Report says illicit cryptocurrency mining has surged 459% in 2018 YoY and that the spike is tied to the 2017 US government leak of hacking tool EternalBlue
- Cyber Threat Alliance releases report on cryptocurrency mining — Illicit cryptocurrency mining surged 459 percent in 2018
Context & Ripple Effects
The Cyber Threat Alliance's finding closes a loop that opened when researchers found EternalBlue — the NSA exploit behind WannaCry — had already been used in an earlier Adylkuzz campaign to install a cryptocurrency miner. The alliance's attribution matters because it names the leak itself, not just opportunistic hackers, as the supply chain for the 459% surge.
The report also quantifies a shift Symantec had flagged months earlier, when cryptojacking instances rose 8,500% in Q4 2017 on the back of easy-to-run mining apps. Together they show illicit mining moving from niche malware to industrial-scale exploitation of unpatched machines.
First-order effects
- Organizations running unpatched Windows machines face direct financial loss: their compute power is silently diverted to mining for attackers, with EternalBlue acting as the go-to entry tool across many victims.
- Cyber Threat Alliance member firms gain shared attribution intelligence, letting them detect and block EternalBlue-based mining campaigns faster than any single vendor could.
Second-order effects
- Security vendors are pushed to make cryptojacking detection a standard product feature rather than an afterthought, since Symantec's tracking shows the category growing fast enough to justify dedicated tooling.
- Attackers' preference for mining over data theft pressures privacy-focused coins like Monero — the currency a hacking group linked to North Korea chose when hijacking computers to mine roughly $25K worth — as the payout rail of choice for hijacked machines.
Third-order effects
- If leaked government exploit stockpiles keep seeding criminal campaigns, patching cadence becomes a structural cost of doing business for every organization, and the debate over whether agencies should disclose vulnerabilities intensifies.
- Illicit mining establishes itself as a lower-risk monetization model than ransomware or theft — no victim interaction, no payment trail — pointing toward a persistent baseline of hijacked compute even as headline-grabbing hacks like the $1.38B stolen in H1 2024 follow a different playbook.
The trend: Leaked state-grade exploits are turning illicit cryptocurrency mining into a commoditized, self-scaling criminal revenue stream built on unpatched machines.