Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that cryptojacking is taking…
Cyber Security

What are the signs that cryptojacking is taking hold on enterprise endpoints?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Common signs of cryptojacking include sustained high CPU or GPU usage, unexpected resource spikes, noisy endpoint alerts, and outbound traffic to mining pools. Security teams should correlate those signals with EDR telemetry and system performance alarms. If endpoints are consistently overtaxed without a clear business workload, treat it as a possible mining incident and investigate quickly.

What the Endpoint Signals Usually Mean

Cryptojacking on enterprise endpoints is usually operationally noisy before it is obviously malicious. Mining workloads are compute-intensive, so the first clues are often sustained CPU or GPU saturation, fans running hard for long periods, sluggish user sessions, and battery drain on mobile devices. Those signals matter most when they persist outside approved high-load business activity.

Resource abuse is not limited to the endpoint itself. A miner also needs a pool connection, so network indicators such as repeated outbound traffic to unfamiliar mining infrastructure, abnormal DNS lookups, or long-lived connections can help distinguish legitimate heavy use from covert mining. When the process is hidden well, the performance pattern may be more visible than the binary name.

For enterprise triage, the key question is whether the load pattern matches a known workload. Batch jobs, renders, software builds, and analytics can all spike resources, but they usually have an owner, a schedule, and an expected footprint. Cryptojacking tends to look persistent, opportunistic, and out of proportion to the endpoint’s normal role.

  • Watch for sustained high utilisation rather than isolated spikes.
  • Correlate performance complaints with endpoint process trees and network egress.
  • Compare the affected host’s behaviour with its normal workload profile.

Why Cryptojacking Stands Out in Enterprise Environments

Cryptojacking is attractive because it converts someone else’s compute into private gain, which means defenders often notice the cost before the root cause. The practical impact is not just slower machines. Mining can steal capacity from business applications, increase heat and power draw, accelerate hardware wear, and create a breadcrumb trail that leads into a broader endpoint compromise.

In many cases the miner is the visible payload, not the whole incident. Initial access may come from a phishing click, a malicious download, an exposed service, or another foothold that lets the attacker run code on the host. Once present, the miner tries to remain quiet, persist across reboots, and avoid security tools long enough to make the campaign profitable.

This is why endpoint telemetry matters. Process execution, parent-child relationships, network destinations, and suspicious persistence mechanisms are often more useful than a single alert. A miner that repeatedly relaunches after termination, or one that spawns from an unexpected script or office application, is more concerning than a one-off resource blip.

Risk and Threat Considerations

Cryptojacking can be both an operational nuisance and an indicator of broader compromise. The immediate risk is degraded endpoint performance, but the deeper concern is that the same access path used to drop a miner can also support credential theft, lateral movement, or additional payloads.

Failure mechanism: Attackers gain code execution on the endpoint, launch a miner, and then rely on persistence, concealment, and low-and-slow execution to avoid detection while consuming enterprise resources.

Impact: Organisations may see reduced user productivity, higher infrastructure costs, unstable endpoints, and delayed discovery of a wider intrusion if the mining activity is treated as a standalone nuisance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-10 — Audit Log ManagementEndpoint mining often shows up in logs before users report impact.
CIS-4 — Secure Configuration of Enterprise Assets and SoftwareHardening helps reduce miner footholds on enterprise endpoints.
CIS-7 — Continuous Vulnerability ManagementCryptojacking often follows exploitation of unpatched endpoints or exposed software.
Recommendation — Review endpoint logs for repeated suspicious process launches and abnormal outbound connections. Harden endpoint builds and remove unnecessary execution paths that malware commonly abuses. Prioritise patching on endpoints that expose exploitable services or outdated software.
NIST CSF 2.0DE.CM — Continuous MonitoringResource spikes and egress anomalies are monitoring signals for cryptojacking.
DE.AE — Anomalies and EventsCryptojacking is usually detected as abnormal endpoint behaviour first.
Recommendation — Monitor endpoint performance and network telemetry for anomalous mining behaviour. Triage anomalous CPU, GPU, and network patterns as potential compromise indicators.
MITRE ATT&CKT1496 — Resource HijackingCryptojacking is a direct instance of attacker resource hijacking for mining.
Recommendation — Map observed mining behaviour to resource hijacking and hunt for the initial access path.

Practitioner Guidance

What to verify: Confirm whether the endpoint’s resource spike aligns with an approved workload, maintenance window, or known application stack. If it does not, inspect the running process tree, recent downloads, script activity, and outbound connections before assuming the issue is just performance drift.

Decision rule: If you can pair the CPU or GPU surge with suspicious egress, unexpected persistence, or an unknown parent process, treat the case as a security incident rather than a performance ticket. That distinction changes the urgency of containment, triage, and scoping.

Practitioner takeaway: The most useful signal is not high utilisation by itself, but high utilisation that cannot be explained by the endpoint’s business role and is accompanied by miner-style network behaviour.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org