What is cryptojacking?¶
Cryptojacking is cryptomining carried out without authority using someone else's device, account or computing service. It describes the unauthorised use, not a single technical method.
The mining may run through installed code, a browser page, a compromised cloud account, a container or a legitimate management platform.
Common routes produce different traces¶
A compromised website can deliver a browser script that mines only while a visitor keeps the page open. A stolen cloud credential can create many virtual machines that continue running independently. A poisoned container image or deployment template can reproduce the same workload across multiple systems.
Those routes require different evidence. Depending on the case, preserve:
- page content, cached scripts and browser history;
- cloud identity, API and resource-creation logs;
- image, template and orchestration identifiers;
- endpoint process and memory records;
- pool connections and worker configuration; and
- cost, performance or service impact.
Shared images and closely timed launches may explain why many systems show similar activity without requiring a separate manual installation on each one.
Ownership is not control¶
The website owner, cloud subscriber or device user may also be a victim. Establish the route that introduced the workload and the identity or automation that controlled it before drawing conclusions about knowledge or benefit.
Likewise, related mining workloads do not automatically share one controller. Infrastructure or deployment commonality should be tested alongside account, configuration and payment evidence.
Key takeaway
Cryptojacking is unauthorised mining by any delivery route; identify how the workload arrived, what it consumed and who controlled or benefited from it without treating the resource owner as the offender.