Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is cryptomining abuse?

Cryptomining abuse is unauthorised use of computing resources to perform cryptocurrency-mining work. The relevant harm may include electricity or cloud cost, degraded service, exhausted quotas and unauthorised financial benefit.

High processor use can prompt investigation, but proving mining requires evidence of the workload and its purpose.

Identify the mining workload

Mining software repeatedly performs calculations and usually communicates with a pool or other coordinating service that assigns work and records credit. Useful evidence can include:

  • the process, container, virtual machine or script running the workload;
  • command lines, configuration and process lineage;
  • pool addresses, protocols and worker identifiers;
  • wallet or payment identifiers;
  • the account or deployment mechanism that launched it; and
  • measured resource use, billing and operational effect.

The visible process may be packed, renamed or memory-resident. Process, memory and network evidence can therefore be more informative than a search for known filenames.

Preserve what can recreate it

A terminated miner may return because a scheduled task, container image, cloud template or orchestration rule remains active. Collect the deployment mechanism as well as the running process. That distinction is important both for understanding the incident and explaining why activity continued after an apparent shutdown.

Wallet and pool identifiers may link activity or show where credit was directed, but they do not necessarily identify a person. Pools, hosted wallets and intermediaries can reuse or control those identifiers.

Key takeaway

Prove mining by linking the workload, launch mechanism, pool or payment route and resource impact; high utilisation or a wallet address alone is not proof of criminal activity or personal identity.

Reference: CIM-267Cyber Incidents & Offender Methods