Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Wit Olszewski via Shutterstock

Number of websites infected by cryptocurrency hack, Ireland's National Cyber Security Centre says

It said that there are no indications at this stage that members of the public are at risk.

IRELAND’S NATIONAL CYBER Security Centre (NCSC) has said that it is aware that a number of websites have been infected by hackers using the sites’ to “mine” cryptocurrencies without their permission.

Thousands of websites around the world, including many operated by governments, have been affected by the breach, security researchers have said.

The attack is the first major incident made public in which a new breed of hackers took over a large number of websites to effectively create currencies like bitcoin which are generated by using computing power.

The attacks made public over the weekend by British security researcher Scott Helme showed more than 4,000 websites were infected in this manner, including those of the British data protection and privacy watchdog and the US federal courts system.

The NCSC said it has issued an advisory to all its constituents of government departments and agencies, as well as critical national infrastructure providers, “informing them of the issue and outlining a number of mitigation tech steps to prevent similar types of incidents occurring in the future”.

It said that there are no indications at this stage that members of the public are at risk. It has not indicated which websites have been infected by the hack.

“The NCSC will continue to monitor developments in relation to this matter.”

Type of attack

Unlike traditional attacks, these infections do not contain “ransomware” or steal data, but operate in stealth mode to make profits from the shadowy world of cryptocurrencies.

Helme said in a blog post yesterday that the hackers were able to reach large numbers of websites by infecting a commonly used “plug-in”, or software which helps a site run better.

In this case, the hackers used the malicious software to create Monero, one of several new cryptocurrencies which are making a splash in financial markets.

“If you want to load a crypto miner on 1,000+ websites you don’t attack 1,000+ websites, you attack the 1 website that they all load content from,” he said.

The creator of the plug-in, the British software firm TextHelp, said it took the affected software offline after it discovered the “attempt to illegally generate cryptocurrency”.

“This was a criminal act and a thorough investigation is currently underway,” the company said in a statement.

Increasing risk of attacks

Researchers have been warning in recent weeks about this kind of malware, which can deliver profits without being obvious to users.

Security researchers at Cisco Talos warned last month that this kind of hacking activity “has exponentially increased.”

Because of the huge financial gains in cryptocurrencies, Cisco researchers said this has become a prime target for hackers.

“At a high-level mining is simply using system resources to solve large mathematical calculations which result in some amount of cryptocurrency being awarded to the solvers,” Cisco researchers wrote in a research note.

Security researcher Graham Cluley said the latest attack highlights vulnerabilities in websites which may have weaknesses in third-party components.

“Things could have been much worse,” Cluley said in a blog post. “Imagine if the plug-in had been tampered with to steal login passwords rather than steal CPU resources from visiting computers.”

The NCSC is an operational arm of the Department of Communications, founded in 2011 and is responsible for overseeing the cybersecurity of government IT infrastructure.

With reporting by AFP. 

Read: Irish banks monitoring bitcoin buys on credit cards after UK bank brings in ban

More: Bitcoin brain teaser: This cryptic painting just earned someone €40,000

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
23 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Install the app to use these features.
    Mute Ciarán Ó Fallúin
    Favourite Ciarán Ó Fallúin
    Report
    Apr 16th 2018, 10:19 PM

    No doubt there will be a lot of older folks reading this feeling contemptuous, don’t judge it, until you’ve listened to him. He has captured and distilled the sense of unrest among African Americans better than any journalist or poet. Incredible artist.

    197
    Install the app to use these features.
    Mute Alan McCartney
    Favourite Alan McCartney
    Report
    Apr 16th 2018, 11:54 PM

    @Ciarán Ó Fallúin: ah there’s always unrest with them. They need something to blame.

    80
    Install the app to use these features.
    Mute Shy Tall Knight
    Favourite Shy Tall Knight
    Report
    Apr 16th 2018, 10:09 PM

    Be humble

    122
    Install the app to use these features.
    Mute Daniel Donovan
    Favourite Daniel Donovan
    Report
    Apr 16th 2018, 11:33 PM

    @Shy Tall Knight: Sit down

    32
    Install the app to use these features.
    Mute Sean Higgins
    Favourite Sean Higgins
    Report
    Apr 16th 2018, 10:25 PM

    In Spain a rapper has been sentenced for three and a half years in jail for criticizing the Royal Family, now that’s rough……….

    49
    Install the app to use these features.
    Mute Acedeuce
    Favourite Acedeuce
    Report
    Apr 16th 2018, 10:47 PM

    He’s no 2pac or biggie

    37
    Install the app to use these features.
    Mute Permo Dermo
    Favourite Permo Dermo
    Report
    Apr 17th 2018, 12:48 AM

    Rap is gobbledegook spouted over talented artists sampled riffs. Take away those riffs and whatcha ya got dawg?

    41
    Install the app to use these features.
    Mute Mark Donoghue
    Favourite Mark Donoghue
    Report
    Apr 17th 2018, 7:47 AM

    @Permo Dermo: a Pullizer?

    35
    Install the app to use these features.
    Mute Shaun Gallagher
    Favourite Shaun Gallagher
    Report
    Apr 17th 2018, 7:20 AM

    He was great in blazing saddles

    20
    Install the app to use these features.
    Mute Brendan Boyce
    Favourite Brendan Boyce
    Report
    Apr 16th 2018, 10:14 PM

    Lil Wayne be fuming

    24
    Install the app to use these features.
    Mute Jasun Ó Cearnaigh
    Favourite Jasun Ó Cearnaigh
    Report
    Apr 17th 2018, 7:46 AM

    Not even close to the best in the game but the commercial pull of Jimmy Iovine and Dre is too powerful! Fair play

    6
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.

Leave a commentcancel

 
JournalTv
News in 60 seconds