Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
What's Hot

New SIMD-0675 Proposal Aims to Streamline Block Production

October 3, 2026

New SEC crypto rules threaten small advisers, but big firms win

October 3, 2026

Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

October 3, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

    October 3, 2026

    Bank group sues U.S. regulator over granting crypto trust charters

    October 3, 2026

    When The Banks Don’t Work, Bitcoin Does: Report

    October 3, 2026

    Bitcoin clears $85K, but is ‘Uptober’ setting up a bull trap?

    October 3, 2026

    Ethereum: Why ETH faces October reversal risk after 70% Q3 rally

    October 3, 2026

    Why Did Blast Decide to Wind Down Its L2?

    October 2, 2026

    Bitcoin Q3 Strength Faces a Tougher Q4 Test

    October 1, 2026

    Ethereum beats Bitcoin by 42.71% in Q3 – Can ETH do it again?

    October 1, 2026

    Can NEAR crypto rebound? THESE metrics could decide what’s next

    October 3, 2026

    Polymath And CineCity Explore Regulated Tokenized Film Investment Platform

    October 3, 2026

    XLM price prediction – Why Stellar’s $0.21 rebound could trigger a 9% rally

    October 2, 2026

    XRP’s $1.54 breakout test meets Ripple’s 1B token unlock – Can demand absorb supply?

    October 2, 2026

    Thinking Cat Gains Momentum After CASHCAT’s Breakout

    August 12, 2026

    What Tokens Could He Target?

    July 30, 2026

    The Next Meme Coin Winner Could Be Determined by Incentives, Not Memes

    July 30, 2026

    Why Is BOME’s Price Up Today? Finally, Capital Rotating to the Meme Coins?

    July 28, 2026

    New SIMD-0675 Proposal Aims to Streamline Block Production

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

    October 3, 2026

    Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

    October 3, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    New SIMD-0675 Proposal Aims to Streamline Block Production

    October 3, 2026

    State Street Fund Goes Live on Stellar

    October 3, 2026

    Blockchains Unlock an Explosion of New Markets

    October 3, 2026

    Cloak Launches Payroll Feature for Private Onchain

    October 2, 2026

    Masked Robbers Threaten Pregnant Wife in UK Crypto Home Attack

    October 3, 2026

    Bitcoin Lightning Nodes Targeted as Core Lightning Sounds Alarm

    October 2, 2026

    The $459,000 Bot Hacker Was a Customer First, Researchers Say

    October 2, 2026

    Metamask Pulls Validators as Meager ETH Theft Sounds Big Alarm

    October 2, 2026

    New SIMD-0675 Proposal Aims to Streamline Block Production

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

    October 3, 2026

    Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

    October 3, 2026
  • Web 3
    1. Gaming
    2. View All

    Top 12 NFT games every player should know about in August 2026

    September 22, 2026

    GameShame Studios founder details Raijin Protocol’s roadmap in NeoPod’s sixth AMA

    September 22, 2026

    Proof of Play to shut down after blockchain gaming thesis falls short

    September 22, 2026

    How BC.GAME is turning players into stakeholders

    September 22, 2026

    New SIMD-0675 Proposal Aims to Streamline Block Production

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

    October 3, 2026

    Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

    October 3, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

    October 3, 2026

    Tax on Bitcoin Gains? Dutch Government to Introduce Capital Gains Tax From 2028

    October 3, 2026

    Bitwise CIO says Clarity Act failure gave crypto ‘better rules faster’

    October 3, 2026

    Stablecoin issuers have replaced 40% of China’s lost US Treasury demand

    October 3, 2026

    Bitcoin’s $113,000 case strengthens as US regulators push 9 crypto actions

    October 2, 2026

    Bitget restores $300M fund after absorbing $388M security breach

    October 2, 2026

    Ripple’s biggest institutional bet may now be Brazil

    October 1, 2026

    New SIMD-0675 Proposal Aims to Streamline Block Production

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

    October 3, 2026

    Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

    October 3, 2026
  • Analysis

    Bull Market Targets for BTC, ETH, SOL, and XRP

    October 3, 2026

    Ethereum Price Faces A Critical $0.040 ETH/BTC Test

    October 2, 2026

    AAVE Price Surges 8% as Whale Activity Spikes — Can AAVE Break $200?

    October 2, 2026

    PropAMMs lower Solana trade costs, and public pool returns crash

    October 2, 2026

    Wall Street arrived in NEAR just as a $4 billion-a-month app got hacked

    October 2, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Robinhood Chain? The Ethereum Layer-2 Network for Tokenized Stocks

    July 12, 2026

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    Coinbase completes Deribit migration, ends INTX trading

    October 2, 2026

    Binance Funding Account ends direct crypto deposits

    October 1, 2026

    Coinbase just completed its US derivatives stack but its biggest bet still sits outside it

    September 30, 2026

    Bitget had 30 minutes to contain its hack before $290 million started moving

    September 30, 2026

    New SIMD-0675 Proposal Aims to Streamline Block Production

    October 3, 2026

    New SEC crypto rules threaten small advisers, but big firms win

    October 3, 2026

    Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

    October 3, 2026

    Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

    October 3, 2026
  • Tools
    • Market Overview
    • Exchange Tool
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Crypto Jacking: What’s New in the World of Resource Hijacking?
Crypto Jacking: What’s New in the World of Resource Hijacking?
Security and Privacy

Crypto Jacking: What’s New in the World of Resource Hijacking?

October 24, 2025No Comments7 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Phil Muncaster discovers that a combination of surging crypto prices and the pandemic have given cyber-criminals a shot in the arm…

There was a time a few years ago when cryptojacking supplanted ransomware as the pre-eminent global cyber-threat. As detections of the latter slumped in 2018, incidents involving cryptocurrency mining malware surged on the back of a thriving digital currency market. Many commentators claimed this was a sign of things to come. Cryptojacking is easier to make money from because threat actors don’t need to extract payment directly from their victims – they simply add more compromised machines to ramp up mining capability. Or so the argument went.

Then came ransomware-as-a-service, affiliate groups and double extortion – driving a renaissance in ransomware that saw attacks soar 485% in 2020, as home workers and remote access infrastructure were remorselessly targeted during the pandemic. Yet cryptojacking never went away. In fact, it evolved in the intervening years to become something arguably even more prolific. So the question is, should CISOs really care if the only apparent impacts are higher energy bills and slightly slower servers?

Stealing Compute Power

Cryptojacking, on the face of it, has always seemed a lower-level threat than the likes of data breaches, banking Trojans, DDoS and of course, ransomware. At a very high level, it involves the unauthorized use of a victim’s computing power to mine for cryptocurrency in order to generate profits. A variety of coin mining malware has been designed to achieve these ends. Enterprise targets offer arguably the richest pickings in terms of processing and memory resources, although campaigns have been known to go for large numbers of lower-powered smart devices conscripted into coin mining botnets.

One thing is clear: it’s still a popular way to make money. CrowdStrike’s recent OverWatch report recorded a 100% year-on-year increase in detections of cryptojacking intrusions, which it puts down to a sharp rise in the value of digital currencies from late 2020. Skybox Security claims to have seen double the volume of cryptojacking malware in the first half of 2021 versus the previous year. Monero remains the most popular currency to target, as the mining requirements are much lower than those for Bitcoin and there’s no tracking of transactions.

See also  Formjacking Replaced Cryptojacking, Ransomware in 2018

What’s Changed Since 2018?

To an extent, the same techniques are being used to get coin-mining code onto victim systems today as they were when Infosecurity reported on cryptojacking three years ago. That means scripts embedded into web pages that automatically execute when users visit, or phishing tactics designed to trick users into installing the malware directly on their machines.

However, some actors are going to more extraordinary lengths to stay hidden, according to Nathaniel Quist, senior threat researcher at Palo Alto Networks’ Unit 42.

“Cryptojacking groups vary in sophistication and capability. Some groups, like those behind campaigns such as dbused, avalonsaber and opsec_x12 appear to use copied, stolen or patched-together code, which lends their operations to being easier to detect and prevent. Others such as TeamTNT, Lemon_Duck and WatchDog have elevated their cryptojacking operations to include near zero day, or 1-day, attacks against cloud infrastructure,” he explains to Infosecurity. 

“Cryptojacking groups vary in sophistication and capability”

“Lemon Duck has begun targeting cloud Microsoft Server instances that are vulnerable to ProxyLogon. WatchDog has included 32 unique remote code execution exploits within its cryptojacking malware, and TeamTNT has developed some of the first Kubernetes lateral movement attacks designed specifically to increase their mining operations. Each of these groups is considered to be technically proficient and a persistent threat.”

The pandemic has also unintentionally benefited cryptojackers. Although remote and hybrid workers aren’t being targeted directly, as enterprise resources offer more bang for the buck, the growing public cloud infrastructure needed to support them is targeted directly.

“The growing use of public cloud infrastructure as more users work remotely not only expands the attack surface of devices, but it also increases the management complexity and risk from shared cloud services,” CrowdStrike threat expert Scott Taschler tells Infosecurity.

“They’re facing new kinds of cyber-attacks. They’re accessing data and apps in the cloud, often from personal devices. They may not be protected by the security controls you’ve deployed across your network. Adversaries are looking to take advantage of any human error and misconfigurations from devices, and all lapses in IT hygiene increase the risk that a determined attacker will find a way to gain access.”

See also  SEC Charges Man With $42 Million Crypto Fraud Scheme

Unit 42’s Quist agrees that cloud environments have been the subject of mounting cryptojacking activity in recent months.

“We saw a rise in security incidents across nearly all industry verticals with retail, manufacturing and government leading the rest. This is significant as these three industries also saw the largest increase in the creation of cloud workloads during the same time, April to June 2021,” he argues.

Lisa Short, a professor at London Graduate School and co-founder of P&L Digital Edge, argues that SMEs may be particularly at risk today.

“Widespread use of third-party JavaScript is making it easier for cyber-criminals to infiltrate websites with client-side attacks. They are particularly effective at exploiting non-technical SME websites, often self-built with low security and snippets of code copy-and-pasted into editing software,” she tells Infosecurity.

“Obviously, the move to remote working and vertiginous rise in digital transformation by the 99% of the economy which are small businesses, has exposed a new vulnerability for exploitation by these hackers and cyber-criminals.”

Hitting Back and Shifting Left

Security experts have long sought to raise awareness about the potentially severe repercussions of a cryptojacking infection. Yes, the bad guys are ultimately ‘only’ stealing your compute power, and yes, there’s a relatively minimal regulatory risk from being compromised. However, there’s a genuine risk that an attacker may not stop there. With possible access to your networked machines, what’s to prevent them monetizing one step further by deploying ransomware or info-stealing malware, for example? As such, organizations should get a handle on mitigation. The good news is that well-understood industry best practices will go a long way to diffusing the threat.

See also  Taiwan’s new crypto law gives banks the first real stablecoin advantage

“Security teams must be able to identify an event and understand the attack vector, they must be able to stop an active breach and remediate systems quickly and they must learn from an attack and close security gaps”

“Security teams must be able to identify an event and understand the attack vector, they must be able to stop an active breach and remediate systems quickly and they must learn from an attack and close security gaps,” says CrowdStrike’s Taschler.

“As ever, organizations must always practice strong security hygiene: regularly patching vulnerable apps and operating systems, and protecting privileged user accounts. They need an endpoint protection platform so that they are able to prevent and detect all threats, including known and unknown malware, as well as identifying in-memory attacks.”

For Unit 42’s Quist, cloud-based next-gen firewalls are a great place to start to help detect malicious network traffic and malware targeting cloud environments. Nevertheless, organizations should also adopt and enforce industry standards such as CIS benchmarks, and more fundamentally, adopt a ‘shift-left’ security mindset, he adds.

“Embed cloud security directly into your code reviews and development pipeline by scanning for vulnerabilities and misconfigurations,” Quist argues. “The earlier development teams can find and remove security risks from their cloud architecture, the more secure the final production architecture will be.”

For Short, the very nature of cryptocurrencies may aid the work of investigators.

“We don’t talk enough about transparency and the evidentiary asset trails that blockchain affords to protect business assets rather than just to store and transfer value,” she concludes. “Bear in mind that all digital assets, not just crypto, have an evidentiary trail on a blockchain, so capturing the criminals and recovering assets is much easier.”

Crypto Hijacking Jacking Resource whats World
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

New SEC crypto rules threaten small advisers, but big firms win

October 3, 2026

Daines Unveils Crypto Tax Bill Pairing Payment Relief With Wash-Sale Rules

October 3, 2026

Masked Robbers Threaten Pregnant Wife in UK Crypto Home Attack

October 3, 2026

Can NEAR crypto rebound? THESE metrics could decide what’s next

October 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Kazakhstan eyes crypto future with national reserve

September 9, 2025

Blockchains Unlock an Explosion of New Markets

October 3, 2026

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

New SIMD-0675 Proposal Aims to Streamline Block Production

October 3, 2026

New SEC crypto rules threaten small advisers, but big firms win

October 3, 2026

Bitcoin Is Up, DeFi Is Recovering, So Why Doesn’t This Look Like a Bull Market Yet?

October 3, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.