Attacker Installs Crypto Mining Malware on Over 170,000 Devices

Coinhive was installed on more than 170,000 devices in Brazil last month.

AccessTimeIconAug 9, 2018 at 5:00 p.m. UTC
Updated Sep 13, 2021 at 8:16 a.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

More than 170,000 devices in Brazil were targeted in a cryptojacking attack last month.

According to a blog post published by security firm Trustwave, a wide-scale cyberattack was launched on MicroTik routers. The effort led to the installation of the Coinhive mining software in a "mass" infection of more than 17,000 devices.

Trustwave security researcher Simon Kenin wrote that all of the devices used "the same sitekey," indicating that one entity reaped the mined tokens from all of the devices.

He wrote:

"This attack may currently be prevalent in Brazil, but during the final stages of writing this blog, I also noticed other geo-locations being affected as well, so I believe this attack is intended to be on a global scale."

According to a previous post by Trustwave, also co-authored by Kenin, Coinhive gained traction in 2017 as a service that claimed to provide monetizing solutions for websites without using any advertisements. Instead, site owners were to embed JavaScript code that would take hold of the central processing unit (CPU) power of site visitors to mine the cryptocurrency monero.

However, mining reportedly ended up costing site visitors up to 99 percent of their CPU processing power, leading to further issues for consumers as their devices generated more heat and used up large amounts of electricity.

Trustwave has since released a detection tool to block the mining malware, and as Kenin explains in his most recent post, readers should heed his "warning call" and patch any MikroTik devices "as soon as possible," emphasizing that the severity of the attacks could reach "hundreds of thousands" of consumers around the globe.

Kenin also reports that illicit cryptocurrency mining operations such as these are "a trend we've been seeing a lot of over the last three years, as attackers shift from ransomware into the world of miners."

Such sentiments are being echoed by other cybersecurity firms such as Skybox Security which also reported in their 2018 mid-year update that among cybercriminals, crypto mining now accounted for 32 percent of all cyberattacks, with ransomware making up 8 percent.

Typing image via Shutterstock

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.