Chattanooga Times Free Press

How your smart fridge might be mining bitcoin for criminals

- BY ROBERT STEVENS

LONDON — Is the web browser on your phone slower than usual? It could be mining bitcoin for criminals.

As the popularity of virtual currencies has grown, hackers are focusing on a new type of heist: putting malicious software on peoples’ handsets, TVs and smart fridges that makes them mine for digital money.

So-called “crypto-jacking” attacks have become a growing problem in the cybersecur­ity industry, affecting both consumers and organizati­ons. Depending on the severity of the attack, victims may notice only a slight drop in processing power, often not enough for them to think it’s a hacking attack. But that can add up to a lot of processing power over a period of months or if, say, a business’s entire network of computers is affected.

“We saw organizati­ons whose monthly electricit­y bill was increased by hundreds of thousands of dollars,” said Maya Horowitz, Threat Intelligen­ce Group Manager for Checkpoint, a cybersecur­ity company.

Hackers try to use victims’ processing power because that is what’s needed to create — or “mine” — virtual currencies. In virtual currency mining, computers are used to make the complex calculatio­ns that verify a running ledger of all the transactio­ns in virtual currencies around the world.

Crypto-jacking is not done only by installing malicious software. It also can be done through a web browser. The victim visits a site, which latches onto the victim’s computer processing power to mine digital currencies as long as they are on the site. When the victim switches, the mining ends. Some websites, including Salon.com, have tried to do it legitimate­ly and been transparen­t about it. For three months this year, Salon.com removed ads from its sites in exchange for users allowing them to mine virtual currencies.

Industry experts first noted crypto-jacking as a threat in 2017, when virtual currency prices were skyrocketi­ng to record highs.

The price of bitcoin, the most widely known virtual currency, jumped six-fold from September to almost $20,000 in December before falling back down to under $10,000.

The number of crypto-jacking cases soared from 146,704 worldwide in September to 22.4 million in December, according to anti-virus developer Avast. It has only continued to increase, to 93 million in May, it says.

The first big case emerged in September and centered on Coinhive, a legitimate business that let website owners make money by allowing customers to mine virtual currency instead of relying on advertisin­g revenue. Hackers quickly began to use the service to infect vulnerable sites with miners, most notably YouTube and nearly 50,000 Wordpress websites, according to research conducted by Troy Mursch, a researcher on crypto-jacking.

Mursch says Monero is the most popular virtual currency among cyber-criminals. A report by cybersecur­ity company Palo Alto Networks estimates that more than 5 percent of Monero was mined through crypto-jacking. That is worth almost $150 million and doesn’t count mining that occurs through browsers.

In the majority of attacks, hackers infect as many devices as possible, a method experts calls “spray and pray.”

“Basically, everyone with a [computer processing unit] can be targeted by crypto-jacking,” said Ismail Belkacim, a developer of an applicatio­n that prevents websites from mining virtual currencies.

As a result, some hackers target organizati­ons with large computing power. In what they believe might be the biggest crypto-jacking attack so far, Checkpoint discovered in February that a hacker had been exploiting a vulnerabil­ity in a server that over several months generated over $3 million in Monero.

Crypto-jackers have also recently targeted organizati­ons that use cloud-based services, in which a network of servers is used to process and store data, providing more computing power to companies who haven’t invested in extra hardware.

Abusing this service, crypto-jackers use as much power as the cloud will allow them to, maximizing their gains. For businesses, this results in slower performanc­e and higher energy bills.

 ?? ASSOCIATED PRESS FILE PHOTO ?? A neon sign hangs in the window of Healthy Harvest Indoor Gardening in Hillsboro, Ore. A raft of recent cybersecur­ity firms and government­s now cite the rising trend of ‘crypto-jacking’ as the main cybersecur­ity threat to businesses and consumers...
ASSOCIATED PRESS FILE PHOTO A neon sign hangs in the window of Healthy Harvest Indoor Gardening in Hillsboro, Ore. A raft of recent cybersecur­ity firms and government­s now cite the rising trend of ‘crypto-jacking’ as the main cybersecur­ity threat to businesses and consumers...

Newspapers in English

Newspapers from United States