Cybercriminals are increasingly hijacking enterprise systems and websites for cryptocurrency mining. Crowdstrike and other security vendors have recently reported incidents where businesses have suffered serious application – and operational – disruptions after attackers took over their systems to mine for Monero, and to a lesser extent, other digital currencies like Ethereum and Zcash. In many other instances, criminals are surreptitiously installing cryptominers on websites and hijacking systems belonging to people visiting the sites.
Unlike ransomware and other malware, cryptominers are often legitimate software tools that are not always detected by anti-malware products. Since the only thing they do is use a system’s CPU resources to crunch algorithms, cryptomining tools can sometime run invisibly without anyone detecting them. Many cryptomining tools deliberately throttle CPU and power usage so their presence on a system becomes even more unobtrusive. In fact, performance slowdowns often are the only indication that a computer has been hijacked for cryptocurrency mining.
Read about 7 of the best practices you should already be following to protect against cryptomining tools – and any malware, on DarkReading.