Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should cryptomining and automated abuse be reported?

Report the workload, unauthorised resource use, automation, beneficiary and control as separate findings. A large bill, repeated activity or wallet identifier can support part of the account but does not identify the offender by itself.

This separation makes clear what ran, what it cost and what the evidence says about the people behind it.

State what is directly established

A structured account should identify:

  • the process, script, image or service involved;
  • how it was introduced, launched and persisted;
  • the affected device, account or cloud resource;
  • when and for how long it operated;
  • measured consumption, cost and service impact;
  • pool, wallet, customer or other apparent beneficiary;
  • evidence that activity was automated; and
  • the account, configuration or session linked to control.

Separate preparation from execution. A target list or mining image may show capability or planning; scheduler, process, provider and network records show whether a workload actually ran.

Keep estimates and attribution qualified

Provider billing, measured utilisation and projected loss are different measures. A bill may include legitimate resources, while serious abuse stopped early may produce little cost. State how each figure was derived.

Similarly, “the wallet received mining credit” does not mean its controller deployed the workload. Shared wallets, pools, proxies, compromised accounts and automation can insert further layers. Identify which findings come from direct workload evidence and which are inferred from cost or behavioural patterns.

Key takeaway

Describe the unauthorised workload and its measured impact first, then report automation, benefit and human control at the precise level supported by independent evidence.

Reference: CIM-277Cyber Incidents & Offender Methods