Cryptomining is the process of using computing power to solve the cryptographic work required to validate transactions and create new cryptocurrency units. In practice, miners repeatedly generate hashes until one meets the coin’s difficulty requirement. The work is computationally expensive, which is why attackers seek out other people’s machines.
Expanded Definition
Cryptomining is the process of using computing power to validate blockchain transactions and earn cryptocurrency rewards. In security discussions, it is often shorthand for both legitimate mining and unauthorised mining activity, sometimes called cryptojacking.
The term is often misunderstood as a purely financial or blockchain topic, but from a cyber perspective the key issue is resource consumption: CPU, GPU, memory, power, cloud spend, and system performance. The same software and techniques used by legitimate miners can also be used by attackers, which makes context essential. A mining workload running on approved infrastructure is different from the same workload silently deployed on an endpoint, server, or container cluster.
There is also an important boundary between the blockchain protocol and the malware or abuse that may ride on top of it. The mining algorithm itself is not the security problem. The security problem arises when mining is hidden, unauthorised, or operationally disruptive, or when it is used as a persistence mechanism for broader compromise.
Examples and Use Cases
- Legitimate cryptocurrency operations run mining software on dedicated hardware where owners accept the cost, heat, and power draw as part of the business model.
- Attackers deploy mining binaries on compromised servers or workstations to monetise spare capacity without the owner’s consent.
- Cloud environments can be abused for mining when exposed keys, weakly governed containers, or neglected test instances provide cheap or free compute.
- Browser-based mining scripts may execute in a session to consume local CPU, often causing sluggishness, fan noise, and battery drain.
- Security teams may also see mining as a follow-on activity after intrusion, because it offers a low-visibility way to profit while keeping the host online.
In practice, the tradeoff is straightforward: the more scalable the compute environment, the more attractive it becomes for opportunistic abuse if monitoring and cost controls are weak. Mining itself may be low-complexity, but large fleets turn even small per-host consumption into material waste.
Security Implications
Unauthorised cryptomining is usually a sign that an environment has already lost some degree of control. Even when the payload is “only mining,” it can indicate missed detection, excessive permissions, exposed management interfaces, or a host that is being quietly repurposed by an adversary.
The consequences are practical and measurable. Organisations can see degraded endpoint performance, inflated cloud bills, shortened hardware life, higher cooling demand, and reduced capacity for legitimate workloads. In shared infrastructure, mining can also create noisy-neighbour effects that make troubleshooting harder and mask additional malicious activity.
A common practitioner mistake is to treat mining as merely a cost issue. In reality, it is often a compromise indicator and should be investigated alongside process creation, persistence, outbound connections to mining pools, and unusual spikes in resource usage. Security teams should also watch for repeated reinfection, which suggests the underlying access path or control gap has not been closed.
Security, Operational and Governance Implications
Cryptomining matters because it sits at the intersection of abuse, availability, and governance. On endpoints and servers, it can erode service levels; in cloud and container platforms, it can become a direct financial drain; in regulated environments, it can signal weak asset control and poor workload oversight.
The operational risk increases when teams lack clear ownership for compute estates, do not baseline normal utilisation, or fail to distinguish approved mining from unauthorised activity. That distinction is especially important in environments where blockchain projects, development sandboxes, or research systems coexist with production services.
A useful reference point is MITRE ATT&CK, which treats cryptomining as a monetisation outcome often enabled by intrusion and persistence. For defenders, the important question is not whether mining exists somewhere in the environment, but whether it is authorised, visible, and contained before it becomes a standing drain on resources.
Risk and Threat Considerations
Unauthorised cryptomining creates both exposure and threat. It consumes compute that should support business services, and it can also serve as a quiet persistence layer after compromise, especially when attackers want to monetise access without disrupting the host enough to trigger immediate response.
Failure mechanism: Attackers usually gain execution through weakly protected systems, exposed services, vulnerable containers, stolen credentials, or malicious scripts, then optimise for stealth by throttling usage, avoiding obvious file changes, and blending into normal background processing.
Impact: The result is resource theft, higher operating cost, service degradation, and a stronger signal that the environment may contain broader compromise, not just mining activity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1496 — Resource Hijacking | Cryptomining is a common resource-hijacking outcome in ATT&CK. |
| Recommendation — Map mining indicators to T1496 and hunt for resource abuse across endpoints and cloud workloads. | ||
| CIS Controls v8 | CIS 4 — Secure Configuration of Enterprise Assets and Software | Mining abuse often follows exposed, misconfigured, or unmanaged systems. |
| CIS 8 — Audit Log Management | Mining campaigns often leave process, network, and utilization traces in logs. | |
| Recommendation — Harden exposed assets and remove unnecessary software paths that let miners persist. Collect and review logs that reveal abnormal execution, outbound pool traffic, and reinfection. | ||
| NIST CSF 2.0 | DE.CM — Security Continuous Monitoring | Mining abuse is usually found through anomalous resource and network monitoring. |
| PR.AA — Identity Management, Authentication and Access Control | Unauthorized mining often depends on compromised access or weak control over execution. | |
| Recommendation — Baseline normal utilisation and alert on sustained compute or network anomalies. Tighten access paths that permit unauthorised workload execution or persistence. | ||
Practitioner Guidance
What to watch for: Focus on unexplained CPU or GPU saturation, abnormal power use, persistent outbound traffic to mining pools, and processes that survive reboots or reappear after removal. Those signals usually matter more than the presence of a miner binary alone.
Governance implication: Treat cryptomining policy as part of asset use and workload governance, not just malware response. Clear rules for approved mining, if any, help reduce ambiguity when performance spikes or cloud bills rise unexpectedly.
Practitioner takeaway: If mining appears without business approval, assume it is an incident until the access path, persistence mechanism, and scope have been understood.