Compute Hijacking

T1496.001

Sub-technique of T1496 Resource Hijacking.View on attack.mitre.org

About this technique

Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

One common purpose for Compute Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency. Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive. Servers and cloud-based systems are common targets because of the high potential for available resources, but user endpoint systems may also be compromised and used for Compute Hijacking and cryptocurrency mining. Containerized environments may also be targeted due to the ease of deployment via exposed APIs and the potential for scaling mining activities by deploying or compromising multiple containers within an environment or cluster.

Additionally, some cryptocurrency mining malware identify then kill off processes for competing malware to ensure it’s not competing for resources.

Detection rules0

Rules on DetectionCode tagged with T1496.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software9

Campaigns1

Procedure examples14

Groups4

Used byProcedure example
GroupAPT41

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.

GroupBlue Mockingbird

Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems.

GroupRocke

Rocke has distributed cryptomining malware.

GroupTeamTNT

TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency.

Software9

Used byProcedure example
MalwareBonadan

Bonadan can download an additional module which has a cryptocurrency mining extension.

MalwareCookieMiner

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency.

MalwareDarkGate

DarkGate can deploy follow-on cryptocurrency mining payloads.

MalwareHildegard

Hildegard has used xmrig to mine cryptocurrency.

ToolImminent Monitor

Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.

MalwareKinsing

Kinsing has created and run a Bitcoin cryptocurrency miner.

MalwareLoudMiner

LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.

MalwareLucifer

Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero.

View all 9 software examples

Campaigns1

Used byProcedure example
CampaignShadowRay

During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining.

References5

  1. CloudSploit - Unused AWS Regions Open source
    CloudSploit. (2019, June 8). The Danger of Unused AWS Regions. Retrieved October 8, 2019.
  2. Kaspersky Lazarus Under The Hood Blog 2017 Open source
    GReAT. (2017, April 3). Lazarus Under the Hood. Retrieved April 17, 2019.
  3. Trend Micro Exposed Docker APIs Open source
    Oliveira, A. (2019, May 30). Infected Containers Target Docker via Exposed APIs. Retrieved April 6, 2021.
  4. Trend Micro War of Crypto Miners Open source
    Oliveira, A., Fiser, D. (2020, September 10). War of Linux Cryptocurrency Miners: A Battle for Resources. Retrieved April 6, 2021.
  5. Unit 42 Hildegard Malware Open source
    Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.