Skip to content
Threat Feed

Tag

Cryptomining

5 briefs RSS
high advisory

Detection of Newly Observed Processes with High CPU Usage

This detection capability monitors for unauthorized resource hijacking, such as cryptomining or exploit payload execution, by identifying new processes exhibiting sustained CPU usage above 90 percent.

impact resource-hijacking cryptomining detection-rule
1t
medium advisory

Detection of Security Alerts Correlated with High CPU Utilization

A cross-platform detection methodology correlates security alerts with processes exhibiting sustained high CPU utilization to identify potential resource abuse or post-compromise activity.

threat-detection impact system-monitoring resource-abuse cryptomining
1t
high advisory

AWS Potential Cryptomining via ECS Task Definition Deployment

Adversaries, after compromising AWS credentials, deploy cryptomining operations on Amazon ECS and AWS Fargate by registering task definitions with public high-CPU container images and then launching them, leading to unauthorized resource consumption and increased cloud costs.

Amazon ECS +1 cloud aws cryptomining resource-hijacking ecs fargate
1t 5i
high advisory

You do surprise me.exe: Unexpected Crypto-Miner in Hola Browser

Sophos X-Ops discovered that Hola Browser version 1.251.91.0 was distributed with an undeclared crypto-mining executable, me.exe, due to a supply chain compromise, leading to resource hijacking on affected Windows systems.

Hola Browser supply-chain-compromise cryptomining pua windows executable
3r 5t 4i
medium advisory

Unusual EC2 Instance Creation with Unseen Instance Type

An attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.

EC2 cloud anomaly cryptomining
2r 1t