Close X
Monday, November 25, 2024
ADVT 
National

The Rise Of Cryptojacking: How Hackers Hog Computer CPUs To Make Money

Darpan News Desk The Canadian Press, 20 Nov, 2017 11:57 AM
    VANCOUVER — Anyone casually surfing the internet at home can be deployed as an unwittingly productive member of a hacker's workforce, a practice known as "cryptojacking" that is on the rise.
     
    Internet sleuths have discovered malicious code on the websites of several major companies — including Canada's Loblaw Companies Ltd. — left by cryptojackers looking to break into computers and commandeer their processing power for cryptocurrency mining.
     
    Cryptocurrencies, such as Bitcoin, are digital "coins" created by groups of computers — known as miners — that work together to solve mathematical puzzles that verify transactions. The more puzzles they solve, the more currency they earn. The exercise is hugely taxing on a computer's processing power and the electricity it requires is expensive.
     
    By surreptitiously adding JavaScript code to a website, the central processing unit on a visitor's computer is employed to join the effort to mine a digital currency.
     
    "It basically just hogs your CPU," said Konstantin Beznosov, a professor at the University of British Columbia's electrical and computer engineering department. Computers that have been cryptojacked can become unresponsive or slow down significantly. The practice can also result in higher electricity bills.
     
    Web surfers have spotted such code on major websites, including American politics fact-checking site Politifact and CBS Corporation's Showtime and Showtime Anytime sites.
     
    In Canada, a web page for Shoppers Drug Mart job listings appeared to be trying to use visitors' computer power to mine for Monero via Coinhive — a website that provides other sites a cryptocurrency mining code embed in exchange for a share of the profits.
     
    Screenshots taken in late September offer limited information, said Daniel Tobok, CEO of cybersecurity boutique firm Cytelligence Inc., but appear to show a third party trying to leverage the website to connect to a cryptocurrency miner.
     
    Catherine Thomas, a spokeswoman for Shoppers' parent Loblaw, confirmed that code from a third party was present on the web page for a short time, but stressed that at no time was there a risk to anyone's machine or personal information.
     
    These types of breaches are extremely common, Tobok said.
     
     
     
    In 2013, Kapersky Lab's products detected such a threat about 205,000 times. In the first eight months of this year, the company's security software found 1.65 million users were attacked.
     
    A more invasive scenario is for hackers to install malicious code so that every time the person uses their computer to surf the web the hackers will attempt to mine for digital currency, Tobok said.
     
    "You become another spoke in the wheel."
     
    The Office of the Privacy Commissioner of Canada is aware of the issue but has not examined it in depth, according to a spokesperson.
     
    Targeted system owners may not always inform or request assistance from the Canadian Cyber Incident Response Centre, said spokesperson Jean-Philippe Levert.
     
    "As this type of malicious activity is generally intended to go unnoticed, it often is not destructive and does not result in loss of confidential information," Levert said, adding CCIRC is ready to assist if needed.
     
    Levert added CCIRC does not comment on whether reports have been received on specific incidents, like cryptojacking, to protect sensitive information submitted by those voluntarily reporting.
     
    For web surfers looking to avoid being cryptojacked, several internet browser extensions can block attempts, including No Coin and Ad Block Plus.
     
    But it's not always hackers behind the code. In some cases, companies knowingly run a cryptocurrency miner.
     
    File-sharing site The Pirate Bay, for example, tested Monero-miner Coinhive as a potential advertisement replacement, but faced complaints from users for not informing them about the practice after it was discovered.
     
    "We really want to get rid of all the ads. But we also need enough money to keep the site running," the company wrote in a September blog post, asking users for feedback on whether they'd prefer ads or giving "away a few of your CPU cycles every time you visit the site."
     
    New charities are also asking people to consider the relatively passive way to donate.
     
    The Clean Water Coin Initiative, a non-profit organization that has partnered with Charity: Water, has raised more than US$2,000 by asking people to donate 0.1 per cent of their digital currency transactions.
     
    Charity Mine asks users to keep its site open in a tab, so their unused CPU power can generate Monero for charity. While it's raised less than US$13 to date, the site estimates four million users could create roughly US$7.1 million annually.
     
     
     
     
    WHAT IS A DIGITAL CURRENCY AND HOW DOES CRYPTOCURRENCY MINING WORK?
     
     
    Cryptocurrency is a digital currency with no physical form or intrinsic value, but is an increasingly hot commodity as Bitcoin, its most well-known iteration, flirts with a record high.
     
    Bitcoin, the self-proclaimed original decentralized digital currency, is hovering around US$8,000 as investors pour into alternative currencies.
     
    Many other types of cryptocurrencies exist, including Monero and Litecoin. These digital currencies are decentralized, meaning there is no third-party authority like a bank that oversees activity, and transactions happen directly between two individuals. This offers some benefits, such as lower fees and global use.
     
    Cryptocurrencies rely on blockchain technology. The blockchain is a public ledger of the currency's transactions.
     
    Generally speaking, there are two ways to obtain cryptocurrencies: A person can purchase units on an exchange, or they can participate in cryptocurrency mining.
     
     
    Miners secure cryptocurrency networks. They receive new issues of the currency for verifying transactions, which are then recorded on the blockchain.
     
    Miners run software that can require special hardware, like asic chips — designed for Bitcoin mining. Their computers solve complicated math problems in exchange for new issues of the currency. A mathematical proof of work, created by trying billions of calculations per second, is required to confirm a Bitcoin transaction. The more puzzles a miner solves, the more cryptocurrency they earn — incentivizing miners to participate and strengthening the overall system.
     
    On Bitcoin's network, the problems become more complex if they are being solved too quickly. As more miners joined the system and the problems grew very difficult, miners started to pool together to do this work.
     
    Once purchased or mined, cryptocurrency lives in the individual's digital wallet and can be used to purchase items online or at local stores that accept the currency.
     
    The digital currency's value is derived from demand. At the time of writing, one Bitcoin was worth roughly $9,800 (it is highly volatile), while Monero has yet to hit four-digit worth.

    MORE National ARTICLES

    Loblaw Closing 22 Stores, Launching Home Delivery Ahead Of 'Difficult Year'

    Loblaw Closing 22 Stores, Launching Home Delivery Ahead Of 'Difficult Year'
    VANCOUVER — Loblaw Companies Ltd. is closing 22 stores and launching home delivery in two major Canadian cities, ahead of what it believes will be a challenging new year.

    Loblaw Closing 22 Stores, Launching Home Delivery Ahead Of 'Difficult Year'

    Court Sides With Filmmaker Who Took On Vancouver Aquarium's Captivity Practice

    Court Sides With Filmmaker Who Took On Vancouver Aquarium's Captivity Practice
      It says a lower court judge erred in ordering the filmmaker to remove 15 segments of his documentary that the aquarium said could cause the facility irreparable harm.

    Court Sides With Filmmaker Who Took On Vancouver Aquarium's Captivity Practice

    BC Junior Hockey Team Says No Money Received From $7.5M Donation Pledge

    BC Junior Hockey Team Says No Money Received From $7.5M Donation Pledge
    The board of directors of the Kimberley Dynamiters posted a statement Monday on Facebook thanking fans for their support and explaining that it had yet to receive the $7.5 million.

    BC Junior Hockey Team Says No Money Received From $7.5M Donation Pledge

    Vancouver Limits Short-term Airbnb Rentals In Laneway Houses, Basement Suites

    Vancouver Limits Short-term Airbnb Rentals In Laneway Houses, Basement Suites
    City council approved new regulations in a 7-4 vote Tuesday for vacation websites such as Airbnb and Expedia. The rules prohibit hosts from listing homes that are not their principal residence, including any secondary suites on their property.

    Vancouver Limits Short-term Airbnb Rentals In Laneway Houses, Basement Suites

    Toronto Constable Who Shot Teen Arrested For Allegedly Breaching Bail Conditions

    Toronto Constable Who Shot Teen Arrested For Allegedly Breaching Bail Conditions
    Ontario's police watchdog said Const. James Forcillo is accused of breaching the conditions related to his house arrest, but gave no other details about the case.

    Toronto Constable Who Shot Teen Arrested For Allegedly Breaching Bail Conditions

    Ultra Low-Cost Airline Battle Heats Up As Canada Jetlines Prepares To Launch

    Ultra Low-Cost Airline Battle Heats Up As Canada Jetlines Prepares To Launch
    MONTREAL — The ultra low-cost airline battle is heating up as fledgling airline Canada Jetlines prepares to take on WestJet's efforts to regain its mantle as the country's low-cost leader.

    Ultra Low-Cost Airline Battle Heats Up As Canada Jetlines Prepares To Launch