Cryptojacking was the first widespread attack whose primary symptom was an invoice. Through 2018 it became, by several measures, the most commonly detected malicious activity on enterprise networks — and it produced almost none of the things security programmes were built to look for. Nothing was encrypted. Nothing was exfiltrated. No extortion note arrived. The attacker's objective was simply to use your compute to mine cryptocurrency, and the ideal outcome from their point of view was that you never noticed. The economics made sense for the first time that year. Browser-based mining scripts — Coinhive being the best known, launched in late 2017 and eventually shut down in early 2019 — made it trivial to monetise someone else's processor through a compromised web page. Privacy-focused coins that could be mined effectively on general-purpose CPUs removed the need for specialised hardware. And cloud infrastructure provided something an attacker had never had before: an environment where compute capacity expands automatically and the cost lands on someone else's account. That combination reframed the threat. Cryptojacking is not really a malware problem. It is an unauthorised-usage problem, and the discipline it demands is closer to financial controls than to endpoint defence.
Why cloud made it worse
On a physical server, mining is bounded by the hardware you already own. The cost is a slower machine and a higher electricity bill. In the cloud, the same compromise has a different shape. Auto-scaling turns unauthorised compute into unbounded spend. A workload that mines aggressively looks, to a scaling policy, exactly like a workload under legitimate load — so the platform obligingly provisions more capacity, and the attacker's yield scales with your credit limit. Credentials are the real target. Access keys committed to public repositories, exposed metadata endpoints, and unauthenticated management interfaces gave attackers the ability to provision fresh capacity rather than merely borrow an existing instance. The best-documented case of the period involved an unsecured Kubernetes administration console at Tesla, reported by cloud security researchers in early 2018, where attackers used access to the orchestration layer to run mining containers — and took deliberate steps to stay quiet, including keeping CPU usage moderate and hiding traffic behind a proxy. Orchestration platforms became a favourite because they are designed to schedule workloads on demand. An exposed container API, an over-permissive service account or an unauthenticated dashboard is, functionally, a compute vending machine. And the detection surface is different. On a shared cloud platform, a modest increase in utilisation across many instances is invisible to any endpoint tool and visible only in the billing data — which is typically reviewed monthly, by finance, in aggregate.
The reason it matters more than the bill
It would be easy to treat cryptojacking as a cost problem and resolve it with a budget alert. That misses the point that made it genuinely important. Unauthorised mining is evidence of an access path. Whoever is mining in your environment got in somehow: a leaked key, an exposed interface, an unpatched server, a compromised container image, a malicious dependency. Mining is simply the least harmful thing they chose to do with that access. The same path supports data theft, ransomware or lateral movement, and the next occupant of that path may not be so considerate. Seen that way, a mining detection is a gift — a low-consequence signal of a high-consequence weakness. The correct response is not to kill the process and move on. It is to treat it as an intrusion, establish how the access was obtained, and close that route. There are secondary costs worth counting too: degraded performance on production systems, thermal and lifespan effects on hardware, wasted capacity that displaces real workloads, and reputational exposure where mining scripts were served to your customers from your own web properties.
Notice the change
Compare unexpected resource consumption with the expected workload.
Assign the investigation
Connect finance observations with security and a named service owner.
Trace access
Review credentials, exposed services and the activity behind the usage.
Verify the response
Check resource use and the access path after containment.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for Cloud Abuse Detection Review
- Treat cost anomaly detection as a security control, not a finance report. Alerts on unexpected spend or utilisation by account, region and service belong in the same queue as security alerts, with a same-day owner.
- Alert on activity in regions and services you do not use. Attackers routinely provision in unused regions precisely because nobody looks there; this is one of the highest-signal, lowest-effort detections available.
- Hunt for exposed management interfaces continuously. Unauthenticated container, orchestration and CI dashboards are the classic entry point, and they appear through configuration drift as often as through error.
- Scan repositories and build pipelines for credentials, and rotate on exposure. Leaked keys are the dominant cause of provisioning abuse rather than borrowed capacity.
- Cap and constrain scaling. Maximum instance counts, budget controls and hard limits per account turn an unbounded loss into a bounded one.
- Investigate every mining detection as an intrusion. Removing the miner without finding the access path leaves the door open for a worse tenant.
- Baseline normal utilisation per workload. Without a baseline, a sustained 30 per cent uplift is indistinguishable from business growth.
- Review third-party scripts on your public web properties. Injected mining code on customer-facing pages is both an abuse of your visitors and a signal that your content pipeline is compromised.
The Regional Angle
Three features of the regional environment make cloud abuse both more likely to happen and less likely to be noticed quickly. The first is who holds the cloud account. In a large share of Gulf organisations, infrastructure is provisioned and operated by a systems integrator or managed service provider, and the billing relationship sits with them. That arrangement dissolves exactly the control that detects cryptojacking fastest: the person who sees the invoice is not the person who would recognise the anomaly, and the invoice frequently arrives as a fixed managed-service charge with the underlying consumption detail aggregated away. The remedy is contractual and specific — require line-item consumption reporting by account, service and region, require that anomalies above a threshold be reported to you within a defined period, and establish who pays for unauthorised consumption, because that clause is almost never present and the dispute is unpleasant without it. The second is the pace of cloud adoption relative to cloud governance. Regional cloud regions arrived recently and were adopted quickly, frequently project by project, which has left many organisations with more accounts and subscriptions than they have an inventory for — shadow accounts created for a proof of concept, a marketing campaign or a departmental tool, some with payment cards attached and nobody monitoring them. Unowned accounts are where abuse persists longest. A simple reconciliation between the cloud provider's account list, the finance ledger and a named owner per account is among the highest-value exercises available here. The third is operational context. Fixed statutory deadlines — VAT filing, ZATCA clearance, WPS submission windows, customs declarations — mean performance degradation on shared infrastructure has a compliance consequence rather than merely an inconvenience one, and the regional working week and holiday pattern creates predictable low-attention windows: differing weekends, Ramadan hours, Eid and Hajj periods. Attackers do not need to know your calendar to benefit from it, and an alerting model that depends on someone noticing during business hours will be least effective when it matters most. One further specific worth naming. Where regional cloud capacity is priced above the largest global regions and residency requirements constrain you to it, the financial impact of unauthorised consumption is proportionally larger — and if a residency commitment is in play, an attacker provisioning capacity in a convenient foreign region has also, incidentally, created a compliance problem on top of a cost one.
The objection worth taking seriously
The strongest criticism is that cryptojacking received attention out of all proportion to its harm, and that it functioned mainly as a marketing opportunity for security vendors during a quiet period. The argument has real merit. Measured by actual loss, this was among the least damaging attack categories of its era. Most incidents cost a modest amount of compute, were resolved by terminating a process, and involved no data loss whatsoever. Browser-based mining in particular was closer to an abuse of advertising economics than to a security breach — and the market corrected it without much help from the security industry, as coin prices fell, mining difficulty rose, the best-known script provider shut down, and browsers and blockers began stripping the code. Meanwhile ransomware, business email compromise and credential theft were doing enormous quantified damage, and any hour spent on mining detection rather than on those was arguably misallocated. There is a fairer version of the objection too: for many organisations, the tooling purchased to detect cryptojacking was justified on a cost-avoidance case that never materialised, and the cloud cost anomalies that actually hurt them were self-inflicted — forgotten test environments, over-provisioned instances, unattached storage and untagged resources at a scale that dwarfed anything an attacker consumed. The counter is not that mining was dangerous but that the capability it forced organisations to build was the right one anyway. Cost anomaly detection, per-account ownership, scaling caps, credential hygiene and visibility into unused regions are all controls with value entirely independent of mining — they are the same controls that limit the damage of a compromised key used for anything else, and they happen to fix the self-inflicted waste as well. The defensible position is to keep the capability and drop the framing: do not run a cryptojacking programme, run a cloud usage accountability programme, and treat any unexplained consumption — malicious or merely wasteful — as a finding that needs an owner.
Common Questions
Is cryptojacking still a meaningful threat?
Browser-based mining largely collapsed with the economics and the browser countermeasures. Abuse of cloud and container infrastructure through exposed interfaces and leaked credentials did not, because the value is in the free capacity rather than in any particular coin.
How is it usually detected?
In practice, through cost and utilisation anomalies rather than malware alerts — which is why billing data belongs in the security monitoring stack. Activity in unused regions and unexpected instance types are the highest-signal indicators.
If we find mining, is removing it enough?
No. Mining proves someone had the access to run workloads in your environment. Find and close that path, rotate the credentials involved, and check what else was done with the same access.
Has AI changed the incentive to steal compute?
It has strengthened it considerably. GPU capacity is scarce, expensive and metered, which makes stolen accelerator time more valuable per hour than stolen CPU time ever was — and stolen model API credentials are now their own category, since an exposed key can be resold and consumed at a rate that produces a serious bill within days. Two practical consequences. Treat model API keys with the same discipline as cloud access keys: scoped, rotated, rate-limited, budget-capped and monitored for usage patterns rather than merely for validity. And extend cost anomaly detection to inference spend, because it is a new consumption line that most organisations have not baselined and cannot yet distinguish from legitimate growth. The underlying lesson is unchanged: unexplained consumption is a security signal, and the only reason it ever gets noticed is that someone owns the bill.
Cloud Abuse Detection Review — put billing anomalies in the security queue, give every account an owner, and treat any miner you find as proof of an open door.
