Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Suspect cryptomining when sustained CPU or GPU use has no approved AI workload to explain it—especially if unfamiliar processes, mining-related DNS or network activity, or unauthorized cloud-account changes appear at the same time. No single high-utilization reading proves infection: compare activity with the server’s normal workload and correlate host, network, and cloud audit evidence.

What signs can indicate cryptomining?

Use the server’s own workload baseline as your reference. Training, inference, data loading, and GPU maintenance can all consume substantial resources; an unexplained deviation is more useful than any universal utilization threshold. AWS recommends watching for unusual CPU, network, or GPU usage spikes in its cryptomining guidance.

Compute use that does not fit the job schedule

Persistent CPU or GPU activity, elevated GPU temperature, or power use outside expected training and inference windows deserves investigation. A busy GPU during a scheduled training run may be normal; continued activity after the job ends is more concerning, particularly when workload logs do not account for it.

Unfamiliar processes or persistence

Look beyond a process name. Inspect executable path, owner, command line, parent process and lineage, launch time, and whether it is configured to start again through a service, scheduled task, container, or other startup mechanism. AWS GuardDuty runtime findings can identify binaries associated with mining activity and provide process and lineage context; see GuardDuty Runtime Monitoring finding types.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Unexpected DNS queries or outbound connections

Review DNS queries and network connections to unfamiliar destinations, including infrastructure associated with cryptocurrency mining. AWS documents cryptocurrency-related DNS and runtime findings, while Google Cloud recommends DNS logging and describes detections for known bad IP addresses and domains in its cryptomining detection guidance. Treat a match as a lead to investigate, not proof: indicators change, and one address or domain alone cannot establish compromise.

Cloud-account activity no one authorized

Check whether someone unexpectedly created compute resources, changed quotas, deployed GPU driver extensions, altered roles, or signed in from an unusual location or address. Microsoft’s account of cloud compute abuse identifies unexpected quota increases and suspicious GPU-extension deployment as useful signals in Azure environments: Microsoft Security Blog. An attacker using a legitimate tenant account can make actions look routine, so correlate control-plane and identity logs with what the server shows.

Security product alerts

Review enabled runtime, workload, DNS, and control-plane detections rather than assuming one security dashboard covers everything. AWS GuardDuty AI Protection documents coverage around AWS AI workloads and related suspicious activity; actual visibility depends on which features and plans are enabled. Google Cloud distinguishes events that may precede mining from findings indicating mining activity is underway.

How to investigate a suspicious AI server

  1. Compare activity with the workload baseline. Check current and historical CPU and GPU usage against the job schedule, workload logs, and comparable systems. Establish whether an approved training, inference, data-loading, or maintenance task explains the activity.
  2. Trace the processes using resources. Record process names, executable paths, owners, command lines, parent-child lineage, and launch times. Check persistence settings, containers, Kubernetes workloads, and the host as applicable.
  3. Correlate network evidence. Review DNS resolver logs, firewall or flow logs, endpoint telemetry, and security alerts together. Do not treat one IP address, domain, or product alert as a definitive finding.
  4. Verify cloud actions and identities. Examine audit logs for new instances or containers, GPU extensions, role changes, quota increases, unusual sign-ins, and credential use. Confirm each action maps to an approved operator or automation.
  5. Check whether the activity is authorized. Some environments intentionally perform cryptocurrency or blockchain work. AWS notes that cryptocurrency-related findings can be expected in those environments. Suppress alerts only for assets and activity that are known and authorized, following the guidance in GuardDuty Runtime Monitoring finding types.

What to do if you suspect compromise

Treat credible evidence of mining as a possible sign of broader access, not just an unwanted process. In a documented intrusion, CISA reported that actors installed XMRig on an unpatched server and then moved laterally, compromised credentials, and established persistence. Its advisory AA22-320A recommends promptly isolating affected systems, collecting and reviewing logs and artifacts, and capturing memory and forensic images before applying mitigations. It also advises investigating connected systems when lateral movement is suspected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Coordinate with your incident-response team or cloud provider and follow your organization’s evidence-handling procedures.
  • Preserve relevant logs and artifacts and capture memory or forensic images before making changes that could destroy evidence, when your response procedures call for it.
  • Investigate the initial access route, persistence, exposed or stolen credentials, unauthorized resources, and possible movement to other hosts.

Removing a miner or killing one process does not establish that the attacker is gone. Base containment and recovery on the incident-response plan and findings across the connected environment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What your monitoring should cover

Host metrics alone can miss activity in a container, Kubernetes cluster, AI service, or cloud account. When assessing visibility, check whether monitoring covers processes and runtime behavior, DNS and network traffic, cloud control-plane and identity logs, and containers or Kubernetes—and identify which features or plans must be enabled for each source.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.