Categories: NewsSecurity

Major Malvertising Campaign Mines Cryptocurrencies Using Users’ Browsers

Mining cryptocurrency has become even more popular over the past few months. Unfortunately, this trend has also attracted a lot of attention from cybercriminals. As a result of this growing attention by the wrong crowd, criminals have come up with some unique ways to mine cryptocurrencies using other people’s computers. This new malvertising campaign goes to show how things have devolved over just the past few weeks.

Malvertising Campaign Mines Cryptocurrency

The popularity of malvertising campaigns is on the rise. In most cases, malvertising campaigns are used to distribute malware on a very large scale. These types of malware can cause all kinds of harm, including the mining of cryptocurrency using other people’s computer resources. The latest malvertising campaign shows it is certainly possible to make this process a lot more straightforward.

Rather than tricking users into downloading cryptocurrency mining malware, this new campaign effectively hijacks users’ browsers. Using a piece of JavaScript code, the developers mine different cryptocurrencies directly through the visitor’s browser. The victim will be none the wiser in this regard, as there is no indication anything malicious is going on in the first place. Users may notice their computers responding a bit slower than normal, though.

This new malvertising campaign mainly focuses on gaming and streaming sites. That is not entirely surprising, as gamers often have decent computers with powerful graphics cards. Those GPUs can then be used by criminals to successfully mine cryptocurrency. Malicious ads were distributed through an online advertising company which allows clients to deploy custom JavaScript code. Why such a service is allowed in the first place remains a big mystery to security researchers.

Related Post

The JavaScript code is a modified version of MineCrunch, a notorious script which can be used to mine cryptocurrency through the browser. MineCrunch was released back in 2014 and seems to be making a comeback in a nefarious package. By delivering ads running this JavaScript code on streaming and gaming sites, most users may not even notice the increased strain on their computer resources.

The criminals were mainly interested in Monero, ZCash, and Litecoin. Moreover, it appears the code is also capable of mining Feathercoin, although that currency has become far less valuable over the past few months. For the time being, it appears only the Monero mining feature has been used in the initial stages  That is not entirely surprising, as Monero is the most anonymous cryptocurrency in the world today.

Thankfully, most users will not see any negative repercussions from this malvertising campaign. Most ad blockers successfully prevent the execution of JavaScript code. However, if the code loads from unusual ad slots, the ad blocker will not be of much help. It will be interesting to see whether or not this malvertising campaign remains active, and if so, how much money it generates in the process.  What is certain is that this will not be the last malvertising campaign focusing on cryptocurrency mining.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

TRON Leads All Blockchains in November Fees as Perpetuals Trading Surges 271%

TRON ended November as the top blockchain by fees, extending its dominance in payment infrastructure…

24 hours ago

Prediction Markets Hit New All-Time Highs as November Volume Surges to $14.3B

Prediction markets just locked in another breakout month. November closed with $14.3 billion in total…

24 hours ago

Trust Wallet Launches Native Predictions: A New Era for On-Chain Betting

Trust Wallet is stepping into a completely new lane. The CZ-owned self-custody wallet has launched…

2 days ago

Kraken Acquires Backed to Supercharge Tokenized Equities as xStocks Enters Its Next Phase

Kraken has announced the acquisition of Backed, the tokenization platform behind some of the fastest-growing…

2 days ago

Sui Pauses & AVAX Rebounds While Zero Knowledge Proof’s 200M Daily Presale Auction Goes Live, Sparking Massive Buyer Rush

Sui Pauses & AVAX Rebounds While Zero Knowledge Proof’s 200M Daily Presale Auction Goes Live,…

3 days ago

Europe Takes Down Cryptomixer: A $1.4B Bitcoin Laundering Machine Falls After Eight Years

Europe just shut down one of crypto’s longest-running shadows. Germany and Switzerland, backed by Europol,…

3 days ago