How to catch crypto miners using syscall signatures
Blog post from Modal
Modal developed seccheck, a syscall-based runtime analysis system to detect and stop cryptomining abuse on its serverless GPU container platform, where fraudsters may use stolen payment information to occupy costly NVIDIA GPUs. Earlier metadata-based heuristics, such as checks on user profiles, IP addresses, and payment signals, remain a first defense but can produce false positives and are vulnerable to evasion. Because users can run arbitrary Linux code and download software at runtime, Modal rejected source, binary, and container-image analysis in favor of monitoring system calls, which reveal operational behaviors such as suspicious subprocess launches, file access, and network connections commonly associated with miners. Rather than use the slow ptrace-based approach employed by strace, Modal relies on gVisor’s existing syscall interception infrastructure to stream trace events through a socket to seccheck with limited overhead. The system evaluates selected syscall events, particularly execve calls, against detection rules, immediately terminates flagged containers, and links incidents to user accounts for potential bans; Modal reports no false positives so far and plans to expand rules, correlate sequences of calls, update blacklists, and potentially inspect GPU control activity.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Observability | 2 | 1,314 | 247 | 97 | +26% |
| Serverless | 1 | 602 | 128 | 75 | +1% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.