It may involve malware, browser-delivered code, compromised servers or containers, stolen cloud credentials, or abused automation. The defining issue is lack of authorization: cryptocurrency mining performed knowingly on owned or properly contracted resources is not cryptojacking.
The unauthorized workload consumes processor, graphics, memory, electricity, quotas, or paid cloud capacity and may degrade other services. Persistent campaigns can create or alter workloads and accounts, while browser-based mining may stop when a page closes. Some intrusions also contain credential theft, persistence, or proxying capabilities beyond mining.
Key points
Possible signalsUnexpected sustained resource use, new compute instances or containers, changed schedules, unknown mining processes, connections to mining infrastructure, thermal problems, or unexplained cloud charges warrant investigation.
Cloud and service reviewExamine identity events, management interfaces, deployment pipelines, images, regions, quotas, billing changes, and whether an authorized owner can explain the workload.
ResponseStop unauthorized consumption safely, preserve evidence, revoke exposed access, remove persistence, identify the entry path, review related resources, and confirm that business workloads recover normally.
Important limitationHigh resource use or a connection to a mining pool is not proof of compromise. Conversely, efficient throttling, proxy infrastructure, short-lived jobs, or stolen cloud accounts can make cryptojacking inconspicuous; removing a miner alone does not establish that the intrusion is resolved.