Threat-Specific
Cryptominer Detection and Response
Guide for identifying cryptomining activity and removing mining malware from affected systems.
Threat-Specific · intermediate · 1-3 hours
Procedures for detecting and responding to cryptocurrency mining malware on systems.
Steps
5
01
Detection Confirmation
Verify cryptomining activity.
- Check for high CPU/GPU utilization alerts
- Look for known mining pool connections
- Identify suspicious processes with high resource usage
- Check for common cryptominer file names
02
Scope Assessment
Determine how widespread the infection is.
- Search for mining pool domains in proxy logs
- Scan for same file hashes across environment
- Check for lateral movement indicators
- Identify initial access vector
03
Containment
Stop the mining activity.
- Block mining pool domains and IPs at firewall
- Isolate heavily affected systems
- Kill mining processes if safe
04
Removal
Remove cryptominer malware.
- Identify and remove miner binaries
- Check for and remove persistence mechanisms
- Verify scheduled tasks and services
- Clean up any dropped tools
05
Root Cause Analysis
Determine how miners were deployed.
- Identify initial compromise vector
- Check for vulnerable applications or services
- Review recently exploited vulnerabilities
- Assess patching gaps
Checklist
- Mining activity confirmed
- Scope of infection determined
- Mining pools blocked
- Affected systems identified
- Miner processes killed
- Malware removed
- Persistence removed
- Root cause identified
- Patches applied if needed
- Incident documented
Evidence
- Process list showing miners
- Network logs to mining pools
- Malware samples
- CPU/GPU utilization data
- Initial access indicators