Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • If You Thought Ransomware was Big, Illegal Crypto-Mining May be Bigger current page
Link copied

If You Thought Ransomware was Big, Illegal Crypto-Mining May be Bigger

Feb 12, 2018
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
If You Thought Ransomware was Big, Illegal Crypto-Mining May be Bigger
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Crypto-mining

There has been an interesting trend if you follow the daily barrage of security breaches, malware, and other related incidents. Ransomware is still a threat and getting plenty of press, but there has been a recent uptick by threat actors using the same delivery mechanisms to deploy crypto-mining malware. Once installed on a target, it remains hidden mining for electronic currency instead of blatantly asking for a ransom and causing a disruption.

Why? Simply, if the malware can remain present and undetected, the threat actors can leverage your resources over a longer period of time and potentially make even more money at a lower risk than taking your system and data hostage. Since they are “just” stealing your computing power you may not even know, and in the end, they have compromised resources potentially all over the world to create crypto-mining farms. If you need proof of this trend, look at the following articles:

  • UK Government website offline after hack infects thousands more worldwide
  • Cyber Espionage Group Targets Asian Countries With Bitcoin Mining Malware
  • Adult content domains are home to half the sites using crypto-mining malware
  • Is your computer slow lately? It could be mining Monero (XMR)
  • Thousands of Government Websites Hacked to Mine Cryptocurrencies

This is an interesting new trend for 2018, and with the public hype over electronic currency, it is something that can easily create revenue for rogue nations or other sponsored threat actors. Of course, all these methods leverage vulnerabilities, exploits, social engineering, and other drive-by delivery methods already associated with other malware and threats. In order to stay protected, we need to keep our basic cybersecurity hygiene in check:

  • Ensure anti-virus solutions are installed and signatures are up to date to detect and prevent this malware
  • Remove end of life operating systems from your environment since they are no longer receiving security patches
  • Perform regular vulnerability assessment scans to identify at-risk devices and install security patches in a timely manger
  • Remove administrator rights from all workstations to prevent drive by malware
  • Educate users on the risks of social engineering and how to detect a phishing or spear phishing attacks
  • Leverage application control to mitigate illegal execution of applications within their environments

If we can keep these six items in pristine order from policy to operations within our organizations, the chances of becoming a host to crypto-mining malware can be minimized. Contact us today to schedule a strategy session.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Here's a Little Cybersecurity Trick I Learned to Keep Your Identity Secure
    Apr 10, 2018 Here's a Little Cybersecurity Trick I Learned to Keep Your Identity Secure
    Blog
    1m
  • CeX sees 2 million customer details compromised
    Oct 20, 2017 CeX sees 2 million customer details compromised
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.