📈 Get daily crypto insights that make you smarter about your money

Cryptojacking Attacks Surge 399% in First Half of 2023: SonicWall Report Reveals Shifting Threat Landscape

A mid-year threat report from cybersecurity firm SonicWall has revealed a staggering 399% increase in global cryptojacking volume during the first half of 2023, as threat actors pivot from traditional ransomware toward stealthier, lower-risk attack methods. The findings signal a fundamental shift in how cybercriminals operate in the cryptocurrency space, with significant implications for organizations of all sizes.

The Threat Landscape

The 2023 SonicWall Mid-Year Cyber Threat Report paints a complex picture of evolving cyber threats. While global ransomware attempts declined by 41% — the lowest first-half totals since 2020 — other attack vectors have surged dramatically. Cryptojacking volume reached record levels, with North America seeing a 345% increase and Europe experiencing an extraordinary 788% jump compared to the same period in 2022.

SonicWall researchers also observed increases in IoT malware (+37%) and encrypted threats (+22%). The company discovered 172,146 never-before-seen malware variants during the period, underscoring the rapid pace of threat evolution. Overall intrusion attempts climbed 21% year-over-year.

“The seemingly endless digital assault on enterprises, governments and global citizens is intensifying, and the threat landscape continues to expand,” said SonicWall President and CEO Bob VanKirk. The data suggests that increased law enforcement activity, heavy sanctions, and victims’ refusal to pay ransom demands have altered criminal behavior, pushing threat actors toward alternative revenue streams.

Core Principles

Cryptojacking — the unauthorized use of computing resources to mine cryptocurrency — has become attractive to threat actors for several key reasons. Unlike ransomware, cryptojacking operates silently, often going undetected for extended periods. The victim’s computing resources are hijacked to mine privacy coins like Monero, generating a steady stream of income for the attacker without requiring direct interaction with the victim.

SonicWall Vice President of Product Security Bobby Cornwell explained: “Bad actors are pivoting to lower-cost, less risky attack methods with potentially high returns, like cryptojacking.” The economics are compelling: minimal development costs, low risk of detection, no need for ransom negotiations, and a continuous revenue stream that scales with the number of compromised systems.

Tooling and Setup

Organizations looking to defend against cryptojacking should implement a multi-layered security approach. Network monitoring tools that detect unusual outbound traffic patterns are essential, as cryptojacking scripts communicate with mining pools through identifiable connection patterns. Endpoint detection and response (EDR) solutions can identify unauthorized mining processes running on individual machines.

Browser-based cryptojacking remains a significant vector, often delivered through compromised websites or malicious browser extensions. Organizations should enforce browser security policies, use content filtering to block known mining domains, and educate users about the risks of installing unverified browser extensions.

Cloud infrastructure is increasingly targeted, with attackers exploiting misconfigured containers and serverless functions to deploy mining operations at scale. Cloud security posture management tools and proper access controls are critical for organizations running workloads in public cloud environments.

Ongoing Vigilance

The SonicWall report warns that the decline in ransomware is likely temporary, with researchers anticipating a rebound in the second half of 2023. The combination of cryptojacking’s stealth and ransomware’s profitability creates a dual threat environment where organizations must defend against both simultaneous attack vectors.

Education and government sectors have been particularly hard hit, with opportunistic threat actors targeting institutions that often lack robust cybersecurity budgets. Financially motivated threat actors continue to search for the weakest points of entry with the lightest possible repercussions, limiting their risk while maximizing potential profits.

Final Takeaway

The 399% surge in cryptojacking is not a temporary anomaly — it represents a strategic shift by sophisticated threat actors toward attacks that are harder to detect and prosecute. With Bitcoin trading around $29,210 and Ethereum near $1,860 at the time of this report, the financial incentive for cryptocurrency-related cybercrime remains strong. Organizations must adapt their security strategies to address both the loud, disruptive threat of ransomware and the quiet, persistent threat of cryptojacking. The most dangerous attack is not the one that makes headlines — it is the one you never notice.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified cybersecurity professionals for your specific needs.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Cryptojacking Attacks Surge 399% in First Half of 2023: SonicWall Report Reveals Shifting Threat Landscape”

  1. 172,146 new malware variants discovered in 6 months. thats almost a thousand per day. AV software is fundamentally broken against that volume

  2. cryptojacking payout scales with how long you stay undetected. a single xmrig pod costs the victim hundreds in compute while generating pocket change for the attacker. asymmetry is brutal

  3. 788% jump in europe is nuts. my companys kubernetes cluster got hit last month, someone deployed a hidden xmrig container

    1. kubernetes clusters are the perfect target. most teams dont monitor resource usage closely enough to catch a single xmrig pod among hundreds

    2. we found a xmrig pod in our cluster last quarter. it was disguised as a metrics exporter. been running for 3 weeks before anyone noticed the CPU spike

      1. container_ghost_

        Yuki M. xmrig disguised as a metrics exporter is the classic pattern. if youre not scanning pod signatures youre paying for someone elses mining

        1. prometheus_grab_

          container_ghost_ xmrig as a prometheus exporter is genius level social engineering. who questions their metrics pod. brilliant and terrifying

    3. k8s_nightmare

      cpu_thief kubernetes clusters are basically free money for attackers. most teams cant even tell you how many pods they have running let alone catch one mining xmrig

  4. 788% in europe is bonkers. ransomware crews realized negotiating takes skill and opsec. cryptojacking is just set and forget on some underfunded k8s cluster

  5. Ransomware dropping 41% while cryptojacking surges makes perfect sense. Why deal with hostage negotiations when you can silently steal compute cycles?

    1. ransomware requires negotiation skills and OPSEC. cryptojacking is set-and-forget. the economics made this inevitable

      1. ransomware also requires cashing out, which exposes the attacker. cryptojacking mines directly to your wallet. the opsec advantage is massive

  6. 788% jump in Europe alone. most companies dont even monitor CPU baseline patterns so this goes undetected for months

  7. europe up 788 percent is bonkers. ransomware crews realized negotiating with victims is harder than just silently mining xmrig on someones k8s cluster

    1. cloud_bill_ the xmrig disguised as a prometheus exporter trick is so common now. had it happen to us twice last year. runtime monitoring is non-negotiable

      1. container_paranoia

        Bogdan M. we switched to falco for runtime detection. caught a cryptonight miner within hours. the old cillium setup never would have spotted it

    2. cloud_bill_ 172146 new variants in 6 months means signature based detection is dead. runtime monitoring is the only thing that catches novel payloads

  8. 788% jump in europe is insane. my SOC team caught a xmrig pod last month disguised as a prometheus exporter. ran for 2 weeks before anyone noticed the CPU allocation

    1. container_ghost_

      xmrig disguised as a prometheus exporter is nightmare fuel. anyone running k8s without admission controllers or runtime scanning is a sitting duck

    2. soc_team_lead we found one hidden in a fake calico daemon. naming malicious pods after legit k8s system components is getting sophisticated

  9. 788% jump in europe and my company still doesnt have runtime threat detection on our containers. some people never learn until they get the AWS bill

    1. burndown_chart

      Regina O. the AWS bill is usually what gives it away. a single m5.xlarge running xmrig costs like 130 a month and most teams dont notice until the invoice hits

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,256.00-1.5%ETH$2,412.70-2.1%SOL$99.80-3.2%BNB$681.03-1.4%XRP$1.35-2.2%ADA$0.1956-1.5%DOGE$0.0815-1.6%DOT$0.8648+3.4%AVAX$7.19-0.4%LINK$11.18-1.3%UNI$5.84+12.3%ATOM$1.46-0.7%LTC$49.50+2.0%ARB$0.1089+0.3%NEAR$1.89-0.9%FIL$0.7648+12.4%SUI$0.7197-0.8%BTC$77,256.00-1.5%ETH$2,412.70-2.1%SOL$99.80-3.2%BNB$681.03-1.4%XRP$1.35-2.2%ADA$0.1956-1.5%DOGE$0.0815-1.6%DOT$0.8648+3.4%AVAX$7.19-0.4%LINK$11.18-1.3%UNI$5.84+12.3%ATOM$1.46-0.7%LTC$49.50+2.0%ARB$0.1089+0.3%NEAR$1.89-0.9%FIL$0.7648+12.4%SUI$0.7197-0.8%
Scroll to Top