Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a computer, server, container, or cloud account is mining cryptocurrency without your permission, treat it as a security incident—not just a performance problem. Check for suspicious compute use, unfamiliar processes and persistence, and unexpected cloud activity. Contain affected systems, preserve evidence, investigate connected identities and resources, then remove the miner or rebuild systems and tighten access controls.

What cryptojacking is—and what a warning sign can tell you

Cryptojacking is the unauthorized use of someone else’s computing resources to mine cryptocurrency. An attacker may compromise an account, start new cloud resources, install mining software, and use persistence or lateral movement to keep the operation running. MITRE ATT&CK classifies this activity as Compute Hijacking (T1496.001), with coverage across containers, IaaS, Linux, Windows, and macOS.

No single symptom proves that a device or account is compromised. High CPU or GPU use can have legitimate causes, and Microsoft notes that some coin-mining tools are classified as potentially unwanted applications rather than malware. Treat unexplained or sustained resource use as a reason to investigate alongside process, identity, network, and cloud activity.

Where to look for mining activity

Endpoint performance and resource use

Look for sustained or unexplained CPU or GPU utilization, heat, noisy fans, unusual battery drain, or sluggish interactive performance. Compare the change with what the device is expected to do: a temporary spike during a known workload is different from persistent heavy use while the computer is otherwise idle. Microsoft and Intel describe CPU telemetry and execution behavior as useful signals even when a cryptojacker is obfuscated or fileless.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Processes, binaries, and execution behavior

Review running processes and recently introduced binaries for unfamiliar miners, trojanized utilities, suspicious child processes, and signs of process injection. XMRig is one mining framework associated with trojanized variants documented by Microsoft, but its name alone does not establish malicious activity. Check whether the software and its parent process are expected, where they came from, and whether their behavior matches the stated purpose of the application.

Persistence and attempts to evade detection

Check for unexpected scheduled tasks, registry Run keys, startup-folder shortcuts, newly created services, process hollowing, and unauthorized antivirus exclusions. These mechanisms can allow a miner to return after a restart or avoid security controls. Microsoft’s 2026 campaign report describes these techniques and recommends endpoint detection and response (EDR) and attack-surface-reduction controls.

Cloud control plane, identities, and network activity

Review cloud audit and identity activity for unfamiliar logins, access from unexpected locations, unusual role or permission changes, and newly created resources. Pay particular attention to oversized or unexpected virtual machines, unfamiliar regions or instance types, sudden quota use, and mining-pool network connections. Microsoft reports that compromised accounts were commonly used to provision mining resources; AWS reported on November 2, 2025, that it had detected the beginning of a coordinated cryptomining campaign targeting customer EC2 and ECS environments through compromised IAM credentials.

Billing, quotas, and service availability

Compare cloud costs and resource consumption with expected workloads. Sudden cost increases, depleted quotas, reduced application capacity, or resource exhaustion can indicate that compute is being diverted. Microsoft warns that cloud cryptojacking can cause unexpected charges and service interruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to respond, in order

1. Contain the affected systems or account

Isolate suspected endpoints, virtual machines, or containers from the network where practical. For a suspected cloud compromise, contain the affected account or resources while keeping the response coordinated with the people responsible for business-critical services. CISA’s 2022 incident-response guidance says to “Immediately isolate affected systems.”

2. Preserve evidence before cleanup

Collect relevant logs and artifacts before deleting files, terminating resources, or making other destructive changes. When feasible, capture memory and forensic disk images. Record which systems and cloud resources are affected, what actions were taken, and when; that context can help establish scope and support a reliable recovery.

3. Scope the compromise

Investigate connected hosts, identity systems, privileged accounts, cloud audit logs, newly created resources, persistence mechanisms, and signs of lateral movement. Do not assume the visible miner is the entire incident: the same access may have been used to create other resources or reach other systems. CISA recommends investigating connected systems and, in suspected compromises, the domain controller.

4. Revoke exposed access

Disable or rotate exposed credentials, remove unauthorized keys and tokens, review IAM roles, and require multifactor authentication (MFA). Microsoft Incident Response reported in 2023 that nearly all of the cloud cryptojacking cases it investigated lacked MFA. Review access from a trusted administrative environment so that credentials used to investigate are not exposed to a compromised host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Remove the miner and restore trusted systems

After evidence is preserved and the scope is understood, eradicate the miner and its persistence mechanisms. If you cannot trust a system’s integrity, rebuild it from a known-good source rather than relying on cleanup alone. Restore only the access and services the system needs, then monitor for re-entry and abnormal resource use.

6. Escalate or report when appropriate

Bring in an incident-response provider if the compromise is complex, affects privileged identities or multiple systems, or cannot be confidently contained. Report qualifying incidents to CISA, the FBI, or the relevant national authority for your location.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the chance of another compromise

Protect identities and limit access

  • Require MFA, apply least privilege, and use separate identities for administration.
  • Review IAM roles, keys, and tokens regularly; remove access that is no longer needed.

Reduce endpoint and software exposure

  • Patch internet-facing software and remove unused remote-access paths.
  • Enable cloud-delivered endpoint protection, EDR block mode, network and web protection, and relevant attack-surface-reduction rules. Microsoft Defender Experts recommended these measures in its 2026 campaign report.
  • Monitor scheduled tasks, startup entries, services, registry autoruns, and antivirus exclusions for unauthorized changes.
  • Use browser reputation protections and train users to download utilities only from trusted vendor domains.

Put guardrails around cloud resources

  • Set budgets and quota alerts so unexpected usage is visible quickly.
  • Restrict permitted instance types and regions where your workloads allow it, and alert on unexpected resource creation.
  • Monitor IAM activity, new virtual machines and containers, and network traffic to mining pools.

Microsoft Defender Experts and Microsoft Security Research reported identifying more than 150 malicious domains since March 2026 in a campaign report. That figure describes domains identified by those teams during that period; it is not a count of all mining domains or a measure of the risk to any one organization.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.