Wednesday, August 19, 2026

Hackers Сovertly Mining Cryptocurrency on Government Websites in India

Almost all government sites in India have been infected by malware that uses the power of visitors’ computers to extract cryptographic material using the CoinHive script.

India’s official government sites have become the primary target for cryptocurrency, The Economic Times reports. The attack on the computers leads to malware that uses the processing power to extract the cryptocurrency in favor of the attacker, without the knowledge of the computer owner.

A new study by cybersecurity analysts shows that government sites with very high levels of trust have been subjected to web-based injections (code injection), including one of the latter that infected the Andhra Pradesh administration page.

The experts identified the infected sites as one of the most visited resources in the country. The government of India confirmed that the attack actually took place, but so far the problem has not been resolved. The volumes of tokens on government sites have also not been disclosed yet.

“Hackers are targeting government sites because these pages have extremely high traffic, which facilitates mining, plus visitors trust the content of the website. It wouldn’t occur to anyone that a provincial or state administration website would contain malicious code. Previously, we watched such sites being cracked; now web injections are in fashion because that’s how an attacker can make a lot of money,” the research authors say.

Along with government domains, CoinHive have infected 119 more Indian sites. The researchers warn that, in addition to these government sites, of particular interest to hackers are sites of illegal video streaming, because while the user watches a movie or series script has the ability to fully load the processor machine. This original idea only confirms that outsourcing in India is not a bad idea.

Hidden mining brings a noticeable profit to cybercriminals. Only a month ago, researchers from RWTH Aachen University, Germany, calculated that the script CoinHive, which infected sites around the world, mines more than 250 thousand USD per month in Monero.

This is mainly done through the process of the hidden use of computing resources on people’s computers without their consent.

Since browser extensions do not require user rights, the software can simply operate in a hidden mode. This results in attackers adding mining functionality to their websites as a means of generating additional revenue.

Although CoinHive is not the only mining extension for a browser, it has been found to have the highest usage share – over 75% of browser usage.

CoinHive does a lot of damage to the industry. The fact that CoinHive is widely used among website owners has a bad impact on the cryptographic industry as a whole. CoinHive script itself is not officially a virus – the authors of this software suggest using extensions as a way to monetize those resources where there is no advertising.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps

A Google-sponsored search result for Claude installation instructions is...

Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix

A large-scale malware operation called StopAndProtect is exploiting thousands...

Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data

The Cl0p ransomware and extortion operation is likely exploiting...

Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion

Medusa ransomware operators have compromised over 500 organizations across...

Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click

A critical one-click vulnerability in Microsoft Copilot Personal, tracked...

Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity

Threat actors behind the Projextor campaign are abusing Electron-based...

Critical MLflow SSRF Flaw Exploited in the Wild

A critical unauthenticated server-side request forgery (SSRF) vulnerability in...

Related Articles

Recent News