Hacker News new | ask | show | jobs
by bigiain 1581 days ago
It's a bit buried, but the article says:

"We want to detect traces of RandomX (the CPU-intensive mining function for Monero) running on a cluster. "

This isn't for "Has someone rooted my laptop and started mining Monero on it", this is for "Have any of the nodes in my cluster (of potentially thousands of machines) been rooted and had Monero miners dropped on them." Your comment about being pwned totally applies to your container orchestration or hypervisor though...