CYBER WARS
Thousands of websites infected by 'crypto mining' malware
by Staff Writers
Washington (AFP) Feb 12, 2018

Thousands of websites around the world, including many operated by governments, have been infected by hackers using the sites' computing power to "mine" cryptocurrencies, security researchers said.

The attack is the first major incident made public in which a new breed of hackers took over a large numbers of websites to effectively create currencies like bitcoin which are generated by using computing power.

The attacks made public over the weekend by British security researcher Scott Helme showed more than 4,000 website were infected in this manner, including those of the British data protection and privacy watchdog and the US federal courts system.

Unlike traditional attacks, these infections do not contain "ransomware" or steal data, but operate in stealth mode to make profits from the shadowy world of cryptocurrencies.

Helme said in a blog post Sunday that the hackers were able to reach large numbers of websites by infecting a commonly used "plug-in," or software which helps a site run better.

In this case, the hackers used the malicious software to create Monero, one of several new cryptocurrencies which are making a splash in financial markets.

"If you want to load a crypto miner on 1,000+ websites you don't attack 1,000+ websites, you attack the 1 website that they all load content from," he said.

The creator of the plug-in, the British software firm TextHelp, said it took the affected software offline after it discovered the "attempt to illegally generate cryptocurrency. "

"This was a criminal act and a thorough investigation is currently underway," the company said in a statement.

Researchers have been warning in recent weeks about this kind of malware, which can deliver profits without being obvious to users.

Security researchers at Cisco Talos warned last month that this kind of hacking activity "has exponentially increased."

Because of the huge financial gains in cryptocurrencies, Cisco researchers said this has become a prime target for hackers.

"At a high level mining is simply using system resources to solve large mathematical calculations which result in some amount of cryptocurrency being awarded to the solvers," Cisco researchers wrote in a research note.

Security researcher Graham Cluley said the latest attack highlights vulnerabilities in websites which may have weaknesses in third party components.

"Things could have been much worse," Cluley said in a blog post. "Imagine if the plug-in had been tampered with to steal login passwords rather than steal CPU resources from visiting computers."


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

CYBER WARS
China orders microblog companies to ramp up censorship
Beijing (AFP) Feb 2, 2018
China Friday ordered the country's microblog operators to establish mechanisms to remove false information, in the latest move by authorities to tighten policing of the web. The Cyberspace Administration of China said the Twitter-like microblog platforms have allowed the spread of pornographic, vulgar and fraudulent content. In addition to making sure to remove such content, companies should also keep a copy of what users post for at least six months, the CAC said in an online statement. "Mi ... read more

Comment using your Disqus, Facebook, Google or Twitter login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
China to Develop Sea-Based Missile Interceptors

Lockheed awarded $523M for Patriot missiles for Qatar, Saudi Arabia, Romania

Beijing holds successful missile defense test

Saudi says Yemen rebel ballistic missile shot down

CYBER WARS
Russia, India may sign contract on S-400 air defense systems supplies soon

Raytheon awarded $44.6M for missile systems research, development

Finland approved for Harpoon, SeaSparrow missile purchases

Lockheed Martin Miniature Hit-to-Kill Missile Demonstrates Increased Agility and Affordability

CYBER WARS
L-3 awarded $8.2M for retrofits to Predator simulators

General Atomics awarded $49M for Reaper drone software development

Drones learn to navigate autonomously by imitating cars and bicycles

Northrop Grumman tapped to service Army's Hunter drones

CYBER WARS
Improve European defence with new commercial space capabilities

Military innovation demands state-of-the-art satellite connectivity for maritime applications

L-3 to provide advanced optics, sensors to U.S. Air Force

DARPA Seeks to Improve Military Communications with Digital Phased-Arrays at Millimeter Wave

CYBER WARS
Boeing contracted by Air Force for MOP 'bunker busters'

Marines successfully test mine plow prototype for assault breacher

Oshkosh awarded $476.2M contract for tactical vehicles

Army turns to Olin Corp. for small caliber ammo

CYBER WARS
US budget outline calls for huge Pentagon increase, cuts to State

France hikes defence spending to hit NATO target

Okinawa vote seen as boosting Japan's bid to relocate US base

Italy's Leonardo outlook sends shares into tailspin

CYBER WARS
British warship to sail through disputed South China Sea

US power not in decline across Asia-Pacific: Dunford

China activity on reclaimed reef has eroded trust: ASEAN

Trump's military parade plan sparks backlashl

CYBER WARS
More-sensitive DNA nanowires promise better measurements of biological processes

On the rebound as nanoparticles self-heal

Optical nanoscope allows imaging of quantum dots

Let the good tubes roll