Hackers target smartphones to mine cryptocurrencies

Agencies
August 23, 2018

Paris, Aug 23: Has your smartphone suddenly slowed down, warmed up and the battery drained down for no apparent reason? If so, it may have been hijacked to mine cryptocurrencies.

This new type of cyberattack is called "cryptojacking" by security experts.

It "consists of entrapping an internet server, a personal computer or a smartphone to install malware to mine cryptocurrencies," said Gerome Billois, an expert at the IT service management company Wavestone.

Mining is basically the process of helping verify and process transactions in a given virtual currency. In exchange miners are now and then rewarded with some of the currency themselves.

Legitimate mining operations link thousands of processors together to increase the computing power available to earn cryptocurrencies.

Mining bitcoin, ethereum, monero and other cryptocurrencies may be very profitable, but it does require considerable investments and generates huge electricity bills.

But hackers have found a cheaper option: surreptitiously exploiting the processors in smartphones.

To lure victims, hackers turn to the digital world's equivalent of the Trojan horse subterfuge of Greek mythology: inside an innocuous-looking app or programme hides a malicious one.

The popularity of games makes them attractive for hackers.

"Recently, we have discovered that a version of the popular game Bug Smasher, installed from Google Play between one and five million times, has been secretly mining the cryptocurrency monero on users' devices," said researchers at IT security firm ESET.

Growing number of attacks

The phenomenon is apparently growing.

"More and more mobile applications hiding Trojan horses associated to a cryptocurrency mining programme have appeared on the platforms in the last 12 months," said David Emm, a security researcher at Kaspersky Lab, a leading supplier of computer security and anti-virus software.

"On mobiles the processing power available to criminals is less," but "there is a lot more of these devices, and therefore taking in total, they offer a greater potential," he added.

But for smartphone owners, the mining is at best a nuisance, slowing down the operation of the phone and making it warm to the touch as the processor struggles to unlock cryptocurrency and accomplish other task.

At worst, it can damage the phone.

"On Android devices, the computational load can even lead to 'bloating' of the battery and thus to physical damage to, or destruction of, the device," said ESET.

However, "users are generally unaware" they have been cryptojacked, said Emm.

Cryptojacking affects mostly smartphones running Google's Android operating system.

Apple exercises more control over apps that can be installed on its phones, so hackers have targetted iPhones less.

But Google recently cleaned up its app store, Google Play, telling developers that it will no longer accept apps that mine cryptocurrencies on its platform.

"It is difficult to know which applications to block," said Pascal Le Digol, the country manager in France for US IT security firm WatchGuard, given that "there are new ones every day."

Moreover, as the miners try to "be as discreet as possible" the apps do not stand out immediately, he added.

How to save your phone

There are steps to take to protect one's phone.

Besides installing an antivirus programme, it is important "to update your Android phone" to the latest version of the operating system available to it, said online fraud expert Laurent Petroque at F5 Networks.

He also noted that "people who decide to download apps from non-official sources are at more risk of inadvertently downloading a malicious app".

Defending against cyberattacks of all kinds is "a game of cat and mouse", said Le Digol at WatchGuard. "You need to constantly adapt to the evolution of threats."

In this case he said "the mouse made a large leap", said Le Digol, adding cryptojacking could evolve to other forms in the future to include all types of connected objects.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 22,2020

New delhi, Jun 22: As consumer sentiment runs high amid growing chorus for boycotting Chinese goods in the country, the fluid market situation offers new opportunities for various smartphone makers, especially the non-Chinese ones like Samsung, Apple, Nokia, Asus and others, to realign their strategies and regain the lost market share in the face of fierce Chinese competition.

The challenge here would be not to look "opportunistic" and leverage the current explosive situation on just riding on the anti-Chinese sentiment but to offer real challenges in the form of top-end devices with solid internals at affordable price points, feel industry experts.

"The current market conditions in India are fluid and open up new opportunities for smartphone original equipment manufacturers (OEMs) to focus and leverage," Prabhu Ram, Head-Industry Intelligence Group, CyberMedia Research (CMR), told IANS.

In the first quarter (January-March) this year, Samsung's shipments were driven by its upgraded A and M series (A51, A20s, A30s, and M30s).

According to Counterpoint Research, Samsung managed to hold third position in Q1 2020 due to launches across several price tiers, especially in the affordable premium segment (S10 Lite, Note 10 Lite).

The South Korean smartphone maker last week announced a Rs 4,000 price drop on its popular Galaxy Note10 Lite smartphone that will now cost Rs 37,999 (6GB variant).

Earlier this month, Samsung launched two new smartphones, Galaxy M11 and Galaxy M01, with powerful batteries under Rs 15,000 in India.

Galaxy M11 comes in two variants. The 3GB+32GB will be priced at Rs 10,999 while the higher 4GB+64GB variant will be available for Rs 12,999.

Samsung has also launched an affordable Galaxy A21s smartphone with quad-camera system and 5,000mAh battery at a starting price of Rs 16,499.

Also read: Boycott China? OnePlus 8 Pro sold out within minutes of going on sale

On the other hand, Apple grew a strong 78 per cent YoY driven by strong shipments of iPhone 11 and multiple discounts on platforms like Flipkart and Amazon in Q1, according to Counterpoint.

Apple has also brought its cheapest yet powerful new iPhone SE that costs Rs 38,900 (64GB) in India with a special offer from HDFC Bank. The new iPhone SE is powered by the Apple-designed A13 Bionic, the fastest chip in a smartphone and features the best single-camera system ever in an iPhone.

According to Tarun Pathak, Associate Director, Counterpoint Research, consumer sentiments are running high and a section of users will look for alternatives, benefitting global and Indian brands.

"However, we do not think non-Chinese brands will run aggressive campaigns based on the situation as it might look like being opportunistic," Pathak told media.

It may actually let brands of Chinese origin try to run aggressive campaigns on their presence and scale.

"Some of these Chinese brands have been active in scaling up local value addition, creating jobs and investing in research and development," Pathak noted.

On Saturday, market leader Xiaomi said that it is "more Indian" than any other smartphone brand.

The company's India head Manu Kumar Jain said that the company's mobile phone R&D centre and product team is in India, it employs 50,000 people in the country, the entire leadership team is Indian and that the company pays its taxes in India.

Earlier, Realme India CEO Madhav Sheth who is also very active on social media said that Realme is an Indian startup.

In his latest episode of Ask Madhav' series on YouTube, Sheth said: "I can proudly say Realme is an Indian startup, which is now a global MNC (multinational corporation)".

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 12,2020

New Delhi, Jun 12: The Supreme Court on Friday asked Solicitor General Tushar Mehta to convene a meeting of the Finance Ministry and RBI officials over the weekend to decide whether interest incurred on EMIs during the moratorium period can be charged by banks.

A bench comprising Justices Ashok Bhushan, Sanjay Kishan Kaul and M.R. Shah queried Mehta as the court was concerned since the Centre has deferred loan for three months.

"Then how can interest of these 3 months be added?" the apex bench asked. Mehta replied: "I need to sit down with the RBI officials and have a meeting."

SBI's counsel, senior advocate Mukul Rohatgi, intervened during the proceedings and said "all banks are of the view that interest cannot be waived for a six month EMI moratorium period".

"We need to discuss it with the RBI," insisted Rohatgi.

Justice Bhushan then asked Mehta to convene a meeting of the RBI and Finance Ministry officials over the weekend, and listed the matter for further hearing on June 17.

The top court, during the hearing, indicated that it was not considering a complete waiver of interest but was only concerned that postponement of interest shouldn't accrue further interest on it.

After the RBI said the waiver of interest charges on EMIs during moratorium will lead to loss of 1 per cent of the nation's GDP, the top court had earlier asked the Finance Ministry to reply, whether the interest could be waived or it would continue during the moratorium period.

The top court said these are not normal times, and it is a serious issue, as on one hand moratorium is granted and then, the interest is charged on loans during this period.

"There are two issues in this (matter). No interest during the moratorium period and no interest on interest," said Justice Bhushan. The observation from the bench came on a petition by Gajendra Sharma, in which he sought a direction to declare portion of the RBI's March 27 notification as ultra vires to the extent it charged interest on the loan amount during the moratorium period.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 19,2020

Cybersecurity researchers on Monday warned of a Trojan malware campaign which is targeting India's co-operative banks using COVID-19 as a bait.

Seqrite, the enterprise arm of IT security firm Quick Heal Technologies, detected the new wave of Adwind Java Remote Access Trojan (RAT) campaign.

Researchers at Seqrite warned that if attackers are successful, they can take over the victim's device to steal sensitive data like SWIFT logins and customer details and move laterally to launch large scale cyberattacks and financial frauds.

According to the researchers, the Java RAT campaign starts with a spear-phishing email which claims to have originated from either the Reserve Bank of India or a nationalised bank.

The content of the email refers to COVID-19 guidelines or a financial transaction, with detailed information in an attachment, which is a zip file containing a JAR based malware.

Upon further investigation, researchers at Seqrite found that the JAR based malware is a Remote Access Trojan that can run on any machine which has Java runtime enabled and hence it can impact a variety of endpoints, irrespective of their base operating system.

Once the RAT is installed, the attacker can take over the victim's device, send commands from a remote machine, and spread laterally in the network.

In addition, this malware can also log keystrokes, capture screenshots, download additional payloads, and extract sensitive user information, Seqrite said, adding that such attack campaigns can effectively jeopardise the privacy and security of sensitive data at the co-operative banks and result in large scale attacks and financial frauds.

To prevent such attacks, users need to exercise ample caution and avoid opening attachments and clicking on web links in unsolicited emails.

Banks should also keep their operating systems updated and have a full-fledged security solution installed on all the devices, Seqrite advised.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.