Categories: Cryptocurrency hack

Malware Abuse Google Ads to Injecting Coinhive Cryptocurrency Miner

Cyber Criminals using Malvertising Campaign to inject coinhive Cryptocurrency Miner using Google DoubleClick Ads and deployed it on legitimate websites.

coinhive is a Cryptocurrency miner that mainly using Javascript to the mine cryptocurrency like Menero that runs on user systems while they visit a website.

Attackers now Abusing google DoubleClick ads and running Malvertising Champaign into high traffic website to run the coinhive crypto miner and other web-based miners that connect to some private tools.

This Malware detected as JS_COINHIVE.GN and it mainly affected countries include Japan, France, Taiwan, Italy, and Spain.

Security researchers had a close look at 5 malicious domain where the traffic has dramatically increased and finally they confirmed that the traffic coming from DoubleClick advertisements.

Also, There are 2 web miners scripts are running in the malicious webpage and the script displays in the advertisement from DoubleClick.

These affected web pages are showing legitimate Google ads at the time of two web miners performing their task.

Also Read: Coincheck Cryptocurrency Exchange Hacked & Stolen More than $500 Million Worth Currency

How does  Coinhive Cryptocurrency Miner Works

Google Doubleclick advertisement contains javascript code that can generate a random code form 1 to 101.

When Random numbers generate a variable and it will be more than 10, then it will call the script called coinhive.min.js.

It will help to mine almost 80% of CPU Power and later a private web miner will be launched.

According to Trend Micro, after de-obfuscating the private web miner called mqoj_1.js, there will be a JavaScript code that is still based on Cognitive. The modified web miner will use a different mining pool at wss[:]//ws[.]l33tsite[.]info[:]8443. This is done to avoid Coinhive’s 30% commission fee.

So Blocking the JavaScript-based applications from running on browsers can prevent Coinhive miners from using CPU resources.

IOC

SHA256

e72737a8cf29eeae795a3918e56c07b4efa2e9ce241ec56053d6a95f878be231
296d081b6b0a6d1a09b5c54c35392a4d2ea0bec9a0c99e6351374628b713d8ed

 

Malicious domains Attribution
doubleclick1[.]xyz Malvertising Domain
doubleclick2[.]xyz Malvertising Domain
doubleclick3[.]xyz Malvertising Domain
doubleclick4[.]xyz Malvertising Domain
doubleclick5[.]xyz Malvertising Domain
doubleclick6[.]xyz Malvertising Domain
api[.]l33tsite[.]info Private Webminer Domain
ws[.]l33tsite[.]info Private Webminer Domain

 

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a Taiwanese…

5 hours ago

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files

Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals in…

5 hours ago

Sophisticated Phishing Attack Targeting Ukraine Military Sectors

The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215 against…

6 hours ago

Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks

Researchers have identified a network of compromised devices, CovertNetwork-1658, used by Chinese threat actors to…

6 hours ago

New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine

A security researcher discovered a vulnerability in Windows theme files in the previous year, which…

6 hours ago

SYS01 InfoStealer Malware Attacking Meta Business Page To Steal Logins

The ongoing Meta malvertising campaign, active for over a month, employs an evolving strategy to…

6 hours ago