{"id":47415,"date":"2022-07-07T00:00:00","date_gmt":"2022-07-07T00:00:00","guid":{"rendered":"urn:uuid:4863dad5-781a-7215-2023-d766b28095a4"},"modified":"2022-07-07T00:00:00","modified_gmt":"2022-07-07T00:00:00","slug":"unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/","title":{"rendered":"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/cryptomineTN.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/cryptomineTN.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"36.273291925466\">\n<div readability=\"17.888198757764\">\n<p>In this section, we cover how malicious actors are leveraging Windows runners in their attempts to mine cryptocurrency, as well as the persistence techniques they use to dodge detection by GitHub to prevent their Actions from being disabled. GitHub provides the runner, a server designed to run workflows (aka Actions). Workflows are deployed on Azure and terminated after an enterprise\u2019s automation is completed. While this service has its limits, users do not pay anything to use it, even with a free GitHub account.&nbsp;<\/p>\n<p>Figure 2 (retrieved <a href=\"https:\/\/github.com\/limoain14\/Langs\/blob\/main\/.github\/workflows\/main.yml\" target=\"_blank\" rel=\"noopener\">here<\/a>) shows one of the many YAML scripts we found while analyzing hundreds of repositories on GitHub:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"30.512578616352\">\n<div readability=\"6.8899371069182\">\n<p>We unpack this workflow YAML to better understand the process involved here: &nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Lines 1 and 2.<\/b> The malicious actors set a trigger for GitHub Actions workflow called \u201cCI\/CD\u201d to commence upon any push or pull request events. This means the workflow begins when you push a commit or tag, or when changes are made to a pull request in a repository.&nbsp;&nbsp;<br \/><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 3 to 6.<\/b> The workflow is running only one job called \u201cCI\u201d and named \u201cRun Tests\u201d using the latest version of the Windows runner provided by GitHub inside Azure. More details on the technical specifications of this GitHub-hosted runner can be found <a href=\"https:\/\/docs.github.com\/en\/actions\/using-github-hosted-runners\/about-github-hosted-runners\" target=\"_blank\" rel=\"noopener\">here<\/a>. &nbsp;&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 7 to 12.<\/b> This part uses a multidimensional matrix strategy to create multiple job runs at the same time. The <a href=\"https:\/\/docs.github.com\/en\/actions\/using-jobs\/using-a-matrix-for-your-jobs\" target=\"_blank\" rel=\"noopener\">GitHub official documentation<\/a> provides more details on how to use a matrix for your jobs. The maximum number of concurrent jobs is set to 50 with the max parallel directive on line 8. This allows the malicious actors to make the most out of the servers so that they can mine cryptocurrency before their incursions are discovered and shut down. Malicious actors define how the Action will handle job failures on line 9. By default, fail-fast is set to true, which means that it will cancel any other jobs, whether in progress or queued, should any of the other jobs in the matrix fail. On the other hand, attackers will set the fail-fast to false since they do not want any of the jobs to fail, and so that other jobs continue running despite failures occurring in&nbsp;others that are running in parallel. The next step is defining&nbsp;the matrix itself, used only to set the number of concurrent jobs. This is set to 60 in this case. Based on the number of entries on each directive, the total number of jobs in this two-dimensional matrix is 60 (from 6 x 10 = 60). This, however, doesn\u2019t make sense since we saw earlier that the attackers set the max parallel to 50 jobs, implying a possible mistake in their calculation.&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 13 to 23. <\/b>The steps being executed by the job are stated during each run. The first one, named \u201cCheckout,\u201d uses a third-party action provided by GitHub to check out the current repository inside the runner before doing anything. The code for this action can be found <a href=\"https:\/\/github.com\/actions\/checkout\">here<\/a>. The second step, starting on line 16, is called sad-path (retry_wait_seconds). This also runs another third-party GHA that now belongs to a regular GitHub user. It retries a GHA step on failure or timeout. The code for this action can be found <a href=\"https:\/\/github.com\/nick-fields\/retry\" target=\"_blank\" rel=\"noopener\">here<\/a>. Lines 19 to 23 set the details to retry the step to run the cryptocurrency miner binary by waiting for 15 seconds before the retry and only attempting to retry it twice before failing the step or after a timeout of 10 minutes. The retry GHA description can be found <a href=\"https:\/\/github.com\/nick-fields\/retry\" target=\"_blank\" rel=\"noopener\">here<\/a>. The continue-on-error command guarantees that the job exits successfully even if an error occurs.<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>There was another Portable Executable (PE) binary inside the repository named lang.exe, but it wasn\u2019t being used by GitHub Actions. Nonetheless, we analyzed it and found that it was another cryptocurrency miner, only with fewer detections according to VT.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"30.642857142857\">\n<div readability=\"10.214285714286\">\n<p>This next repository we analyzed was published on GitHub&nbsp;in April 2022. Similar variations of the same GHA script can be found from different users. Figure 6 shows the GHA workflow script labeled as kapten_crypto, (retrieved&nbsp;<a href=\"https:\/\/github.com\/Hffffhujft\/hahsy\/blob\/main\/.github\/workflows\/main.yml\" target=\"_blank\" rel=\"noopener\">here)<\/a>. This is set to be manually triggered with the <a href=\"https:\/\/docs.github.com\/en\/actions\/using-workflows\/events-that-trigger-workflows#workflow_dispatch\" target=\"_blank\" rel=\"noopener\">workflow dispatch<\/a> directive.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<p>Looking at the repository structure, we can clearly see how it shows that the user does not understand GitHub Actions very well, having created the GHA YAML in different locations with different names and extensions. We saw that the worflows file on the repository root as well as the one found on .GitHub\/workflows and .github\/Workflows were all the same. Someone familiar with GHA would know that the workflow scripts should be placed under .github\/workflows inside the root directory and with their YAML\/YML extension for the scripts to work. Workflows with \u201cW\u201d in uppercase are also accepted, but it is important to remember adding \u201cS\u201d at the end.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.656993805021\">\n<div readability=\"25.870231496576\">\n<p>Going back to the GHA script on Figure 6, we can see a few similarities with the previous one we just analyzed. It uses the multidimensional matrix strategy that sets the max parallel jobs to 5 and disables the fail-fast approach by setting it to false on lines 7 to 12. It creates an environment variable, NUM_JOBS, and sets it to 20. Then it creates each job by labeling them using the matrix parameters on lines 13 to 15. After that, it has three main steps: download, extract, and run. &nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Download (lines 17 and 18).<\/b> This uses the <a href=\"https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/microsoft.powershell.utility\/invoke-webrequest?view=powershell-7.2\">Invoke-WebRequest PowerShell command<\/a> to download the XMRig Windows binary from its GitHub repository.&nbsp;&nbsp;<br \/><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Extract (lines 19 and 20).<\/b> The next step also uses a PowerShell command called <a href=\"https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/microsoft.powershell.archive\/expand-archive?view=powershell-7.2\">Expand-Archive<\/a> to extract the files from the zip.&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Run (lines 21 and 22).<\/b> The last step is to run the xmrig.exe binary with a few parameters such as the URL of the mining server (-o), the mining algorithm (-a), and the user (-u), among others. A more detailed reference of the command-line options can be found <a href=\"https:\/\/xmrig.com\/docs\/miner\/command-line-options\" target=\"_blank\" rel=\"noopener\">here<\/a>.&nbsp;<\/span><\/li>\n<\/ul>\n<p>The following list of repositories shows similar versions of this same script. After cross-referencing the usernames or wallet addresses, we were able to identify that different GitHub users were using the same wallet, suggesting that they are either the same person or a group working together as a pool. &nbsp;<\/p>\n<p><span class=\"body-subhead-title\">Cryptocurrency miners that abuse Linux runners<\/span><\/p>\n<p>Linux and Windows runners are hosted on <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-machines\/dv2-dsv2-series\" target=\"_blank\" rel=\"noopener\">Standard_DS2_v2 virtual machines<\/a> on Azure. Both have two vCPUs and 7 GB of memory, according to the <a href=\"https:\/\/docs.github.com\/en\/actions\/using-github-hosted-runners\/about-github-hosted-runners\" target=\"_blank\" rel=\"noopener\">GitHub documentation<\/a>. Upon discussion with some fellow professionals and legitimate cryptocurrency miners, and considering that these runners are not GPU-based, we can assume that it is more profitable for the cybercriminals to leverage the Linux runners instead of the Windows ones. But without any direct comparison, one cannot say for certain why some choose the Windows runners if that were the case.<\/p>\n<p>Cryptocurrency miners that abuse the Linux runners follow an approach that resembles the one that cybercriminals use to exploit Windows runners to start and run their mining scripts as shown in the following image (retrieved <a href=\"https:\/\/github.com\/jaknan\/pg\/blob\/main\/.github\/workflows\/main.yml\" target=\"_blank\" rel=\"noopener\">here<\/a>).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.887187751813\">\n<div readability=\"14.951651893634\">\n<p>For our purpose, we focus only on the code that is relevant to performing the mining steps: &nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Lines 32-33.<\/b> The script does exactly what the step describes \u2014 it downloads the XMRig binary inside the runner from the GitHub repository.&nbsp;<br \/><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 35-36.<\/b> The script extracts all *.gz files in the current folder. It will only extract the XMRig files present in that folder.&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 38-41<\/b>. This step runs two basic Linux commands (pwd and ls) to show the current directory and list the files. However, we think this is a needless step at this stage. &nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 43-50<\/b>. This command starts the mining process by running the XMRig binary with the proper parameters such as the mining pool, the user, setting keepalive, and enabling TLS.&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Lines 53-54<\/b>. This is essentially the same command from line 50, which doesn\u2019t make much sense unless you know that the previous command failed, and you are running it again. But since there are no checks, we think that this command is redundant.&nbsp;<\/span><\/li>\n<\/ul>\n<p>Fortunately, this GitHub Action, along with many others analyzed and reported in this article, has already been flagged and disabled by GitHub. We can see this by going to the Actions tab inside the repository and noting the alert in Figure 9 (retrieved <a href=\"https:\/\/github.com\/jaknan\/pg\/actions\">here<\/a>):&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"44.608073744437\">\n<div readability=\"36.453909726637\">\n<p>As we saw in the mining scripts on Figure 9&nbsp;and in several <a href=\"https:\/\/documents.trendmicro.com\/assets\/white_papers\/wp-navigating-the-landscape-of-cloud-based-cryptocurrency-mining.pdf\" target=\"_blank\" rel=\"noopener\">attacks reported<\/a> in the past, malicious actors prefer to leverage Monero as their cryptocurrency of choice since Monero CPU-based mining done at scale provides a decent ROI. They therefore deem it a worthwhile endeavor to compromise a significant number of systems and subsequently integrate them into the mining pools&nbsp;<\/p>\n<p><span class=\"body-subhead-title\">Red flag: Is this something to be concerned about?&nbsp;<\/span><\/p>\n<p>For as long as the malicious actors only use their own accounts and repositories, end users should have no cause for worry. This is a problem GitHub is cognizant of and is trying to address and mitigate as much as possible. However, it&nbsp;is hard to eliminate the problem entirely. &nbsp;<\/p>\n<p>Problems arise when these GHAs are shared on GitHub Marketplace or used as a dependency for other Actions. As discussed in a <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/github-action-runners-analyzing-the-environment-and-security-in-action?utm_source=trendmicroresearch&amp;utm_medium=smk&amp;utm_campaign=0122_Github#C06\" target=\"_blank\" rel=\"noopener\">prior report<\/a>, anyone can create and share GHA on&nbsp;GitHub Marketplace. This is why it is recommended to exercise caution and discernment when choosing a shared GHA from Marketplace. We advise looking for the \u201cuses\u201d directive on your GHA YAML files, and for each , you can go to github.com\/username\/action to see its source code. For example, in Figure 2, on line 18, there is the nick-invision\/retry@v2, which as we previously showed, can be found at <a href=\"https:\/\/github.com\/nick-fields\/retry\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/nick-fields\/retry<\/a>.&nbsp;<\/p>\n<p>Users can also enhance the security of their Actions by going to Settings \u00e0 Actions inside each repository they own to apply proper settings such as Actions and workflow permissions, forked pull requests, and log retention expiration.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"53.415138816134\">\n<div class=\"responsive-table-wrap\" readability=\"52.925091671032\">\n<p><span class=\"body-subhead-title\">How to detect cryptocurrency miners&nbsp;<\/span><\/p>\n<p>The first indicator of a possible cryptocurrency mining exploit is an increased resource consumption. As resource consumption can spike CPU utilization to 100%, the presence of miners slows down workloads or applications that are running; these workloads or applications might even stop working altogether because of high CPU usage. Customers and CSPs should inspect such instances to determine any evidence of cryptocurrency mining. &nbsp;<\/p>\n<p>It is also advisable to keep an eye on your organization\u2019s cloud expenses. Since there is a notable increase in CPU usage, the cost resulting from workloads running at 100% CPU can increase by up to 600% with on-demand pricing, as we discuss in one of our <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/probing-the-activities-of-cloud-based-cryptocurrency-mining-groups\" target=\"_blank\" rel=\"noopener\">research <\/a><u>papers<\/u>. It\u2019s important to note that this can scale very quickly depending on the number of compromised workloads for the purpose of mining cryptocurrency. This is why any abrupt increase in your cloud monthly expenses should be investigated and treated with urgency and care. Keep in mind that threat actors are also putting thresholds on their miners to stay under the radar, as we\u2019ve demonstrated on Figure 3.&nbsp;<\/p>\n<p>Ultimately, we recommend that organizations regularly check and monitor their GitHub Actions for any signs of abuse, as early detection of possible exploits in your cloud environment is key. It is also important to ensure that none of the following known cryptocurrency-mining pools and servers and cryptocurrency wallets are present in your GHA:&nbsp;<\/p>\n<p><b>Mining pools\/servers<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">rx.unmineable.com&nbsp;<br \/><\/span><\/li>\n<li><span class=\"rte-red-bullet\">pool.hashvault.pro&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">xmrpool.eu&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sg.minexmr.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">pool.supportxmr.com<\/span><\/li>\n<\/ul>\n<p><b>Wallets<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">TRX:TD5jXT9qUPXZM9Ameqt15ttFD45PLhrCFn.TRUST&nbsp;<br \/><\/span><\/li>\n<li><span class=\"rte-red-bullet\">TRX:TM19JB5YG7KhqJ7L1rUASb1PqMDPNfkDF1.TRUS<\/span><\/li>\n<li><span class=\"rte-red-bullet\">TRX:TT97kccRg4C74kj9ugc4zP2e8t6GSCcTWH.worker2<\/span><\/li>\n<li><span class=\"rte-red-bullet\">TRX:TK6zMrH4pST5FbTen4XGBBa2rJckMojEnx.TRUST&nbsp;&nbsp;&nbsp; &nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">SHIB:0x94c35A97aa678e41700804FB0F409b3D66A075Dc.RIG1&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">SHIB:0x5aB7E2FDE0625d93842c0675BaEdcf9AA7a08c85.TRUST&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">LTC:MMtfXpcRZHAP9VpbjcGNhTUFW4rExdAVFv.RIZKI<\/span><\/li>\n<li><span class=\"rte-red-bullet\">BNB:0xa300949238f80ac9a6fa627eade4e81e4c73bea1.TOBY<\/span><\/li>\n<li><span class=\"rte-red-bullet\">SOL:uoXJ2QnaxJkVwNJrGGyyCiyGEhK27JyWHHMURUsfxWR.yu&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">44xyiky4qfr4X937HgbRv8A4QH2R7ynQSca4PWmBMqjffUbDv19F9DWgde51c6N6UZYi8rJP2AZNE95Jzo3eUWrnLnhFkba<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hvs1ZQN67XB2NqwT6Dd9qbR2S1cqrACvoPGEDJvAd1o83JEpEcVKWA17ScUWTnEqVYYad8zJurahHMF7E2ecpV7c1tQwRcfG4B&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">48waHbFYRVED3gLpqEwXvS4v4ppwLas1UHAwVD8n9mxvFegC39KTGQUTXMyimssFHiGqw491FFBYMdvbmBW9m4KXG5HitDV&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">43aw7X7kKLfb54rvM8nc3MU9ndKoZMnqXMfWaoYvPrJPfauj2uUQAb1hHRtVzvuPCJT9XMWhacQSV94ADZMxLjUDAinsVVY<\/span><\/li>\n<\/ul>\n<p><span class=\"rte-red-bullet\"><span class=\"body-subhead-title\">Trend Micro Solutions&nbsp;<\/span><\/span><\/p>\n<p>An ounce of prevention is always better than a pound of cure, which is why it is recommended to opt for security solutions that provide comprehensive protection for your system to keep this and other threats at bay. &nbsp;<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/services\/managed-xdr.html\" target=\"_blank\" rel=\"noopener\">Trend Micro Vision One<\/a>\u2122\u202fhelps security teams gain an overall view of attempts in ongoing campaigns by providing them with a correlated view of multiple layers such as email, endpoints, servers, and cloud workloads. Security teams can gain a broader perspective and a better understanding of attack attempts and detect suspicious behavior that would otherwise seem benign when viewed from a single layer alone.&nbsp;<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-workload-security.html\" target=\"_blank\" rel=\"noopener\">Trend Micro Cloud One\u2122 \u2013 Workload Security<\/a>\u202fhelps defend systems against vulnerability exploits, malware, and unauthorized change. It can protect a variety of environments such as virtual, physical, cloud, and containers. Using advanced techniques like machine learning (ML) and virtual patching, th<u>is<\/u>e solution can automatically secure new and existing workloads both against known and new threats.&nbsp;<\/p>\n<p><span class=\"body-subhead-title\">Indicators of Compromise (IOCs)<\/span><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"4\">\n<tr>\n<td><b>File Name<\/b><\/td>\n<td><b>SHA256<\/b><\/td>\n<td><b>Trend Micro Detection<\/b><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>lang.exe&nbsp;<\/td>\n<td>297a450166fef7fbbfe17b09884ef684eba83e658ef9eb8a1ef046a993ff1d65<\/td>\n<td>Coinminer.Win64.SRBMINER.A&nbsp;<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>node..exe&nbsp;<\/td>\n<td>495de38df3f28120934380d269d9c78cce52a98e8051a5dd671d3208a507f609<\/td>\n<td>Coinminer.Win64.MALXMR.SMA&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/g\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We investigate cloud-based cryptocurrency miners that leverage GitHub Actions and Azure virtual machines, including the cloud infrastructure and vulnerabilities that malicious actors exploit for easy monetary gain. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":47416,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9520,9555,9509],"class_list":["post-47415","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cloud","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-07-07T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/cryptomineTN.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines\",\"datePublished\":\"2022-07-07T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/\"},\"wordCount\":2286,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cloud\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/\",\"name\":\"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg\",\"datePublished\":\"2022-07-07T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/","og_locale":"en_US","og_type":"article","og_title":"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-07-07T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/cryptomineTN.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines","datePublished":"2022-07-07T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/"},"wordCount":2286,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cloud","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/","url":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/","name":"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg","datePublished":"2022-07-07T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines.jpg","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-actions-and-azure-virtual-machines\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=47415"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47415\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/47416"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=47415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=47415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=47415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}