Hackers hijack millions of Android devices to secretly mine Monero.

in news •  7 years ago  (edited)

Hackers have been hijacking millions of Android devices over the past few months to secretly generate Monero coins. According to Malwarebytes researchers, the campaign was first spotted in January seems to have begun in November 2017.

In this malicious campaign,

  • The threat actors redirect unsuspecting mobile users to dubious pages set up to perform in-browser cryptomining by exploiting their device's processing power to generate Monero coins.

  • Visitors are presented with a CAPTCHA to solve to prove that they are human and not a bot.

  • "Your device is showing suspicious surfing behaviour. Please prove that you are human by solving the captcha. Until you verify yourself as human, your browser will mine the Cryptocurrency Monero for us in order to recover the server costs incurred by bot traffic," the warning message reads.

android-malware.png

  • Until users solve the CAPTCHA code, the site runs an exhaustive cryptojacking script that exploits the phone's CPU power to mine Monero - a process that could damage the device if left running long enough.

  • "Until the code (captcha) is entered and you press the Continue button, your phone or tablet will be mining Monero at full speed, maxing out the device's processor,"

  • Once they enter the code, users are simply redirected to the Google home page.

  • Researchers said victims may encounter this forced redirection during regular browsing sessions or via infected apps with malicious ads.

Five identical domains have been identified using the same CAPTCHA code but with different Coinhive site keys. At least two of them had over 30 million visits per month while the traffic combined from all five domains amounted to about

Over the past few months, experts have found a steady rise in malware-based miners, cryptojacking attacks,and browser-based cryptominers to ensure the processing power of millions of devices to mine digital currencies without the knowledge of device users.

Forced cryptomining is now also affecting mobile, tablets,computers not only via Trojanized apps, but also via redirects and pop-unders

More than 4,000 websites in the UK,USA, Australia and other nations were hacked by hackers tweaking the code of a plugin named "BrowseAloud" to secretly mine cryptocurrency.


Source:http://www.ibtimes.co.uk/hackers-hijack-millions-android-devices-secretly-mine-monero-drive-by-cryptomining-scheme-1660847

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

It's funny how people still fall for this stupid shit

yeah!! but most people really don't know about cryptocurrencies and mining.....

Malware in general

Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
http://www.ibtimes.co.uk/hackers-hijack-millions-android-devices-secretly-mine-monero-drive-by-cryptomining-scheme-1660847

Congratulations! This post has been upvoted from the communal account, @minnowsupport, by snofkin from the Minnow Support Project. It's a witness project run by aggroed, ausbitbank, teamsteem, theprophet0, someguy123, neoxian, followbtcnews, and netuoso. The goal is to help Steemit grow by supporting Minnows. Please find us at the Peace, Abundance, and Liberty Network (PALnet) Discord Channel. It's a completely public and open space to all members of the Steemit community who voluntarily choose to be there.

If you would like to delegate to the Minnow Support Project you can do so by clicking on the following links: 50SP, 100SP, 250SP, 500SP, 1000SP, 5000SP.
Be sure to leave at least 50SP undelegated on your account.

very helpful post