Hackers target smartphones to mine cryptocurrencies

Agencies
August 23, 2018

Paris, Aug 23: Has your smartphone suddenly slowed down, warmed up and the battery drained down for no apparent reason? If so, it may have been hijacked to mine cryptocurrencies.

This new type of cyberattack is called "cryptojacking" by security experts.

It "consists of entrapping an internet server, a personal computer or a smartphone to install malware to mine cryptocurrencies," said Gerome Billois, an expert at the IT service management company Wavestone.

Mining is basically the process of helping verify and process transactions in a given virtual currency. In exchange miners are now and then rewarded with some of the currency themselves.

Legitimate mining operations link thousands of processors together to increase the computing power available to earn cryptocurrencies.

Mining bitcoin, ethereum, monero and other cryptocurrencies may be very profitable, but it does require considerable investments and generates huge electricity bills.

But hackers have found a cheaper option: surreptitiously exploiting the processors in smartphones.

To lure victims, hackers turn to the digital world's equivalent of the Trojan horse subterfuge of Greek mythology: inside an innocuous-looking app or programme hides a malicious one.

The popularity of games makes them attractive for hackers.

"Recently, we have discovered that a version of the popular game Bug Smasher, installed from Google Play between one and five million times, has been secretly mining the cryptocurrency monero on users' devices," said researchers at IT security firm ESET.

Growing number of attacks

The phenomenon is apparently growing.

"More and more mobile applications hiding Trojan horses associated to a cryptocurrency mining programme have appeared on the platforms in the last 12 months," said David Emm, a security researcher at Kaspersky Lab, a leading supplier of computer security and anti-virus software.

"On mobiles the processing power available to criminals is less," but "there is a lot more of these devices, and therefore taking in total, they offer a greater potential," he added.

But for smartphone owners, the mining is at best a nuisance, slowing down the operation of the phone and making it warm to the touch as the processor struggles to unlock cryptocurrency and accomplish other task.

At worst, it can damage the phone.

"On Android devices, the computational load can even lead to 'bloating' of the battery and thus to physical damage to, or destruction of, the device," said ESET.

However, "users are generally unaware" they have been cryptojacked, said Emm.

Cryptojacking affects mostly smartphones running Google's Android operating system.

Apple exercises more control over apps that can be installed on its phones, so hackers have targetted iPhones less.

But Google recently cleaned up its app store, Google Play, telling developers that it will no longer accept apps that mine cryptocurrencies on its platform.

"It is difficult to know which applications to block," said Pascal Le Digol, the country manager in France for US IT security firm WatchGuard, given that "there are new ones every day."

Moreover, as the miners try to "be as discreet as possible" the apps do not stand out immediately, he added.

How to save your phone

There are steps to take to protect one's phone.

Besides installing an antivirus programme, it is important "to update your Android phone" to the latest version of the operating system available to it, said online fraud expert Laurent Petroque at F5 Networks.

He also noted that "people who decide to download apps from non-official sources are at more risk of inadvertently downloading a malicious app".

Defending against cyberattacks of all kinds is "a game of cat and mouse", said Le Digol at WatchGuard. "You need to constantly adapt to the evolution of threats."

In this case he said "the mouse made a large leap", said Le Digol, adding cryptojacking could evolve to other forms in the future to include all types of connected objects.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 19,2020

New Delhi, Jul 19: Indian equities will be driven by a host of factors like corporate earnings, coronavirus cases trend and geo-political developments this week, according to analysts.

Market participants will also keenly watch the progress of monsoon, with experts saying that the farm sector revival will play a key role in lifting the coronavirus-hit economy.

"With no major event, the ongoing earnings season and global cues will continue to dictate the market trend. Besides, the progress of monsoon will also be closely watched," Ajit Mishra, VP - Research, Religare Broking, said.

Globally, the rising coronavirus infections and geo-political tensions have created uncertainty on the economic recovery front.

With India's COVID-19 cases fast approaching the 11 lakh mark, the third-highest behind the US and Brazil, and the death toll nearing 27,000, participants are expected to tread cautiously going forward.

At global level, confirmed COVID-19 cases have crossed 1.4 crore and deaths totalled about 6 lakh.

Markets globally will closely follow developments on the trade and political level between the US and China, according to analysts.

"We would continue witnessing stock-specific action as the earnings season unfold. Though the near-term momentum looks positive, we would advise traders to be cautious, given flaring US-China trade relations, persistent rise in virus cases and implementation of fresh lockdowns in parts of the country," said Siddhartha Khemka, Head - Retail Research, Motilal Oswal Financial Services Ltd.

HDFC Bank will remain in focus on Monday after having announced its June quarter earnings on Saturday.

The lender reported 19.6 per cent rise in its standalone net profit at Rs 6,658.62 crore for April-June 2020; while its income rose to Rs 34,453.28 crore during the quarter.

Other major companies to announce their quarterly results this week are Axis Bank, Bajaj Finance, Hindustan Unilever Limited, Bajaj Auto and ITC.

"Going ahead market participants will closely track the development related to covid vaccine, the rising infection of coronavirus, development on economic activities, corporate earnings and US-China relationship," said Sumeet Bagadia, Executive Director, Choice Broking.

On weekly basis, the Sensex gathered 425.81 points or 1.16 per cent, and the Nifty gained 133.65 points or 1.24 per cent.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 3,2020

Facebook on Monday launched a new consumer marketing campaign in India titled 'More Together'. India is the first country in the Asia Pacific region where such a campaign is being rolled out.

It is also the first time that Facebook is rolling out a 'high decibel campaign of this stature in India', the company said in a statement.

It is also the first time that Facebook is rolling out a 'high decibel campaign of this stature in India', the company said in a statement.

"India is at the heart of Facebook and one of our focus areas this year is to tell the exciting story of a service that is deeply embedded in the fabric of India," said Ajit Mohan, Vice President and Managing Director, Facebook India.

The campaign would have multiple campaigns over the next few weeks in eight languages and the one will be set in the context of Holi.

Facebook in 2019 introduced a new company logo to further distinguish the company from the Facebook app.

The company recently announced the appointment of Avinash Pant as the Marketing Director for India operations, to drive the consumer marketing efforts across the family of apps.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 19,2020

Cybersecurity researchers on Monday warned of a Trojan malware campaign which is targeting India's co-operative banks using COVID-19 as a bait.

Seqrite, the enterprise arm of IT security firm Quick Heal Technologies, detected the new wave of Adwind Java Remote Access Trojan (RAT) campaign.

Researchers at Seqrite warned that if attackers are successful, they can take over the victim's device to steal sensitive data like SWIFT logins and customer details and move laterally to launch large scale cyberattacks and financial frauds.

According to the researchers, the Java RAT campaign starts with a spear-phishing email which claims to have originated from either the Reserve Bank of India or a nationalised bank.

The content of the email refers to COVID-19 guidelines or a financial transaction, with detailed information in an attachment, which is a zip file containing a JAR based malware.

Upon further investigation, researchers at Seqrite found that the JAR based malware is a Remote Access Trojan that can run on any machine which has Java runtime enabled and hence it can impact a variety of endpoints, irrespective of their base operating system.

Once the RAT is installed, the attacker can take over the victim's device, send commands from a remote machine, and spread laterally in the network.

In addition, this malware can also log keystrokes, capture screenshots, download additional payloads, and extract sensitive user information, Seqrite said, adding that such attack campaigns can effectively jeopardise the privacy and security of sensitive data at the co-operative banks and result in large scale attacks and financial frauds.

To prevent such attacks, users need to exercise ample caution and avoid opening attachments and clicking on web links in unsolicited emails.

Banks should also keep their operating systems updated and have a full-fledged security solution installed on all the devices, Seqrite advised.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.