Friday, February 28, 2025
HomeComputer SecurityHackers Performing Massive Crypto-Mining Operation Via Hacked Website with Obfuscated Shortlink

Hackers Performing Massive Crypto-Mining Operation Via Hacked Website with Obfuscated Shortlink

Published on

SIEM as a Service

Follow Us on Google News

The Cyber Criminals now using Obfuscated Coinhive’s Shortlink that silently mining cryptocurrency through the compromised website and it injected in various CMS used websites.

This year a lot of illegal mining operation has been discovered and the attack vector increasing day by day, unlike last year when ransomware incident was the top cyber attack around the globe and now hackers moved to mine the large amount cryptocurrency in illegal ways.

Also past few month browser mining are continuously increasing and affecting the many websites by attackers who discovered various vulnerabilities in CMS websites and compromising it to inject the mining malware.

In this case, researchers found the larger infrastructure receiving traffic from several thousand hacked sites that redirect the traffic to a central server which involved to distribute the standard crypto-miners.

Obfuscated Mining Operation

Initially, researchers discovered that traffic redirection to the websites that belong to coinhive domains by regular crawling and few hundreds of legitimate domain injected with Malicious code.

A domain called cnhv[.]co that belongs to coinhive calls the shortlinks, once the user clicks the link then it will be redirected which is abused by the cybercriminals and it placed as hidden iframes.

Once users click the hidden iframe link, it will keep waiting for the users and indicate it indicates to wait until the redirected being proceed, but meanwhile, users will unknowingly be mining for as long as they stay on the page.

Leverage Hacked Site and Blackhat SEO

There is a specific redirection pattern URI that indicates hacked websites are being redirected into a server at 5.45.79[.]15 and another crafted URI redirection referrer a site that leads to the Coinhive shortlink that will start the web miner.

There are several sites are injected with both the hidden cnvh[.]co iframe method, as well as via backdoors.

According to Malwarebytes, Apart from this, some Google or Bing searches showed us results that included the list of compromised sites that are acting as “doorways,” usually to a traffic distribution system or redirector (5.45.79[.]15).

Doorways mainly used to trick users downloading malicious coin miners instead of the file they were looking for.

In this campaign, hacked servers are instructed to download and run a Linux miner, generating profits for the perpetrators but incurring costs for their owners. Finally, it seems only fitting to see an abuse of Coinhive’s shortlinks to perform in-browser mining, Malwarebytes said.

Also Read:

Bithump Hacked – Hackers Steal $31 Million Worth Cryptocurrency

16 Person Hacker Group Arrested for Mining Cryptocurrency at Internet Cafes

Android Cryptocurrency Mining Malware Infecting Amazon Fire TV & Other Amazon Devices

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Chinese Hackers Breach Belgium State Security Service as Investigation Continues

Belgium’s State Security Service (VSSE) has suffered what is being described as its most...

Hacktivist Groups Emerge With Powerful Tools for Large-Scale Cyber Operations

Hacktivism, once synonymous with symbolic website defacements and distributed denial-of-service (DDoS) attacks, has evolved...

New Pass-the-Cookie Attacks Bypass MFA, Giving Hackers Full Account Access

Multi-factor authentication (MFA), long considered a cornerstone of cybersecurity defense, is facing a formidable...

Chinese Hackers Exploit Check Point VPN Zero-Day to Target Organizations Globally

A sophisticated cyberespionage campaign linked to Chinese state-sponsored actors has exploited a previously patched...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Is this Website Safe: How to Check Website Safety – 2025

is this website safe? In this digital world, Check a website is safe is...

Firefox 133.0 Released with Multiple Security Updates – What’s New!

Mozilla has officially launched Firefox 133.0, offering enhanced features, significant performance improvements, and critical...

Digital Wallets Bypassed To Allow Purchase With Stolen Cards

Digital wallets enable users to securely store their financial information on smart devices and...