Skip to content
CIM-267 Cyber Incidents & Offender Methods

What is cryptomining abuse?

Cryptomining abuse is the unauthorised use of computing resources to generate cryptocurrency or support mining activity.

Evidential caution: that high processor use or a mining application automatically proves criminal activity.

What this means

Mining may be:

authorised;

part of testing;

performed by a user without organisational approval;

carried out through malware;

deployed through compromised cloud accounts;

hidden inside another application.

which process or workload performed the mining;

which device, account or cloud resource was involved;

when it began;

how it was installed or launched;

which mining pool or wallet was used;

what resources were consumed;

whether authority existed;

what financial benefit followed.

Relevant evidence may include process activity, command lines, cloud audit logs, billing records, mining-pool connections, wallet identifiers, scheduled tasks and deployment scripts.

High CPU, GPU or cloud use may support a mining hypothesis.

Legitimate scientific, media, analytics or development workloads may create similar utilisation.

It may be shared, reused, controlled by a service or linked to an intermediary.

Mining may be deployed through scheduled tasks, containers, orchestration platforms or cloud templates. Preserve the mechanism that recreates the workload, not only the visible process. A terminated miner may return automatically if the deployment rule, image or compromised credential remains active.

Prove the mining process, account, resource, pool or wallet and resulting consumption, and distinguish unauthorised mining from legitimate high-performance workloads.

================================================================================

What to check or do next

  • Investigators should establish:

Evidential limits

It may not.

It does not prove mining by itself.

Do not assume the wallet address identifies the offender personally.

Where mining software is packed, renamed or memory-resident, ordinary file searches may not identify it. Process, memory, network and deployment evidence may be more reliable. Preserve the affected system state before remediation removes the workload and its configuration. The operational takeaway is:

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.