Stratum is a mining communication protocol used between cryptocurrency miners and mining pools to submit work and receive assignments. In malware analysis, Stratum-related strings are a strong indicator of mining activity because they point to active coordination with a pool rather than normal application behavior.
What Stratum Does
Stratum is a mining communication protocol that lets miners receive job assignments from a pool and submit completed work. It is a coordination layer, not a blockchain consensus protocol, and its primary value is efficient miner-pool work distribution.
How Stratum Is Used in Mining Operations
In normal operations, Stratum carries the messages that keep miners synchronized with the pool’s current target, job template, and share submission workflow. That makes it central to pool mining because it reduces latency, standardises job delivery, and helps pools aggregate hash power across many devices.
Because the protocol is lightweight and widely reused, the same Stratum traffic patterns can appear in legitimate mining farms, opportunistic malware, and commodity cryptomining tooling. The protocol itself is neutral; the security meaning comes from the surrounding context, such as where it runs, what process opens the connection, and whether the destination is an expected pool.
Why Stratum Strings Matter in Detection
In malware analysis, Stratum-related strings are often treated as strong evidence of mining behaviour because they commonly indicate active communication with a pool rather than ordinary application networking. Analysts look for these strings alongside other signals such as unusual CPU usage, persistent outbound connections, and miner-like process behaviour.
A Stratum indicator is usually more useful as part of a cluster of evidence than as a standalone verdict. Legitimate mining software, test environments, and research tooling can also speak Stratum, so attribution depends on process lineage, destination reputation, configuration files, and the operational context of the host.
Operational and Security Implications
Stratum becomes security-relevant when it appears on systems that should not be mining, because it can reveal unauthorised cryptomining, credential misuse in hosted environments, or concealed resource abuse. On constrained systems, mining activity can also create performance degradation, thermal stress, noisy telemetry, and unexpected cloud or electricity cost.
For defenders, the practical question is not whether Stratum exists, but whether the observed Stratum session aligns with approved mining activity and expected network paths. In incident handling, the protocol is best treated as a behavioural indicator that can help narrow triage quickly when combined with endpoint and network telemetry.
Risk and Threat Considerations
Stratum traffic can expose unauthorised cryptomining, which is often attractive to attackers because it monetises access without obvious data theft. The same pattern can also indicate an environment where outbound controls, host monitoring, or software allowlisting are too weak to stop mining tools from establishing pool connections.
Failure mechanism: A miner, dropper, or loader establishes an outbound Stratum session to a pool, then keeps the host working for the attacker’s benefit while blending in with normal encrypted or repetitive traffic.
Impact: The result can be sustained CPU and GPU consumption, higher cloud spend, degraded service performance, and delayed detection of a broader compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1496 — Resource Hijacking | Stratum is often used to run cryptomining on compromised hosts. |
| Recommendation — Map Stratum detections to resource hijacking activity and triage the host for unauthorized mining. | ||
| NIST CSF 2.0 | DE.AE-01 — Anomalies and events are analyzed to understand potential impact and scope | Stratum strings and pool traffic are anomalous events that require impact and scope analysis. |
| DE.CM-01 — Networks and network services are monitored to find potentially adverse events | Stratum is a network protocol indicator that can be surfaced through monitoring. | |
| Recommendation — Analyze Stratum-related anomalies to determine whether the activity is expected mining or misuse. Monitor for outbound Stratum sessions and alert on unexpected mining-pool connections. | ||
| NIST SP 800-53 Rev 5 | SI-4 — System Monitoring | Stratum traffic is a detectable indicator of potentially malicious host behavior. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Stratum findings need correlation across logs, process data, and network telemetry. | |
| Recommendation — Use system monitoring to flag unexpected Stratum connections and mining-like processes. Review audit data to correlate Stratum indicators with host processes and network destinations. | ||
Practitioner Guidance
What to watch for: Treat Stratum as a lead, not a conclusion. Correlate it with process ancestry, command-line arguments, persistence mechanisms, and destination reputation before deciding whether the activity is authorised mining or abuse.
Governance implication: Organisations that permit mining should explicitly define approved pools, hosts, and exception handling so that Stratum-based activity can be distinguished from shadow mining or malware-driven abuse.