# What is Cryptojacking?

> Cryptojacking is the unauthorized use of another party’s devices, accounts, or computing services to mine cryptocurrency.

- Canonical URL: https://yellowcube.eu/glossary/cryptojacking/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It may involve malware, browser-delivered code, compromised servers or containers, stolen cloud credentials, or abused automation. The defining issue is lack of authorization: cryptocurrency mining performed knowingly on owned or properly contracted resources is not cryptojacking.

The unauthorized workload consumes processor, graphics, memory, electricity, quotas, or paid cloud capacity and may degrade other services. Persistent campaigns can create or alter workloads and accounts, while browser-based mining may stop when a page closes. Some intrusions also contain credential theft, persistence, or proxying capabilities beyond mining.

### Key points

- **Possible signals:** Unexpected sustained resource use, new compute instances or containers, changed schedules, unknown mining processes, connections to mining infrastructure, thermal problems, or unexplained cloud charges warrant investigation.
- **Cloud and service review:** Examine identity events, management interfaces, deployment pipelines, images, regions, quotas, billing changes, and whether an authorized owner can explain the workload.
- **Response:** Stop unauthorized consumption safely, preserve evidence, revoke exposed access, remove persistence, identify the entry path, review related resources, and confirm that business workloads recover normally.
- **Important limitation:** High resource use or a connection to a mining pool is not proof of compromise. Conversely, efficient throttling, proxy infrastructure, short-lived jobs, or stolen cloud accounts can make cryptojacking inconspicuous; removing a miner alone does not establish that the intrusion is resolved.

### Related terms

[Malware](<https://yellowcube.eu/glossary/malware/>) · [Cloud workload protection platform (CWPP)](<https://yellowcube.eu/glossary/cloud-workload-protection-platform/>) · [Endpoint detection and response (EDR)](<https://yellowcube.eu/glossary/endpoint-detection-and-response/>) · [Cloud detection and response (CDR)](<https://yellowcube.eu/glossary/cloud-detection-and-response/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>)

### Sources

[MITRE ATT&CK T1496.001: Compute Hijacking](https://attack.mitre.org/techniques/T1496/001/) · [ENISA Threat Landscape: Cryptojacking](https://www.enisa.europa.eu/sites/default/files/publications/ETL2020%20-%20Cryptojacking%20A4.pdf) · [CISA NICCS Glossary: Cryptojacking](https://niccs.cisa.gov/about-niccs/glossary)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

