Join our Newsletter — 33% off our NHI Course

Miner Proxy

A miner proxy is infrastructure that aggregates mining traffic from infected hosts and forwards it to a mining pool. Attackers use it to combine resources, hide the scale of the campaign, and make analysis of individual victim activity more difficult for defenders.

What a miner proxy does

A miner proxy sits between infected devices and a legitimate mining pool, aggregating many small mining submissions into a single outbound stream. That intermediary role helps the operator hide how many hosts are contributing, reduces the visibility of per-host activity, and can make traffic analysis more difficult.

Because the proxy concentrates many victims through one relay, defenders often see a cleaner external pattern than the underlying infection actually produced. The proxy can also provide a layer of operational buffering, so the campaign survives if some individual miners are removed or throttled.

How miner proxies support cryptocurrency-mining abuse

Miner proxies are usually part of a larger cryptojacking workflow, where attackers want to turn compromised systems into a distributed source of hashing power. By centralising the outbound mining traffic, the proxy can normalise connections, simplify pool switching, and reduce the chance that one noisy host exposes the full campaign.

The key abuse value is operational scale. A single proxy can coordinate many endpoints while presenting as a smaller number of egress destinations, which helps the operator blend into ordinary network noise and makes campaign attribution harder.

Seen as an attack-enablement layer, the proxy is less about computation than coordination. It is the control point that turns many low-value infected hosts into a more manageable mining operation.

Detection and investigation signals

Miner proxies often become visible through repetition, not content. Defenders may notice long-lived connections to the same pool infrastructure, unusual fan-out from many internal hosts to one external relay, or mining traffic that appears concentrated through a single intermediary rather than distributed directly.

That pattern matters because the proxy can obscure the true number of participating endpoints, so investigation should not stop at the first visible egress node. When a proxy is present, the real infection surface is usually broader than the network telemetry initially suggests.

Useful investigation also depends on correlating endpoint activity with network behavior. A host that appears to make only modest outbound requests can still be part of a larger mining set if its traffic is being relayed and consolidated upstream.

Why the proxy layer changes the defender’s view

A miner proxy changes the defender’s job by separating the compromised host from the externally visible mining destination. That separation can delay triage, weaken simple allowlist or blocklist strategies, and reduce confidence in host-by-host traffic comparisons.

It also introduces a concentration point for the attacker. If defenders can identify and disrupt the proxy, they may reduce the campaign’s coordination even when some infected machines remain active. For that reason, the proxy is both a camouflage mechanism and an operational dependency.

In practice, the proxy is a reminder that mining abuse is often networked and managed, not just a collection of isolated infected endpoints.

Risk and Threat Considerations

Miner proxies increase the blast radius of cryptojacking because one relay can hide many compromised hosts and make the campaign look smaller than it is. They also complicate attribution and containment by breaking the simple relationship between one infected endpoint and one observed mining destination.

Failure mechanism: The attacker centralises mining traffic through an intermediary, which masks the true number of victims, concentrates egress patterns, and reduces the usefulness of host-level indicators for detection.

Impact: Defenders may detect the proxy late, underestimate the scale of compromise, and miss additional infected systems that are still mining through the relay.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1496 — Resource Hijacking Miner proxies support cryptojacking by consolidating hijacked compute into mining activity.
Recommendation — Map proxy-backed mining traffic to T1496 and hunt for compromised hosts generating sustained pool-bound activity.
NIST CSF 2.0 DE.CM-01 — Monitoring for Unauthorized Devices, Connections, and Software Miner proxies are exposed through abnormal outbound connection patterns and unexpected relays.
Recommendation — Monitor for proxy-like egress concentration and investigate repeated mining-related connections.
CIS Controls v8 CIS-12 — Network Infrastructure Management Miner proxies depend on network paths and egress infrastructure that must be managed and observed.
Recommendation — Restrict and review outbound network paths that can relay mining traffic.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Miner proxies require log correlation to reconstruct the real source of aggregated mining traffic.
Recommendation — Correlate proxy, host, and egress logs to reconstruct the underlying mining cluster.

Practitioner Guidance

What to watch for: Treat repeated connections to the same mining destination, unusual relays between internal hosts and pool infrastructure, and persistent low-volume encrypted sessions as investigation triggers. The proxy pattern is often the clue that the visible traffic is only the front end of a wider compromise.

Practitioner takeaway: Look for the concentration point, not only the final pool connection, because the proxy is frequently the operational hinge that reveals the rest of the mining cluster.