T1496 Resource Hijacking

Adversaries may leverage the resources of co-opted systems in order to solve resource intensive problems, which may impact system and/or hosted service availability.

One common purpose for Resource Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency. Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive.3 Servers and cloud-based systems are common targets because of the high potential for available resources, but user endpoint systems may also be compromised and used for Resource Hijacking and cryptocurrency mining.2 Containerized environments may also be targeted due to the ease of deployment via exposed APIs and the potential for scaling mining activities by deploying or compromising multiple containers within an environment or cluster.14

Additionally, some cryptocurrency mining malware identify then kill off processes for competing malware to ensure it’s not competing for resources.5

Adversaries may also use malware that leverages a system’s network bandwidth as part of a botnet in order to facilitate Network Denial of Service campaigns and/or to seed malicious torrents.6

Procedure Examples

ID Name Description
G0096 APT41 APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.15
G0108 Blue Mockingbird Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems.16
S0486 Bonadan Bonadan can download an additional module which has a cryptocurrency mining extension.13
S0492 CookieMiner CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency. 12
S0601 Hildegard Hildegard has used xmrig to mine cryptocurrency.1
S0434 Imminent Monitor Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.7
S0599 Kinsing Kinsing has created and run a Bitcoin cryptocurrency miner.89
S0451 LoudMiner LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.10
S0532 Lucifer Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero.14
G0106 Rocke Rocke has distributed cryptomining malware.1920
S0468 Skidmap Skidmap is a kernel-mode rootkit used for cryptocurrency mining.11
G0139 TeamTNT TeamTNT has deployed XMRig Docker images to mine cryptocurrency.1718


ID Data Source Data Component
DS0017 Command Command Execution
DS0022 File File Creation
DS0029 Network Traffic Network Connection Creation
DS0009 Process Process Creation
DS0013 Sensor Health Host Status


