itb-au logo
Story image

Five tips to defend against cryptojacking - Bitglass

28 Aug 2019

Article by Bitglass CTO Anurag Kahol

Cyber-criminals are using malware to steal computing power from various target devices in order to secretly mine cryptocurrency.

This escalating threat is known as cryptojacking.

Additionally, hackers may hijack enterprise IT resources in the cloud (such as AWS) for the same reasons - this is known, specifically, as cloud cryptojacking.

Although these forms of cryptojacking do not necessarily result in data loss, they do lead to stolen resources, a rise in power bills, and diminished productivity among employees whose infected devices have their performance impaired.

The incidence of cryptojacking has seen rapid growth and has emerged as a favourite strategy for hackers.

Notable victims have included Tesla and Drupal.

With cryptojacking becoming a go-to, low-risk way for cybercriminals to make money, it’s important for organisations to know how to spot it and, more importantly, how to stop it.

Here are five tips to do so:

1. Cybersecurity education

Cryptojacking tends to start with phishing emails.

When employees receive these dangerous messages and carelessly click the malicious links or attachments on offer, they unknowingly initiate a script on their devices, beginning the cryptojacking process.

Through IT security training, organisations can teach their employees to identify phishing attacks, reducing the likelihood of illegitimate links being clicked.

Training should also educate users on the consequences of successful phishing attacks, including cryptojacking, so they can understand the importance of remaining vigilant.

2. Ad-blocking and other tools

In addition to phishing, cryptojacking threats can be delivered through advertisements on the internet.

Fortunately, there are browser extensions that block popular cryptomining scripts.

Organisations should leverage extensions like AdBlock in order to reduce the likelihood of cryptocurrency mining that is initiated in this fashion.

3. Strong passwords and multi-factor authentication

As mentioned previously, cloud cryptojacking occurs when cybercriminals commandeer enterprise cloud resources and use them to mine for cryptocurrency.

Hackers constantly scour the internet for misconfigured cloud services, for example, those that do not require a password.

As such, organisations must ensure that they use sufficiently complex passwords as well as multi-factor authentication.

This will drastically reduce the likelihood of cybercriminals controlling cloud and IT assets – even if there is a credential leak.

4. Monitoring the cloud and the network

Cryptojacking burns through IT resources.

Accordingly, one of the simplest ways to identify this scourge is through consistent monitoring of all user and cloud activity.

IT teams should watch for significant changes in resource utilisation and check for unauthorised access to S3 buckets, a common attack vector in cloud cryptojacking schemes.

Similarly, IT teams should leverage network monitoring tools that can review web traffic and generate alerts when they encounter suspicious activities.

5. Adopt complete data security solutions

Cryptojacking is not solely a threat to desktops and laptops.

Mobile devices such as phones and tablets are also at risk. With more and more employees bringing their own devices to work (BYOD), extending security policies to mobile endpoints is critically important for enterprise security.

In light of this reality, agentless solutions have emerged as the tool of choice for BYOD security.

Agentless cloud access security brokers (CASBs) can govern access to data and monitor for threats like malware without requiring software to be installed on users’ personal devices.

This is immensely beneficial in the fight against cryptojacking.

Typically the cryptojacking threat does not cause obvious, catastrophic damage to the enterprise.

Like a parasite, it prefers that its host is kept alive.

However, cryptojacking is still a noteworthy consumer of enterprise resources.

As such, organisations must protect themselves through a mixture of security training, vigilance, and appropriate technology solutions.

In this way, they can significantly reduce the likelihood of cryptojacking impacting on their operations.

Link image
Who knew the catalyst for IT automation would be a pandemic?
COVID-19 broke traditional processes within organisations all over the world. But with every crisis comes opportunity - and now, there's no better time to begin your automation journey.More
Story image
Going back to work: Why we need to rethink enterprise ID cards
Australia and New Zealand are opening up again, and office workers are going back to their desks. Meanwhile, many companies still rely on outdated legacy card issuance systems, which offer little functionality or security assurances, and printing processes can be cumbersome.More
Link image
APAC CFOs share their secrets to customer experience success
We've collected the most common FAQs from CFOs in the Australia-Pacific region (along with client examples) to empower you with a return on investment model that will highlight the true impact of experience management.More
Story image
Closing the cloud skills gap: How certification can maximise cloud investments & keep staff happy
You probably wouldn’t buy an expensive computer program if you didn’t know how to use it. Yet so many organisations invest in costly cloud programs, without having the necessary skills and training on board to make the most of the program.More
Link image
Leave your legacy in the past & look to the future with cloud
With fundamental changes in the nature of the modern workplace, cloud is the obvious choice for providing a flexible cloud and communications environment.More
Story image
Aryaka and 8x8 partner for UC over SD-WAN
The expanded agreement will enable organisations to enhance cloud communications performance across the WAN for improved experience.More