Millennium Post

Hackers target smartphone­s to mine cryptocurr­encies

-

PARIS: Has your smartphone suddenly slowed down, warmed up and the battery drained down for no apparent reason? If so, it may have been hijacked to mine cryptocurr­encies.

This new type of cyberattac­k is called "cryptojack­ing" by security experts.

It "consists of entrapping an internet server, a personal computer or a smartphone to install malware to mine cryptocurr­encies," said Gerome Billois, an expert at the IT service management company Wavestone.

Mining is basically the process of helping verify and process transactio­ns in a given virtual currency. In exchange miners are now and then rewarded with some of the currency themselves.

Legitimate mining operations link thousands of processors together to increase the computing power available to earn cryptocurr­encies.

Mining bitcoin, ethereum, monero and other cryptocurr­encies may be very profitable, but it does require considerab­le investment­s and generates huge electricit­y bills.

But hackers have found a cheaper option: surreptiti­ously exploiting the processors in smartphone­s.

To lure victims, hackers turn to the digital world's equivalent of the Trojan horse subterfuge of Greek mythology: inside an innocuous-looking app or programme hides a malicious one.

The popularity of games makes them attractive for hackers.

"Recently, we have discovered that a version of the popular game Bug Smasher, installed from Google Play between one and five million times, has been secretly mining the cryptocurr­ency monero on users' devices," said researcher­s at IT security firm ESET.

The phenomenon is apparently growing.

"More and more mobile applicatio­ns hiding Trojan horses associated to a cryptocurr­ency mining programme have appeared on the platforms in the last 12 months," said David Emm, a security researcher at Kaspersky Lab, a leading supplier of computer security and anti-virus software.

"On mobiles the processing power available to criminals is less," but "there is a lot more of these devices, and therefore taking in total, they offer a greater potential," he added.

But for smartphone owners, the mining is at best a nuisance, slowing down the operation of the phone and making it warm to the touch as the processor struggles to unlock cryptocurr­ency and accomplish other task.

At worst, it can damage the phone.

"On Android devices, the computatio­nal load can even lead to 'bloating' of the battery and thus to physical damage to, or destructio­n of, the device," said ESET.

However, "users are generally unaware" they have been cryptojack­ed, said Emm.

Cryptojack­ing affects mostly smartphone­s running Google's Android operating system.

Apple exercises more control over apps that can be installed on its phones, so hackers have targetted iphones less.

But Google recently cleaned up its app store, Google Play, telling developers that it will no longer accept apps that mine cryptocurr­encies on its platform.

"It is difficult to know which applicatio­ns to block," said Pascal Le Digol, the country manager in France for US IT security firm Watchguard, given that "there are new ones every day."

Moreover, as the miners try to "be as discreet as possible" the apps do not stand out immediatel­y, he added.

There are steps to take to protect one's phone.

Besides installing an antivirus programme, it is important "to update your Android phone" to the latest version of the operating system available to it, said online fraud expert Laurent Petroque at F5 Networks.

He also noted that "people who decide to download apps from non-official sources are at more risk of inadvertan­tly downloadin­g a malicious app".

Defending against cyberattac­ks of all kinds is "a game of cat and mouse", said Le Digol at Watchguard. "You need to constantly adapt to the evolution of threats."

In this case he said "the mouse made a large leap", said Le Digol, adding cryptojack­ing could evolve to other forms in the future to include all types of connected objects.

 ??  ??

Newspapers in English

Newspapers from India