🔄 Topic

Understanding cryptomining malware and how attackers abuse compromised systems for profit.


🎯 Goal

Learn how cryptomining malware works, what indicators it creates, and why it can remain hidden longer than more destructive malware.


🛠 What I Did

Today I studied cryptomining malware.

Cryptomining malware uses compromised systems to mine cryptocurrency for the attacker.

Unlike ransomware, it does not usually encrypt files or immediately stop business operations.

Instead, it quietly abuses system resources.

Common indicators include:

  • high CPU usage
  • high GPU usage
  • unusual PowerShell activity
  • unknown processes consuming resources
  • connections to mining pools
  • systems becoming slow
  • unexpected scheduled tasks
  • persistence mechanisms

One example I reviewed was WannaMine, a cryptomining malware family that abused Windows systems to mine cryptocurrency.

The important distinction:

Ransomware wants fast impact.

Cryptomining often wants long-term resource theft.


🔗 Key Cybersecurity Connections

Cryptomining matters because it may be overlooked.

If a system is slow, users may assume:

  • old hardware
  • too many applications open
  • normal workload
  • bad performance day

But from a security perspective, persistent high resource usage can be evidence.

Cryptomining malware may enter through:

  • vulnerable services
  • stolen credentials
  • malicious scripts
  • exposed cloud workloads
  • weak container security
  • unpatched systems

In cloud environments, cryptomining can also create major financial cost because attackers consume compute resources.

So the impact is not only performance.

It can also be money.


🔍 Investigation Questions

  • Which process is consuming CPU or GPU?
  • Is the process expected?
  • Who launched it?
  • Where is the executable located?
  • Is PowerShell involved?
  • Is the host connecting to mining pools?
  • Are there suspicious scheduled tasks?
  • Is the activity persistent after reboot?
  • Did the host recently connect to suspicious domains?
  • Are multiple hosts showing the same behavior?
  • Is this happening on servers, endpoints, or cloud workloads?

🚨 Detection Opportunities

Possible detection ideas:

  • sustained high CPU usage by unknown process
  • endpoint connecting to known mining pool domains
  • unusual process names imitating system processes
  • PowerShell downloading mining payloads
  • scheduled task executing suspicious binary
  • container using abnormal CPU
  • cloud instance with unexpected compute spike
  • outbound traffic to mining-related infrastructure
  • many endpoints connecting to the same mining pool

Example detection pattern:

process=unknown.exe
cpu_usage=95%
duration=45 minutes
destination_domain=mining-pool.example
suspicion=cryptomining_malware

This combines endpoint and network evidence.

That is stronger than CPU usage alone.


🧭 MITRE ATT&CK Techniques

  • T1496 — Resource Hijacking
  • T1059 — Command and Scripting Interpreter
  • T1105 — Ingress Tool Transfer
  • T1053 — Scheduled Task/Job
  • T1071 — Application Layer Protocol

🗺 Visual Investigation Diagram

Initial compromise
    ↓
Miner payload delivered
    ↓
Persistence created
    ↓
CPU/GPU resources abused
    ↓
Mining pool contacted
    ↓
Attacker profits quietly

⚠ Challenges

The main challenge is that cryptomining may not create obvious damage.

The system still runs.

The user may only notice slowness.

That makes the infection easier to ignore.

Another challenge is that performance problems are not automatically security problems.

High CPU could be legitimate.

The defender needs to combine:

  • process evidence
  • user context
  • network destinations
  • persistence artifacts
  • historical baseline

📚 What I Learned

I learned that not all malware wants to destroy or encrypt data.

Some malware wants to stay quiet and profit over time.

This changes the detection mindset.

Instead of only looking for dramatic impact, I need to look for resource abuse, persistence, and suspicious outbound communication.


➡ Next Steps

  • Study mining pool traffic patterns
  • Review endpoint process monitoring
  • Practice investigating high CPU alerts
  • Learn cloud cryptomining detection patterns
  • Compare cryptomining malware with botnet behavior
  • Add resource hijacking to my threat notes

🧠 Reflection

Cryptomining malware is interesting because it is quieter than ransomware but still harmful.

It shows that attacker motivation changes attacker behavior.

Some attackers want disruption.

Some want access.

Some want compute power.

The SOC analyst needs to recognize all of them.


🧩 Lessons Learned

What worked

Connecting performance indicators with security investigation.

What broke

Thinking malware always causes immediate visible damage.

Why it broke

Cryptomining can profit from slow, quiet resource abuse.

Fix / takeaway

Sustained abnormal resource usage deserves investigation, especially when combined with suspicious network traffic.


📈 Skill Progression Context

This supports SOC readiness because cryptomining alerts are common in endpoint, cloud, and container environments.

Investigating them requires correlating process telemetry, network activity, and resource usage.


😄 TL;DR

Ransomware kicks the door down.

Cryptomining sneaks in and uses your electricity bill.