The Asian Age

Miners under the guise of legitimate apps: Experts

- AGE CORRESPOND­ENT

Researcher­s from Kaspersky Labs have discovered that more and more cybercrimi­nals are turning their attention to malicious software that is mining cryptocurr­encies at the expense of users’ mobile devices. These criminals are getting greedier and now use not only malware but also risk tools, hiding mining capacities in popular football and VPN applicatio­ns to profit from hundreds of thousands of victims without their knowledge.

The hot topic of cryptocurr­ency mining could not be ignored by cybercrimi­nals, as they seek to increase their profits. They are mining on computers, servers, laptops and mobile devices. However, it is not only mining malware that they use. The experts found evidence showing that criminals are adding mining capacities into legitimate applicatio­ns and spreading them under the guise of football broadcasti­ng and VPN applicatio­ns.

According to Kaspersky Lab data, the most popular “legitimate miners” are football- related applicatio­ns. Their main function is to broadcast football videos while discreetly mining cryptocurr­encies. For this, developers used the Coinhive JavaScript miner. When users launch the broadcast, the applicatio­n opens an HTML file with the JavaScript miner embedded, converting visitors’ CPU power to the Monero cryptocurr­ency for its author’s benefit. The applicatio­ns were spread via the Google Play Store and the most popular of them was downloaded around 100,000 times. Nearly all ( 90 per cent) of these downloads originated from Brazil.

Legitimate applicatio­ns, responsibl­e for VPN- connection­s, became the second target for malicious miners. A VPN is a Virtual Private Network, via which users, for instance, can get access to web resources, that would not otherwise be available due to local restrictio­ns. Kaspersky Lab found the Vilny. net miner, which is able to monitor the battery charge and the temperatur­e of the device — to obtain money with less risk for the attacked gadgets. For this, the app downloads an executable from the server and launches it in the background. Vilny. net was downloaded over 50,000 times — mostly by users in Ukraine and Russia.

Kaspersky Lab products successful­ly detect these applicatio­ns as risk tools.

“Our findings show that authors of malicious miners are expanding their resources and developing their tactics and approach to perform more effective crypto- currency mining. They are now using legitimate thematic applicatio­ns with mining capacities to feed their greed. As such, they are able to capitalize on each user twice — firstly via an ad display, and secondly via discreet crypto- mining,” said Roman Unuchek, a security researcher at Kaspersky Lab.

Kaspersky Lab researcher­s advise users to abide by the following measures in order to protect their devices and private data from possible cyber attacks:

Disable the ability to install applicatio­ns from sources other than official app stores.

Keep the OS version of your device up to date in order to reduce vulnerabil­ities in the software and lower the risk of attack.

Only choose applicatio­ns from trusted and reliable vendors – especially those which are geared towards safeguardi­ng your privacy when online ( e. g., VPN).

Install a proven security solution to protect your device from cyber attack.

 ??  ??

Newspapers in English

Newspapers from India