Home / Companies / Modal / Blog / Post Details
Content Deep Dive

How to catch crypto miners using syscall signatures

Blog post from Modal

Post Details
Company
Date Published
Author
-
Word Count
1,504
Company Posts That Month
2
Language
English
Hacker News Points
7
Post removed?
No
Summary

Modal developed seccheck, a syscall-based runtime analysis system to detect and stop cryptomining abuse on its serverless GPU container platform, where fraudsters may use stolen payment information to occupy costly NVIDIA GPUs. Earlier metadata-based heuristics, such as checks on user profiles, IP addresses, and payment signals, remain a first defense but can produce false positives and are vulnerable to evasion. Because users can run arbitrary Linux code and download software at runtime, Modal rejected source, binary, and container-image analysis in favor of monitoring system calls, which reveal operational behaviors such as suspicious subprocess launches, file access, and network connections commonly associated with miners. Rather than use the slow ptrace-based approach employed by strace, Modal relies on gVisor’s existing syscall interception infrastructure to stream trace events through a socket to seccheck with limited overhead. The system evaluates selected syscall events, particularly execve calls, against detection rules, immediately terminates flagged containers, and links incidents to user accounts for potential bans; Modal reports no false positives so far and plans to expand rules, correlate sequences of calls, update blacklists, and potentially inspect GPU control activity.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 2 1,314 247 97 +26%
Serverless 1 602 128 75 +1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.