Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› Crypto Mining Abuse
Cyber Security

Crypto Mining Abuse

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Cyber Security

Unauthorised use of computing resources to mine cryptocurrency for an attacker’s benefit. It typically shows up as CPU exhaustion, higher power consumption, degraded service performance, and unexpected process activity. The abuse matters because it turns ordinary infrastructure into a revenue source without the owner’s consent or visibility.

How Crypto Mining Abuse Works

Crypto mining abuse is usually a resource hijacking problem, not a malware category by itself. Attackers deploy miners, use stolen infrastructure, and try to stay quiet enough that CPU, GPU, storage, and network consumption looks like ordinary load rather than an obvious intrusion.

The abuse often begins after compromise of a host, cloud account, container, or orchestration environment. Once running, the miner competes with business workloads for compute, which is why degraded performance is often the first clue operators notice.

Common Signs and Operating Patterns

The most visible indicators are sustained processor saturation, unexplained power draw, higher cloud bills, fan noise on endpoints, and processes that restart themselves or appear in unusual execution paths. On shared platforms, the pattern can also show up as noisy-neighbour behaviour or sudden cost spikes across multiple instances.

In cloud environments, crypto mining abuse often overlaps with identity compromise and account misuse. A compromised credential can give an attacker enough access to spin up compute, expand across services, or hide the activity inside legitimate administrative traffic, which is why Amazon AWS Hacked Accounts Crypto-Mining is a useful example of the attack pattern.

Why the Abuse Persists

Crypto mining abuse persists because it is economically simple and operationally noisy only when defenders are already watching closely. The attacker does not need to exfiltrate sensitive data to benefit, so the activity can remain profitable even when it causes gradual performance degradation rather than an immediate outage.

It also benefits from blending into normal infrastructure operations. Autoscaling, ephemeral compute, shared containers, and permissive access paths can make the abuse look like legitimate workload growth unless teams correlate workload behaviour, billing, and process telemetry.

Security Implications for Infrastructure Owners

Beyond wasted compute, mining abuse can be an indicator of broader compromise. The same access path that enables mining may also support credential theft, command execution, lateral movement, or later monetisation by the same threat actor.

For defenders, the key implication is that resource abuse should be treated as both an availability issue and an intrusion signal. If a system is being used to mine cryptocurrency, someone has likely already gained enough execution authority to turn your infrastructure into theirs.

Risk and Threat Considerations

Crypto mining abuse creates direct cost, availability, and control risk because the attacker’s goal is to extract utility from your compute while remaining inside normal operating thresholds for as long as possible. In cloud and virtualised environments, that can also mask deeper compromise, since the mining workload is often just the visible symptom of unauthorised access.

Failure mechanism: Excess compute consumption, credential compromise, container breakout, or insecure cloud permissions let the attacker deploy or persist miners, then scale usage across hosts or accounts.

Impact: Organisations pay for the attacker’s workload, lose service headroom, and may miss the underlying intrusion until bills, performance, or telemetry anomalies become obvious.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1496 — Resource HijackingCovers abusive compute use for mining and other resource theft patterns.
Recommendation — Map resource spikes and miner activity to T1496 and hunt for unauthorized compute consumption.
NIST CSF 2.0DE.CM-01 — Networks and network services are monitored to detect potential cybersecurity eventsMining abuse is commonly detected through sustained telemetry and performance anomalies.
Recommendation — Monitor workload and network telemetry for sustained compute-abuse indicators.
CIS Controls v8CIS-12 — Network Infrastructure ManagementSupports detecting and containing unauthorized infrastructure abuse through monitoring and control of assets.
Recommendation — Restrict and monitor infrastructure paths that could host unauthorized compute workloads.
NIST SP 800-53 Rev 5SI-4 — System MonitoringMining abuse is identified through continuous monitoring of host and workload behaviour.
AC-6 — Least PrivilegeUnauthorized mining often succeeds where excessive execution privilege or cloud access exists.
IA-5 — Authenticator ManagementMining campaigns frequently begin with stolen credentials or weak secret handling.
Recommendation — Use SI-4 to alert on sustained anomalous process and resource consumption. Apply AC-6 to limit the access needed to launch or persist compute workloads. Use IA-5 to protect and rotate credentials that could be abused to provision mining.

Practitioner Guidance

What to watch for: Treat unexplained sustained CPU load, abnormal process trees, new outbound connections, and cost anomalies as investigation triggers, especially when they appear on hosts that should be idle or predictable. Mining abuse is often easiest to stop when detected early, before it spreads into automated or cloud-managed resources.

Practitioner takeaway: The most effective response is to pair workload monitoring with access review, because the miner is usually the symptom and the exposed execution path is the real control gap.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org