Cryptojacking accelerates to record levels in 2023, urging layered security strategies

The surge in cryptojacking attacks in 2023, with over a billion hits recorded, highlights the urgent need for comprehensive defence strategies to combat this clandestine cybercrime phenomenon.

Cryptojacking is a form of cybercrime in which attackers quietly use a victim’s processing power to mine cryptocurrency. According to CloudSEK’s guide and TechTarget, the code can arrive through malicious downloads, phishing links or compromised websites, then run in the background on computers, servers, mobile devices and cloud workloads without obvious warning signs. Unlike ransomware, it is designed to stay hidden while consuming computing resources for the attacker’s gain.

The impact is often financial as well as technical. CloudSEK says cryptojacking can drive sustained CPU or GPU use, slow applications, cause overheating and increase electricity costs. SonicWall’s 2024 Cyber Threat Report, as cited by CloudSEK, recorded 1.06 billion cryptojacking hits in 2023, a 659% rise from 2022 and the highest volume the company has tracked since 2018. That scale helps explain why security teams increasingly treat cryptojacking as an operational risk, not merely a nuisance.

Attackers usually follow a simple pattern: deliver the code, infect the system, execute the mining process and keep it persistent. CloudSEK notes that browser-based attacks can activate when a user opens a compromised site, while file-based attacks may arrive through downloads or email attachments. Common warning signs include unusually high resource use, sluggish performance, unexplained power draw, unknown background processes and browser slowdowns on specific pages. CoinMarketCap and TechTarget both say these symptoms are often the clearest indicators that a device is being used for unauthorised mining.

The most effective defences are layered. CloudSEK recommends keeping operating systems and applications patched, using antivirus and endpoint protection, blocking malicious websites and scripts, limiting browser extensions and monitoring CPU, GPU and memory use for abnormal spikes. Its guidance also stresses network monitoring, threat intelligence and tighter browser controls, particularly in cloud environments where exposed credentials or misconfigured workloads can be abused. In a separate report, Microsoft warned of a recent cryptojacking campaign that used SEO poisoning and AI chatbot recommendations to spread GPU-mining malware disguised as legitimate utilities, underlining how attackers increasingly rely on deception rather than brute-force compromise.

Research also suggests that no single browser extension or security tool is enough on its own. A recent arXiv study found that several Chromium-based extensions had limited success against cryptojacking-infected websites, which supports CloudSEK’s emphasis on layered protection rather than reliance on one blocker. In practice, that means combining patching, endpoint controls, web filtering, resource monitoring and external threat intelligence to reduce exposure across endpoints, browsers and cloud systems.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.