Cryptomining malware, or cryptojacking, is a type of malware that hides on a device and uses its computing resources to mine for valuable online currencies like Bitcoin. Cryptomining malware can cause performance issues, increased energy consumption, overheating, or hardware damage1 The analyst encountered cryptomining malware on the web server, as indicated by the following signs: The analyst was unable to log in remotely or on the console, as the malware blocked access to prevent detection or removal. The console messages showed that the server was running out of memory and CPU resources, as the malware consumed all available resources for mining. The network captures showed many packets with a signature of "Stratum", which is a protocol used for communication between miners and mining pools2 The best step for the analyst to take next is to reboot the server and disable any cron jobs or startup scripts that start the mining software. This can help stop the mining activity and restore access to the server. The analyst should also scan the server for any other traces of malware and remove them.