What is resource hijacking?¶
Resource hijacking is unauthorised use of computing, storage, network or service capacity for someone else's purpose. Cryptomining is one example, but hijacked resources may also relay traffic, host malware, send spam, crack passwords, store data or participate in denial-of-service activity.
The investigation should identify the actual workload and impact rather than using processor consumption as a proxy for every form of abuse.
A resource can support several customers or purposes¶
A compromised server may run more than one unauthorised service at the same time. Access can also be sold, shared or transferred, so changing destinations and workloads may represent several customers or successive controllers rather than one continuous operation.
Establish where possible:
- which process, service, account or cloud resource was used;
- how the workload was launched and persisted;
- its network destinations and apparent function;
- changes in configuration or control over time;
- any service, customer or beneficiary relationship; and
- the specific financial and operational consequences.
Process activity, configuration, system or cloud logs, network records, billing and provider evidence can help separate these layers.
Impact is not limited to exhaustion¶
Hijacking may degrade performance without consuming all available capacity. Storage quotas, network reputation, latency, cloud limits and service availability can be affected even when CPU use appears normal. Measure the resource actually consumed and the consequence for legitimate activity.
A persistent job may continue after the original access session ends. Preserve the mechanism that recreates the workload before assuming the visible process represents the whole incident.
Key takeaway
Identify each unauthorised workload, its launch mechanism, controller or beneficiary and measurable impact; resource hijacking is broader than cryptomining and one host may support several distinct activities.