Desktop Crypto Mining Malware Is Disappearing but Cloud Computing Exploits Are Growing

A new report suggests that cloud containers are the next target for mining malware.

AccessTimeIconJul 24, 2019 at 3:30 p.m. UTC
Updated Sep 13, 2021 at 11:13 a.m. UTC

A new report from Skybox Security suggests that desktop crypto mining malware popularity has fallen considerably this year but that cloud computing attacks - essentially attacks that create hundreds of infected computing containers online - has risen drastically in 2019.

"Use of malicious cryptominers — cybercriminals’ overwhelming tool of choice in 2018 — has declined to just 15 percent of malware attacks, with ransomware, botnets and backdoors rising to fill the void,” wrote the organization. “Vulnerabilities in cloud containers have increased by 46 percent compared to the same period in 2018 and by 240 percent compared to 2017.”

Crypto mining malware like “Nansh0u campaign” has infected tens of thousands of computers, forcing desktop computers to mine bitcoin and other cryptocurrencies via distributed control systems. This software focused on attacking healthcare, media, and IT companies and Guardicore Labs said that some software infected "700 new victims a day.”

The popular new attack vector, however, is cloud containers. These remote services powered by providers like Amazon and Google are often unattended and can be used to process the massive amounts of data needed to mine cryptocurrencies. What’s worse, hackers can replicate these containers instantly, creating a virtual army of zombie machines.

“Cloud technology and adoption has obviously skyrocketed, so it’s no surprise that vulnerabilities within cloud technology will increase,” said Marina Kidron of Skybox. “What is concerning, though, is that as these are published, the race is on for attackers to develop an exploit because launching a successful attack on a container could have much broader consequences. Compared to other technology, containers can be more numerous and quickly replicated. The attack footprint could expand rapidly, and number of victims may be extremely high.”

Unfortunately, vulnerabilities are growing. Skybox reported that companies will be “drowning in the vulnerability flood for some time.”

“More than 7,000 new vulnerabilities were discovered in the first half of 2019 — that’s still significantly more than figures we’d see for an entire year pre-2017,” the company wrote. Further, because these attacks cost compute cycles they can run up huge bills for victims, further adding financial injury to the attacks.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Read more about