackers with an entry point to install cryptojacking software.
- Compromised websites and JavaScript: Malicious code can be injected into legitimate websites or JavaScript libraries, allowing attackers to use a visitor's computing power for mining.
- Browser extensions: Attackers can compromise legitimate browser extensions or create fake versions containing cryptojacking code.
- Cloud environments: Cloud infrastructure provides attackers with access to large amounts of computing power. IBM notes that cloud systems can “exponentially increase attack vectors” for cybercriminals.
- Insider threats: Employees or other insiders with legitimate access, as well as attackers using stolen credentials, can introduce cryptojacking software into an organization's environment.
These sources all provide attackers with the opportunity to secretly use a victim's computing resources for cryptocurrency mining while the victim absorbs the associated costs.
Identifying crypto-jacking
According to Microsoft Threat Intelligence, cryptojacking can be difficult to spot because attackers often use legitimate cloud accounts and resources to hide their activity. However, unusual changes in cloud usage can provide important warning signs.
One of the clearest indicators is a sudden increase in computing resources. Organizations should investigate unexpected spikes in virtual machine deployments, particularly when large numbers of resources are created within a short period. Microsoft found that malicious deployments often followed unusual patterns, with some attacks provisioning large amounts of compute within just a few hours.
Other warning signs include:
- A user suddenly creating large amounts of compute when they have never done so before.
- Unexpected GPU usage, particularly if an organization has no history of using GPU-based computing.
- Resources being deployed in unusual regions that the organization does not normally use.
- Unexpected increases in compute quotas, especially across several regions or within a short period.
- Unusual or suspicious login activity, such as authentication from unfamiliar locations or external Azure IP addresses.
- Connections to cryptocurrency mining pools. Microsoft says that seeing a connection to a mining pool from a virtual machine is a “strong indication of compromise.”
Defending against crypto-jacking
“Defending against cryptojacking requires a holistic approach that is, fortunately, congruent with many other leading cybersecurity strategies for general security hygiene,” says IBM. This approach should combine security tools, monitoring, and employee awareness.
Key measures include:
- Train employees: Educate staff about phishing, suspicious links, unsafe downloads, and other common ways cryptojacking malware can enter an organization.
- Use security software: IBM recommends combining endpoint detection and response (EDR), antivirus, and content disarm and reconstruction (CDR) tools to detect and block malicious code.
- Monitor CPU usage: Regularly checking CPU and system resource usage can help identify unexplained increases that could indicate unauthorized cryptocurrency mining.
- Block malicious scripts: Ad blockers and script-blocking tools can help prevent browser-based cryptojacking from running on users' devices.
- Audit third-party software: Organizations should conduct supply chain audits to identify potentially compromised software, browser extensions, or other third-party components.
- Monitor for threats in real time: Real-time threat detection can help identify suspicious activity before cryptojacking malware has time to operate unnoticed.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
Can cryptojacking go unnoticed?
Yes. Attackers may deliberately keep mining activity relatively quiet to avoid detection. Monitoring resource usage, account activity, and unexpected computing costs can help identify suspicious activity.
Is cryptojacking a cybercrime?
Using someone else's computing resources to mine cryptocurrency without permission constitutes unauthorized use of their systems and resources.
Why does cryptojacking use so much computing power?
Cryptocurrency mining involves performing large numbers of calculations. Mining software can therefore consume substantial CPU or GPU resources, particularly when attackers use multiple compromised systems simultaneously.
