Share this article

Report Finds Cryptojacking Instances Jumped 400% In A Year

A report by a group of cybersecurity researchers found that cryptojacking instances jumped more than 400 percent in a year.

Updated Sep 13, 2021, 8:24 a.m. Published Sep 21, 2018, 6:00 p.m.
mining

Instances of cryptojacking malware have jumped more than 400 percent since last year, a new report finds.

A collaborative group of cybersecurity researchers called the Cyber Threat Alliance (CTA) published the report Wednesday, detailing the various and repercussions from cryptojacking – the illicit practice of hijacking a user's computer to mine cryptocurrencies.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Most notably, CTA points out in the research that the number of instances of illicit mining malware found has sharply spiked in the months from the close of 2017 to end of July 2018.

The report states:

"Combined data from several CTA members shows a 459 percent increase in illicit cryptocurrency mining malware detections since 2017, and recent quarterly trend reports from CTA members show that this rapid growth shows no signs of slowing down."

In the key findings document, the alliance points to a particular exploit that has been plaguing the security world for over a year, Eternalblue, as one of the leading causes.

Eternalblue is the infamous NSA exploit that was used in the Wannacry ransomware and NotPetya attacks.

The CTA's analysis explains that a number of Windows operating systems remain vulnerable to the bug, despite a patch released by Microsoft. As such, these systems run a vulnerable network file sharing protocol dubbed SMB1.

Malicious actors target these susceptible machines for their processing power, which even simple cryptojacking software can hijack.

In fact, these actors have even begun repurposing existing software to specifically mine cryptocurrencies, the report said, explaining:

"Researchers noted in February 2018 that the BlackRuby Ransomware family began 'double dipping' by adding the open-source XMRig software to their tools to mine Monero. The VenusLocker Ransomware family completely shifted gears, dropping ransomware for Monero mining. The Mirai botnet, notable for its 2016 DDoS attack that used IoT devices to impact substantial portions of U.S. internet services, has since been repurposed into an IoT-mining botnet."

Further, by decreasing the mining rate, the malware can easily and cheaply be scaled across a network in large organizations and persist on the host computer for a longer time, resulting in a larger pay-out.

Palo Alto Networks, one the partners in the alliance, found that Coinhive dominates in terms of software used by malicious actors, with some 23,000 websites containing Coinhive source code.

Moreover, the group of security firms has noticed that malicious actors are shifting their focus from traditional systems and personal computers to Internet-of-Things devices like smart TVs.

The CTA also stressed that the presence of cryptojacking malware may just be an indicator of how insecure a system is, saying, "if miners can gain access to use the processing power of your networks, then you can be assured that more sophisticated actors may already have access."

Mining image via Shutterstock

Más para ti

Protocol Research: GoPlus Security

GP Basic Image

Lo que debes saber:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

Lebih untuk Anda

Traders mull the bottom as bitcoin returns to week's lows below $86,000

bart simpson sculpture (mendhak/Wikimedia Commons, modified by CoinDesk)

One analyst isn't quite ready to call a bottom, but says bitcoin is surely in an oversold condition.

Yang perlu diketahui:

  • Bitcoin's early rally Wednesday seems a faint memory as the price has returned to the week's lows.
  • Precious metals continue to get bid, with silver rushing to yet another new record and gold closing in on an all-time high.
  • One analyst cautioned against reading too much into the current bitcoin price action due to year-end positioning and tax considerations.