Tuesday, October 15, 2024
HomeComputer SecurityHackers Performing Massive Crypto-Mining Operation Via Hacked Website with Obfuscated Shortlink

Hackers Performing Massive Crypto-Mining Operation Via Hacked Website with Obfuscated Shortlink

Published on

Malware protection

The Cyber Criminals now using Obfuscated Coinhive’s Shortlink that silently mining cryptocurrency through the compromised website and it injected in various CMS used websites.

This year a lot of illegal mining operation has been discovered and the attack vector increasing day by day, unlike last year when ransomware incident was the top cyber attack around the globe and now hackers moved to mine the large amount cryptocurrency in illegal ways.

Also past few month browser mining are continuously increasing and affecting the many websites by attackers who discovered various vulnerabilities in CMS websites and compromising it to inject the mining malware.

- Advertisement - SIEM as a Service

In this case, researchers found the larger infrastructure receiving traffic from several thousand hacked sites that redirect the traffic to a central server which involved to distribute the standard crypto-miners.

Obfuscated Mining Operation

Initially, researchers discovered that traffic redirection to the websites that belong to coinhive domains by regular crawling and few hundreds of legitimate domain injected with Malicious code.

A domain called cnhv[.]co that belongs to coinhive calls the shortlinks, once the user clicks the link then it will be redirected which is abused by the cybercriminals and it placed as hidden iframes.

Once users click the hidden iframe link, it will keep waiting for the users and indicate it indicates to wait until the redirected being proceed, but meanwhile, users will unknowingly be mining for as long as they stay on the page.

Leverage Hacked Site and Blackhat SEO

There is a specific redirection pattern URI that indicates hacked websites are being redirected into a server at 5.45.79[.]15 and another crafted URI redirection referrer a site that leads to the Coinhive shortlink that will start the web miner.

There are several sites are injected with both the hidden cnvh[.]co iframe method, as well as via backdoors.

According to Malwarebytes, Apart from this, some Google or Bing searches showed us results that included the list of compromised sites that are acting as “doorways,” usually to a traffic distribution system or redirector (5.45.79[.]15).

Doorways mainly used to trick users downloading malicious coin miners instead of the file they were looking for.

In this campaign, hacked servers are instructed to download and run a Linux miner, generating profits for the perpetrators but incurring costs for their owners. Finally, it seems only fitting to see an abuse of Coinhive’s shortlinks to perform in-browser mining, Malwarebytes said.

Also Read:

Bithump Hacked – Hackers Steal $31 Million Worth Cryptocurrency

16 Person Hacker Group Arrested for Mining Cryptocurrency at Internet Cafes

Android Cryptocurrency Mining Malware Infecting Amazon Fire TV & Other Amazon Devices

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Splunk Enterprise Vulnerabilities let Attackers Execute Remote Code

Splunk has disclosed multiple vulnerabilities affecting its Enterprise product, which could allow attackers to...

OilRig Hackers Exploiting Microsoft Exchange Server To Steal Login Details

Earth Simnavaz, an Iranian state-sponsored cyber espionage group, has recently intensified its attacks on...

CoreWarrior Malware Attacking Windows Machines From Dozens Of IP Address

Researchers recently analyzed a CoreWarrior malware sample, which spreads aggressively by creating numerous copies...

TrickMo Malware Targets Android Devices to Steal Unlock Patterns and PINs

The recent discovery of the TrickMo Banking Trojan variant by Cleafy has prompted further...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Digital Wallets Bypassed To Allow Purchase With Stolen Cards

Digital wallets enable users to securely store their financial information on smart devices and...

Best SIEM Tools List For SOC Team – 2024

The Best SIEM tools for you will depend on your specific requirements, budget, and...

Oracle Releases Biggest Security Update in 2024 – 372 Vulnerabilities Are Fixed – Update Now!

Oracle has released its April 2024 Critical Patch Update (CPU), addressing 372 security vulnerabilities...