Moneycontrol PRO
HomeNewsBusinessCryptocurrencyNearly 350 websites infected by in a mass cryptojacking campaign

Nearly 350 websites infected by in a mass cryptojacking campaign

All websites were infected using the same method. A malicious code was injected into the JavaScript library of the website

May 09, 2018 / 19:11 IST
-
Open Trading A/c
-
0 (0%)
Todays L/H
0
0

In a mass cryptojacking campaign, over 300 websites using the Drupal content management system have been infected with cryptocurrency-mining malware.

Security researcher, Troy Mursch who is the brain behind the website Bad Packets Report, uncovered the malicious campaign involving the repeat offender Coinhive on Saturday. He said that many of the discovered websites were government and university sites from all over the world.

All websites were infected using the same method. A malicious code was injected into the JavaScript library of the website.

Cryptojacking is the term used by security researchers to refer to incidents when hacker inject a malicious code to mine cryptocurrency—essentially hacking the browser of a user to mint money at expense of his or her CPU power.

Mursch, in an interaction with Coindesk, said it was not as overt as ransomware—a practice when hackers encrypt user’s document and hold it ransom, but continues to be a problem.

"This is because Coinhive and other cryptojacking services are simply done with JavaScript. Every modern browser and device can run JavaScript, so as such, everybody can mine cryptocurrency and unfortunately Coinhive has been used and abused time and time again. [In] this particular case, Drupal users need to update [as soon as possible]," he said.

Mursch, in order to uncover the length and breadth of the scam, scanned hundreds of thousands of websites. “After the scan completed, the full scope of this cryptojacking campaign was established — 348 infected websites. Using the bulk scan feature of urlscan.io, it became clear these were all sites were running outdated and vulnerable versions of Drupal content management system,” he said.

“The affected sites varied by hosting providers and countries and no specific one appeared to be targeted. The unique domains were found in the United States and were hosted by Amazon.”

The affected sites include US government’s National Labour Relations Board, Government of Chihuahua, Mexico, University of Aleppo, etc. The full list of affected websites can be seen here.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: May 9, 2018 07:11 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advertisement

Crypto Basket
Powered By Mudrex

Bitcoin
Current Price ₹ 7,977,128.34 1D returns -1.16%
Buy Now
Ethereum
Current Price ₹ 269,960.78 1D returns -1.89%
Buy Now
BNB
Current Price ₹ 76,849.93 1D returns -1.79%
Buy Now
Ripple
Current Price ₹ 170.50 1D returns -1.69%
Buy Now
USD Coin
Current Price ₹ 91.17 1D returns 0.01%
Buy Now
Solana
Current Price ₹ 11,219.93 1D returns -2.53%
Buy Now
BTC 50 :: ETH 50
1W returns2.82%
Invest Now
DeFi Tracker
1W returns1.27%
Invest Now
Web3 Tracker
1W returns-0.55%
Invest Now
AI Tracker
1W returns-1.79%
Invest Now

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347