Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
Cookie Policy Privacy Policy {title}
Skip to content

CloudTech is part of the TechForge Publications series

  • View All
  • AI News
  • The Block
  • Developer
  • Edge Computing News
  • IoT News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Sustainability News
  • Telecoms
  • View All
  • AI News
  • The Block
  • Developer
  • Edge Computing News
  • IoT News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Sustainability News
  • Telecoms

TechForge

  • Search
  • News
  • Categories
    • Applications
      • Blockchain
      • Containers
      • Data Centres
      • Infrastructure as a Service
      • Platform as a Service
      • Software as a Service
      • Virtualisation
    • Companies
      • Alibaba Cloud
      • AWS
      • Google Cloud
      • Microsoft
    • Data & Analytics
    • Enterprise
      • Cloud Migration
      • Collaboration
      • Digital Transformation
      • Future Work
      • Hybrid Cloud
      • Private Cloud
      • Public Cloud
    • Industries
      • Banking & Finance
      • Healthcare
      • Public Sector
      • Retail & Consumer
      • Telecoms
    • Infrastructure
    • Interviews
    • IoT
    • Platforms
    • Privacy
    • Regulation & Government
    • Security
    • Sponsored Content
  • Events
  • Resources
    • All Resources
    • On-demand Webinars
    • Exclusive Videos
  • More
    • Advertise
    • Contact Us
    • About Us
  • Search
  • News
  • Categories
    • Applications
      • Blockchain
      • Containers
      • Data Centres
      • Infrastructure as a Service
      • Platform as a Service
      • Software as a Service
      • Virtualisation
    • Companies
      • Alibaba Cloud
      • AWS
      • Google Cloud
      • Microsoft
    • Data & Analytics
    • Enterprise
      • Cloud Migration
      • Collaboration
      • Digital Transformation
      • Future Work
      • Hybrid Cloud
      • Private Cloud
      • Public Cloud
    • Industries
      • Banking & Finance
      • Healthcare
      • Public Sector
      • Retail & Consumer
      • Telecoms
    • Infrastructure
    • Interviews
    • IoT
    • Platforms
    • Privacy
    • Regulation & Government
    • Security
    • Sponsored Content
  • Events
  • Resources
    • All Resources
    • On-demand Webinars
    • Exclusive Videos
  • More
    • Advertise
    • Contact Us
    • About Us
Subscribe
Subscribe
  • Search
  • News
  • Categories
    • Applications
      • Blockchain
      • Containers
      • Data Centres
      • Infrastructure as a Service
      • Platform as a Service
      • Software as a Service
      • Virtualisation
    • Companies
      • Alibaba Cloud
      • AWS
      • Google Cloud
      • Microsoft
    • Data & Analytics
    • Enterprise
      • Cloud Migration
      • Collaboration
      • Digital Transformation
      • Future Work
      • Hybrid Cloud
      • Private Cloud
      • Public Cloud
    • Industries
      • Banking & Finance
      • Healthcare
      • Public Sector
      • Retail & Consumer
      • Telecoms
    • Infrastructure
    • Interviews
    • IoT
    • Platforms
    • Privacy
    • Regulation & Government
    • Security
    • Sponsored Content
  • Events
  • Resources
    • All Resources
    • On-demand Webinars
    • Exclusive Videos
  • More
    • Advertise
    • Contact Us
    • About Us

Blockchain

Step aside ransomware: Why cryptojacking is the new kid on the block

Paolo Passeri

15th May 2018

Share this story:

Tags:

Categories::

Blockchain
Data & Analytics
Security

With the ability to generate a staggering $1.5 trillion in revenues every year, cybercrime is big business. It’s the perfect model – earn a high income for minimum effort and risk of penalty.

It comes as no surprise then that when faced with issues around the fluctuating value of Bitcoin, cybercriminals stepped into action. These savvy criminals created a new attack technique that offers better paid out odds in comparison to ransomware – cryptojacking – unauthorised use of someone else’s computing resources to mine cryptocurrency.

This new technique has quickly risen in the ranks, replacing ransomware as the number one threat for consumers and enterprises. Let’s look more in detail at the factors that have driven this shift.

The money maker

With a cryptocurrency market cap of nearly $500 billion, cryptojacking is extremely attractive for cybercriminals: it doesn’t require high technical skills and, unlike ransomware, offers a potential 100% pay-out ratio. Once compromised, infected machines can immediately start to mine cryptocurrency in stealth mode regardless of its processing power or geographical location. Even low-end systems are useful to the cause since it’s the size of the network of compromised machines, and hence the total computational power, that really matters. Additionally, if the attackers don’t get carried away and tune the miner not to completely drain the CPU, the attack can go on stealth and undetected for a long time.

Ubiquity of the attack surface

It doesn’t matter if the malicious miner component is injected into a mobile device, a personal computer, a server, the cloud, or even an IoT device. It doesn’t even matter what operating system is being used. The attackers can take advantage of its CPU cycles for their illegitimate purposes with any OS. Even IoT devices with limited processing power can be recruited: the Mirai botnet has taught us what multiple IoT devices can do when working together. And it’s not a coincidence that a variant has been repurposed to mine cryptocurrency, and the same botnet has also spawned Satori, a variant infecting mining rigs, hijacking the device owner's mining credentials. In fact, hacking multiple IoT devices can be rewarding: according to a recent estimate, 15,000 hacked internet-connected gadgets can mine $1,000 of cryptocurrency in just four days. Not shabby considering that by 2020, there will be over 20 billion internet-connected devices.

Multiple infection mechanisms

Since malicious miners can be injected in virtually any device, multiple infection vectors can be used such as brute-force attacks, unpatched vulnerabilities, or compromised websites (drive-by cryptomining). The timelines of cyberattacks that I collect each month highlight the attackers’ creativity and their ability to find new ways to carry out these attacks.

Similar techniques can be used to compromise both client and servers, making new slaves for the cryptominer botnets. The Smomirnu botnet and Wannamine malware are two examples of threats exploiting the infamous EternalBlue vulnerability (CVE-2017-144) to spread. Even existing malware can be rewritten to mine cryptocurrency, or to add this “feature” to the existing ones.

In reality clients are even more exposed since they can mine cryptocurrency simply visiting a web-page hosting a JavaScript miner like Coinhive. Coinhive mines a cryptocurrency called Monero (XMR) and the main reason is that besides being able to stay anonymous with this blockchain, the algorithm used to calculate the hashes, called Cryptonight, was designed to run well on consumer CPUs (what a coincidence).

This is only the tip of the iceberg, since drive-by cryptomining campaigns are becoming bigger, more prevalent and more persistent while you browse the internet. Criminals are now adopting a technique similar to malvertising, injecting the Coinhive code into advertisements supplied by platforms like AOL or Google DoubleClick. It doesn’t even matter if the user leaves the compromised page or closes his browser since the malicious code can be hidden in a tiny ‘pop-under’ window hidden behind the Windows taskbar. This makes it persistent and invisible to the user. There have also been cases of malicious browser extensions injecting Coinhive directly into your browser.

The role of the cloud

The list of the five most new dangerous attacks presented by the SANS institute at the last RSA Conference includes both cloud storage data leakage and monetisation of compromised systems via cryptominers. Data leakage in the cloud is often the consequence of misconfigurations like wrong permissions or lack of an adequate password protection. Apart from stealing data, the same misconfigurations can be used by crooks to spin-up their own instances and use them to mine cryptocurrency at the expense of the victim, with the concrete possibility that the latter will not detect the attack until the next bill. A deadly combination of these two attack techniques listed by the SANS Institute has already hit some high-profile victims like Tesla, whose public cloud was used to mine cryptocurrency.

There are also some additional risks. Miners can use known cloud services to spread more quickly inside organisations (Netskope Threat Research Labs discovered a Coinhive miner resident in a Microsoft Office 365 OneDrive for Business instance), or also to avoid detection (like in case of Zminer and Xbooster that download payloads from Amazon S3 cloud storage).

Out-crafting the cryptojacker

The good news is that businesses can reduce their risk of exposure to cryptojacking by enforcing policies such as:

  • Scanning all uploads from unmanaged devices to sanctioned cloud applications for malware
  • Scanning all uploads from remote devices to sanctioned cloud applications for malware
  • Scanning all downloads from unsanctioned cloud applications for malware
  • Scanning all downloads from unsanctioned instances of sanctioned cloud applications for malware
  • Enforcing quarantine/block actions on malware detection to reduce user impact
  • Blocking unsanctioned instances of sanctioned/well known cloud apps, to prevent attackers from exploiting user trust in cloud. While this seems a little restrictive, it significantly reduces the risk of malware infiltration attempts via cloud

These policies combined with an effective patch management process for clients and servers; an updated corporate antivirus the latest releases and patches; and the use of Ad-blockers or browser extensions like NoScript can help to prevent drive-by cryptomining attacks.

Criminals are savvy, smart and are always on the lookout for the opportunity to exploit what they can, when they can, so don’t give them the chance. These preventative measures are effective and offer the barrier you need to protect yourself against mounting cryptojacking attacks and stop them in their tracks.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

About the Author

Paolo Passeri

Cyber Intelligence Principal

Paolo Passeri is cyber intelligence principal at Netskope .

Related

CISA issues guidance amid unconfirmed Oracle Cloud breach

21st April 2025

Trade tensions prompt European firms to rethink cloud strategies

21st April 2025

$100M IFC investment in sub-Saharan Africa data centres

11th April 2025

Dr Mary Aiken, University of East London: The Intersection of technology and human behaviour in cybersecurity

11th April 2025

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Click here

Popular

Cloud Computing

Oracle Cloud denies breach as hacker offers 6 million records for sale

4305 view(s)

Applications

Netflix countersues Broadcom over VMware patents

3086 view(s)

Cloud Computing

5 of the best: cloud technology training platforms

3057 view(s)

Infrastructure

Microsoft’s palm-sized chip brings practical quantum computing within reach

2467 view(s)
See all

Latest

View All Latest

Interviews

11th April 2025

Dr Mary Aiken, University of East London: The Intersection of technology and human behaviour in cybersecurity

Google unveils Cloud WAN and Gemini Tools to simplify app development Google Cloud Next 2025

Applications

10th April 2025

Google Cloud Next 25: AI, cloud, and WAN

Deutsche Telekom extends Google Cloud partnership through 2030

Cloud Computing

10th April 2025

Deutsche Telekom extends Google Cloud partnership through 2030

Subscribe

All our premium content and latest tech news delivered straight to your inbox

Subscribe

Explore

  • About Us
  • Contact Us
  • Newsletter
  • Privacy Policy
  • Cookie Policy
  • About Us
  • Contact Us
  • Newsletter
  • Privacy Policy
  • Cookie Policy

Reach Our Audience

  • Advertise
  • Post a Press Release
  • Contact Us
  • Advertise
  • Post a Press Release
  • Contact Us

Categories

  • Applications
  • Companies
  • Data & Analytics
  • Enterprise
  • Industries
  • IoT
  • Infrastructure
  • Platforms
  • Sponsored Content
  • Applications
  • Companies
  • Data & Analytics
  • Enterprise
  • Industries
  • IoT
  • Infrastructure
  • Platforms
  • Sponsored Content

Other Publications

  • Explore All
  • AI News
  • Developer
  • IoT News
  • Edge Computing News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Telecoms
  • The Block
  • Sustainability News
  • Explore All
  • AI News
  • Developer
  • IoT News
  • Edge Computing News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Telecoms
  • The Block
  • Sustainability News

CloudTech News is part of TechForge 

Subscribe

All our premium content and latest tech news delivered straight to your inbox

Permissions(Required)
This field is for validation purposes and should be left unchanged.

Notifications