Multiple supercomputers in some EU countries were hacked this week with crypto mining malware via compromised SSH credentials; evidence suggests a single actor
Confirmed infections have been reported in the UK, Germany, and Switzerland. Another suspected infection was reported in Spain.
Context & Ripple Effects
This is the third wave of a familiar monetization playbook climbing the hardware stack. The earlier rounds hit commodity infrastructure: an infected plugin that seeded crypto miners across 4,200+ government websites including USCourts.gov and NHS services, then 415K+ MikroTik routers worldwide compromised by CoinHive, Omine, and CoinImp. The Adylkuzz episode showed the same logic at scale — the NSA's EternalBlue exploit, later used in WannaCry, had already been deployed in a possibly larger hack purely to install a cryptocurrency miner.
What is new here is the target class and the entry vector: instead of exploiting unpatched software, the attacker used compromised SSH credentials to log into high-performance computing clusters in the UK, Germany, and Switzerland — with evidence pointing to a single actor, and a suspected related infection reported in Spain.
First-order effects
- The affected national supercomputing centers in the UK, Germany, and Switzerland must revoke credentials, rebuild compromised nodes, and idle workloads while forensics proceed — directly disrupting research compute capacity.
- A single-actor signature means every EU HPC site sharing similar SSH access patterns is now treating itself as potentially next in the same campaign.
Second-order effects
- Other European research centers are pushed toward credential-hygiene overhauls — key rotation, MFA on SSH, access auditing — because this intrusion needed no exploit, only stolen login material.
- The campaign validates crypto mining as a low-friction monetization path for intrusions into critical infrastructure, the same economics that drove the router and website waves, now applied to clusters whose entire value is raw compute.
Third-order effects
- If credential-based entry into shared research infrastructure becomes routine, HPC security consolidates around centralized identity and monitoring standards rather than per-site defenses — a structural shift for facilities that historically prioritized open academic access.
- The escalation path from websites to routers to national supercomputers suggests cryptojacking is becoming a persistent background tax on any under-defended compute layer, reinforcing arguments that states treat domestic compute as strategic infrastructure worth hardening.
The trend: Cryptojacking is migrating from consumer devices and websites up into national research infrastructure, with stolen credentials displacing software exploits as the preferred way in.