-
How does cryptojacking work?
- What are the key components of a cryptojacking cyberattack?
-
What are the primary risks and enterprise impacts of cryptojacking?
-
How can organizations detect cryptojacking activity?
-
How can enterprises protect against cryptojacking?
-
How can enterprises protect against cryptojacking?
- How Akamai can help
Key takeaways
-
Cryptojacking is a cyberattack where threat actors secretly exploit a victim’s computing resources to mine cryptocurrency without authorization.
-
Cybercriminals deploy malicious code, such as JavaScript in a web browser or host-based malware, to hijack processing power from endpoints, servers, or cloud infrastructure.
-
Cryptojacking threatens enterprises by draining computing resources, drastically increasing operational expenses, and exposing broader security vulnerabilities within the corporate network.
-
Enterprises prevent cryptojacking by deploying robust endpoint protection, filtering web traffic, blocking malicious scripts, and maintaining strict access controls over cloud infrastructure.
Cryptojacking is a cyberattack where threat actors secretly exploit a victim’s computing resources to mine cryptocurrency without authorization. Cybercriminals deploy malicious code, such as JavaScript in a web browser or host-based malware, to hijack processing power from endpoints, servers, or cloud infrastructure. This illicit activity generates digital currency for the attacker while leaving the victim with degraded system performance, hardware wear, and inflated energy costs.
How does cryptojacking work?
Cryptojacking works by infiltrating a target device or network with cryptomining scripts that run stealthily in the background to solve complex cryptographic puzzles for blockchain ledgers. Cybercriminals typically rely on two primary vectors to execute these attacks: host-based cryptojacking and browser-based cryptojacking.
Host-based cryptojacking requires the attacker to install malicious code directly onto the target device. Threat actors often use social engineering, such as a phishing email, to trick end users into downloading infected software or Trojans. Once installed, the cryptojacking malware continuously drains the CPU and GPU of the infected endpoint or server. Because this malware runs at the operating system level, host-based cryptojacking is highly persistent and can cause severe overheating and high CPU usage over long periods.
Browser-based cryptojacking does not require the victim to install local software. Instead, cybercriminals inject malicious JavaScript code into compromised websites or distribute the payload through malicious ads. When a user visits the compromised site, the browser executes the script, utilizing the victim’s processing power to mine cryptocurrency for as long as the browser tab remains open.
What are the key components of a cryptojacking cyberattack?
The core components of a cryptojacking attack include a delivery mechanism, specialized cryptomining code, and an external digital wallet to collect the generated cryptocurrency. Unlike ransomware, which announces its presence to demand payment, cryptojacking relies entirely on stealth to maintain long-term access to enterprise computing resources.
Delivery vector: Attackers use phishing attacks, malicious browser extensions, or vulnerable public-facing cloud services to deploy the initial payload into the target environment.
Cryptomining scripts: Programs like XMRig are specifically designed for malicious cryptomining. While early threat actors attempted Bitcoin mining, modern cybercriminals use these scripts to mine privacy-focused cryptocurrencies like Monero, which are optimized for standard CPU processing power rather than specialized GPU rigs.
Mining pool connection: The malicious code communicates with a centralized mining pool via outbound network traffic, combining the computing resources of multiple compromised devices to increase the chances of earning a blockchain reward.
Attacker wallet: Once the compromised devices successfully validate a block on the blockchain, the generated digital currency is automatically deposited into a digital wallet controlled by the attackers.
What are the primary risks and enterprise impacts of cryptojacking?
Cryptojacking threatens enterprises by draining computing resources, drastically increasing operational expenses, and exposing broader security vulnerabilities within the corporate network. Because cryptojacking is designed to remain hidden, organizations often sustain long-term financial and operational damage before identifying the intrusion.
Resource exhaustion: Malicious cryptomining consumes vast amounts of processing power, resulting in severe performance degradation across employee workstations and virtual machines. This resource drain interrupts critical business applications and reduces overall productivity.
Inflated operational and energy costs: Continuous high CPU usage draws excessive power, causing overheating and driving up enterprise electricity bills. In cloud environments, unauthorized mining can trigger autoscaling features, leading to massive, unexpected cloud service fees.
Hardware degradation: Pushing hardware to its thermal limits accelerates wear and tear. Over time, this reduces the lifespan of enterprise devices and forces premature hardware replacements.
Gateway to severe cyberthreats: Cryptojacking signals a fundamental breakdown in perimeter and endpoint security. If cybercriminals can bypass defenses to install cryptojacking malware, threat actors can leverage that exact same access to deploy more destructive payloads, such as ransomware or data exfiltration Trojans.
How can organizations detect cryptojacking activity?
Organizations can detect cryptojacking by monitoring for persistent high CPU usage, investigating reports of device overheating, and analyzing outbound network traffic for connections to known mining pools. Because modern cryptomining code is programmed to throttle its resource consumption to evade detection, uncovering these attacks requires comprehensive endpoint and network visibility.
Endpoint performance monitoring: IT and security teams should investigate endpoints where the Task Manager or Activity Monitor shows unexplained CPU spikes, especially when no intensive applications are currently running on the device.
Network traffic analysis: Cryptojacking requires constant communication with external mining servers. Security teams can identify compromised assets by detecting DNS requests, unusual port activity, or TCP connections routed to known cryptomining domains.
Physical hardware symptoms: End users often report localized overheating, continuously running device cooling fans, or battery drain on laptops. These physical anomalies serve as early indicators of unauthorized processing activity.
Cloud billing alerts: Sudden, unexplainable spikes in cloud infrastructure billing often indicate that attackers have breached the environment and spun up rogue virtual machines specifically dedicated to cryptocurrency mining.
How can enterprises protect against cryptojacking?
Enterprises can prevent cryptojacking by deploying robust endpoint protection, filtering web traffic, blocking malicious scripts, and maintaining strict access controls over cloud infrastructure. Defending against stealthy cyberthreats requires a defense-in-depth strategy that addresses both host-based and browser-based attack vectors.
Script blocking and ad blockers: Deploying enterprise-managed browser policies or extensions that block unauthorized JavaScript code prevents drive-by browser-based cryptojacking and malvertising campaigns.
Web filtering: Utilizing a secure web gateway prevents users from navigating to compromised sites, communicating with known mining pools, or downloading malicious browser extensions.
Endpoint threat detection: Modern anti-malware and endpoint detection tools can identify the signatures and behavioral patterns of common mining software, such as XMRig, automatically terminating the offending processes.
Cloud posture management: Enforcing strict identity and access management policies ensures cybercriminals cannot hijack cloud services or exploit misconfigurations to spin up new instances for cryptomining.
Security awareness training: Educating employees to identify phishing emails, malicious ads, and social engineering tactics reduces the likelihood of initial malware infection.
How can enterprises protect against cryptojacking?
Enterprises can prevent cryptojacking by deploying robust endpoint protection, filtering web traffic, blocking malicious scripts, and maintaining strict access controls over cloud infrastructure. Defending against stealthy cyberthreats requires a defense-in-depth strategy that addresses both host-based and browser-based attack vectors.
Script blocking and ad blockers: Deploying enterprise-managed browser policies or extensions that block unauthorized JavaScript code prevents drive-by browser-based cryptojacking and malvertising campaigns.
Web filtering: Utilizing a secure web gateway prevents users from navigating to compromised sites, communicating with known mining pools, or downloading malicious browser extensions.
Endpoint threat detection: Modern anti-malware and endpoint detection tools can identify the signatures and behavioral patterns of common mining software, such as XMRig, automatically terminating the offending processes.
Cloud posture management: Enforcing strict identity and access management policies ensures cybercriminals cannot hijack cloud services or exploit misconfigurations to spin up new instances for cryptomining.
Security awareness training: Educating employees to identify phishing emails, malicious ads, and social engineering tactics reduces the likelihood of initial malware infection.
How Akamai can help
Akamai helps organizations stop cryptojacking by providing deep network visibility, blocking access to malicious domains, and segmenting workloads to prevent the lateral spread of malware. By securing the edge and the internal network, Akamai ensures that enterprise computing resources remain protected from unauthorized exploitation.
Akamai Secure Internet Access Enterprise protects enterprise users by proactively blocking access to malicious websites. This stops the execution of browser-based cryptomining scripts and prevents users from downloading host-based payloads via phishing attacks.
Akamai Guardicore Segmentation offers granular visibility into all network traffic, instantly identifying the unauthorized outbound connections to mining pools that characterize cryptojacking. By enforcing strict, software-defined microsegmentation, Akamai Guardicore Segmentation prevents attackers from moving laterally across on-premises and cloud infrastructure, isolating infected devices before they can infect the broader network.
Additionally, Akamai App & API Protector defends web properties against malicious code injection. This ensures that an organization’s public-facing assets are not compromised and turned into unwitting distributors for browser-based cryptojacking malware.