Monday, November 4, 2024
HomeCryptocurrency hackCryptocurrency Web Miner Makes into MSN Portal Through Advertising Platform

Cryptocurrency Web Miner Makes into MSN Portal Through Advertising Platform

Published on

Malware protection

Cryptocurrency web miner scripts make into MSN portal through Advertising Platform AOL and create a large number of web miners. Hackers Modified the scripts of AOL advertising platform to launch a web miner program and most of the minor traffic linked to MSN[.]com in Japan.

Security researchers from Trend Micro Spotted a significant increase(108%) in the number of unique miners, the Sudden Spike is because of the effectiveness of the advertising platform.

cryptocurrency web miner

The compromised advertisement was on the front page of the MSN and it uses to redirect the user’s to the number of other pages. Further analysis shows more than 500 websites compromised with the same campaign.

- Advertisement - SIEM as a Service

Also Read Pop-up Ads & Hundreds of Websites Helping to Distribute Botnets, Cryptocurrency Miners and Ransomware

When a user visit’s the MSN portal and if the advertisement is displayed, then their browser starts running cryptocurrency web miner and it stops after the user closes the browser window.

The malicious script was injected into advertising[.]aolp[.]jp and the web miner traffic linked to the domain www[.]jqcdn[.]download that was created on March 18.

Cryptocurrency mining script generated based on the Coinhive and attackers users private mining pools, possibly to avoid charges of using well-established miner’s.

We closely examined compromised sites that this campaign modified and noticed that much of the malicious content was hosted on Amazon Web Service (AWS) S3 buckets. The names of the S3 buckets were visible in some of the compromised URLs, allowing us to investigate them further. We found that the buckets were completely unsecured, left open for anyone to list, copy, and modify” researchers said.

With this campaign, attackers injected malicious script JavaScript library on the unsecured open S3 buckets.

According to Trend Micro “We suspect that the legitimate AWS administrator didn’t properly set the permissions of their S3 bucket, which allowed the attacker to modify the hosted content“.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Allegedly Claiming Leak of Dell Partner Portal Data

A well-known dark web forum threat actor allegedly claimed responsibility for leaking data from...

Securing Your SaaS Application Security

The rapid growth of cloud computing has made SaaS applications indispensable across industries. While...

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical Atlassian Vulnerability Exploited To Connect Servers In Mining Networks

Hackers usually shift their attention towards Atlassian due to flaws in its software, especially...

Log4j Vulnerability Exploited Again To Deploy Crypto-Mining Malware

Recent attacks exploit the Log4j vulnerability (Log4Shell) by sending obfuscated LDAP requests to trigger...

Hackers Abused StackExchange Platform To Deliuver Malicious Python Package

Attackers uploaded malicious Python packages targeting Raydium and Solana users to PyPI, leveraging a...