IT Forensics · Linux
Detecting cryptomining malware on Linux systems – providing forensic evidence of unauthorised resource usage
Cryptomining malware uses compromised Linux systems without authorisation to process cryptocurrency transactions, thereby causing characteristically high and sustained utilisation of system resources.
Such malware is often permanently embedded in the system using common persistence mechanisms such as cron jobs or systemd services, so that it automatically becomes active again even after a reboot.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We carry out targeted scans of systems for signs of cryptomining malware, identify associated processes, persistence mechanisms and network connections, and reconstruct the infection path as far as possible.
Typical areas of application
How a crypto-mining investigation works
Once the system has been secured, ongoing and historically verifiable processes are checked for typical crypto-mining patterns. Associated persistence mechanisms and network connections to known mining pools are identified, and the original route of infection is reconstructed using existing logs.
Why is the crypto-mining investigation of forensic relevance?
In addition to the immediate security risks, cryptomining malware also causes quantifiable financial damage through increased resource consumption, which can be forensically documented for the purpose of quantifying the damage.
As such malware is often used as part of a wider security breach, its detection may also indicate further, more serious breaches, which are investigated separately.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „detecting cryptomining malware on Linux systems"? LanCologne can assist you with the collection of digital evidence in a manner that stands up to legal scrutiny, as well as the transparent analysis of relevant Linux artefacts.
Related to this topic
- Forensic reconstruction of reverse shells – Forensic detection of outbound remote access by attackers
- Forensic analysis of Linux ransomware – reconstructing encryption attacks on Linux systems
- Forensic evidence of SSH brute-force attacks – Providing forensic evidence of systematic login attempts
- Proving privilege escalation through forensic analysis – reconstructing unauthorised expansion of privileges