Google Cloud adds cryptomining protection following widespread exploitation
In nearly all cases of compromised Google Cloud instances, cryptomining malware was installed within 22 seconds
Google Cloud has launched a new threat detection solution for Google Cloud Platform (GCP) specifically designed to tackle the mounting cases of cryptomining malware operating through compromised cloud instances.
Google Cloud said the Virtual Machine Threat Detection (VMTD) is a first-to-market solution from a major cloud provider, now available in public preview as an added security layer within Security Command Center (SCC) Premium.
Virtual machine-based computing accounts for a significant portion of businesses' operations running in the cloud and according to a November 2021 threat intelligence report from Google Cloud, cryptomining activity was observed in 86% of all compromised GCP instances, making it the leading issue affecting Google Cloud customers.
The time it took for attackers to install this financially-motivated malware was quick, too, with more than half of cases (58%) seeing malware installed within just 22 seconds of compromising the platform.
Google Cloud said in most cases, this was due to exploitation of poor customer security practices or vulnerable third-party software. Leveraging the power of cloud computing can improve the efficiency of cryptomining malware due to its scalable nature, potentially raising monthly cloud bills for businesses by a large sum.
"The economy of scale enabled by the cloud can help fundamentally change the way security is executed for any business operating in today’s threat landscape," said Timothy Peacock, product manager at Google Cloud. "As more companies adopt cloud technologies, security solutions built into cloud platforms help address emerging threats for more and more organisations.
RELATED RESOURCE
"VMTD is one of the ways we protect our Google Cloud Platform customers against growing attacks like coin mining, data exfiltration, and ransomware," he added.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Now available in public preview, VMTD detects cryptomining attacks but as it moves closer towards general availability, Google Cloud said customers can expect to see a steady release of new detective capabilities that will integrate with other parts of GCP.
Google Cloud said VMTD complements the existing threat detection capabilities supplied by the existing Event Threat Detection and Container Threat Detection products, providing cover for compute while the others services areas like Kubernetes, identity, managed services, networking, and API.
Agentless approach
Google Cloud's VMTD provides memory scanning for customers on an agentless basis, which means GCP users can expect a smaller performance impact, lowered operational burden, and a less-exposed attack surface.
This is unlike a traditional endpoint security model which involves running additional software inside virtual machines to gather signals and telemetry. Instead, Google Cloud said it 'instruments the hypervisor' - the underlying software that "orchestrates" its virtual machines - to include threat detection that's difficult to tamper with.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
‘Perfect’ Zero Trust is killing your mid-market productivitySponsored Security theory often collapses under real-world deadlines. It’s time for a more auditable, “human-centric” approach to privileged access management
-
Increased AI use means developers spend more time reviewing code than everNews While AI is improving productivity and efficiency, many developers are caught up in a vicious cycle of code reviews and bug hunting
-
Unlocking cloud valueWhitepaper The case for network modernization
-
How to secure employees, applications and networksWhitepaper Everywhere security
-
Protect and preserve your data from endpoint to infrastructureWhitepaper Achieve cyber resilience with help from a powerhouse partnership
-
Google Cloud acquires Israeli security startup SiemplifyNews The SOAR specialist has been described as "the missing piece" for Google's Chronicle platform
-

Kaspersky Endpoint Security Cloud Plus review: One security solution to rule them allReviews Kaspersky is easy to manage, good value and tough on malware
-
Challenging the rules of securityWhitepaper Protecting data and simplifying IT management with Chrome OS
-
Microsoft acquires security startup CloudKnoxNews The tech giant continues to expand its security portfolio to secure its own cloud services
-
Okta agrees to buy rival Auth0 for $6.5 billionNews The merger will see Okta’s cloud-based identity services and Auth0’s backend user management services combine