As soon as you connect to WiFi, you may start mining for hackers

according tobitcoinistaccording to
Malicious cryptocurrency mining software is on the rise, according to the latest report from cybersecurity company WatchGuard Technologies, and it is expected that this form of attack will be included in the top 10 of cyber threats by the end of this year and will become one of the main forms of malware attacks. one.
The report states that 98.8 percent of the detected malware was based on Linux systems mining Monero.
Monero has privacy and anonymity, and the transaction ID and transaction amount can be blurred, so it is difficult to obtain the source of Monero. These characteristics make it the digital currency of choice for illegal mining hackers.
Earlier, hackers used Youtube users to mine Monero. There are some ads on Youtube that have been embedded with malicious scripts (JavaScript) provided by the Coinhive platform. As long as the user visits these ads, the mining program will work on the user’s computer, and the longer the user’s online time, the more mined The more coins, the more money the hacker makes.
Subsequently, Youtube immediately took action against these malicious advertisements: preventing their malicious scripts from running by setting and adding parameters.
according toaccording torelevant media reportsrelevant media reports
, in February this year, 4,200 websites, including US and UK government agencies, were infected with a set of codes for several hours. These include the City University of New York, the US Court Information Portal, Lund University in Sweden, student loan companies in the UK, and a number of UK government and global organisations' websites. In these websites, a large amount of information of citizens is stored.
Infected sites were populated with a popular plug-in called "Browsealoud". Developed by the British software company Texthelp, the plug-in is designed to read web pages to blind users. However, hackers changed the source code of Browsealoud, so that the malicious mining code was implanted into the webpages supporting Browsealoud. After that, Texthelp temporarily shut down the Browsealoud service.
In addition to previous hacking incidents, Kaspersky Lab researchers recently discovered that an attack tool used by a cybercriminal organization uses APT (Advanced Persistent Threat) attack techniques to infect users and install mining software on victims on the user's computer.
APT refers to advanced persistent threats. Its advanced nature is mainly reflected in the fact that APT accurately collects and analyzes information such as the system of the attack target before launching an attack, which is conducive to long-term persistent network attacks on specific targets.
Victims are lured into downloading and installing a piece of software that hides the installer for mining software. The installation program will release a legitimate Windows tool, and the mining software will be disguised as a legitimate application to run, and the user cannot tell whether his computer is infected by the mining software. If the user tries to stop the process, the computer system will reboot. In this way, the mining software can remain in the system forever, and hackers will get more profits.
As for the web version of the mining system, ad-blocking software helps filter out malicious scripts that perform cryptographic number crunching. Software firewalls can also block connections between malicious miners and command servers.

(I am Yannan, a reporter from Odaily. I am exploring the real blockchain. Please add WeChat nangua421262 for breaking news and communicating. Please note your name, unit, position and reason.)


