Analytics BIOC Medium

Suspicious heavy allocation of compute resources - possible mining activity

An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Impact (TA0040) Initial Access (TA0001)
ATT&CK techniques: Resource Hijacking (T1496) Valid Accounts (T1078)
Attacker's goals:

Leverage cloud compute resources to earn virtual currency.

Investigative actions:

Check the identity created resources and its legitimacy. Look for any unusual behavior originated from the suspected identity, and check if they're compromised, e.g. access key, service account, etc.

Test period:
N/A (single event)
Deduplication:
5 Days
3 variations:
  • Suspicious heavy allocation of compute resources - possible mining activity Low (parent: Medium)
  • Suspicious heavy allocation of compute resources - possible mining activity High (parent: Medium)
  • Suspicious heavy allocation of compute resources - possible mining activity Medium