Is the web browser on your phone slower than usual? It could be mining bitcoin for criminals.
As the popularity of virtual currencies has grown, hackers are focusing on a new type of heist: putting malicious software on peoples' handsets, TVs and smart fridges that makes them mine for digital money.
So-called "crypto-jacking" attacks have become a growing problem in the cybersecurity industry, affecting both consumers and organisations. Depending on the severity of the attack, victims may notice only a slight drop in processing power, often not enough for them to think it's a hacking attack. But that can add up to a lot of processing power over a period of months or if, say, a business's entire network of computers is affected.
"We saw organisations whose monthly electricity bill was increased by hundreds of thousands of dollars," says Maya Horowitz, Threat Intelligence Group Manager for Checkpoint, a cybersecurity company.
Hackers try to use victims' processing power because that is what's needed to create - or "mine" - virtual currencies. In virtual currency mining, computers are used to make the complex calculations that verify a running ledger of all the transactions in virtual currencies around the world.
Crypto-jacking is not done only by installing malicious software. It can also be done through a web browser. The victim visits a site, which latches onto the victim's computer processing power to mine digital currencies as long as they are on the site. When the victim switches, the mining ends. Some websites, including Salon.com, have tried to do it legitimately and been transparent about it. For three months this year, Salon.com removed ads from its sites in exchange for users allowing them to mine virtual currencies.
Industry experts first noted crypto-jacking as a threat in 2017, when virtual currency prices were skyrocketing to record highs.
The price of bitcoin, the most widely known virtual currency, jumped six-fold from September to almost $20,000 in December before falling back down to under $10,000.
The number of crypto-jacking cases soared from 146,704 worldwide in September to 22.4 million in December, according to anti-virus developer Avast. It has only continued to increase, to 93 million in May, it says.
_______
Read more:
Bitcoin's 2018 crash stokes fears of a Dot-Com like meltdown
ADGM launches framework to govern spot crypto assets
Crypto influencers are hyping up the market with $105,000 tweets
Avoid the cryptocurrency 'rat poison' and exit while you can
_______
The first big case emerged in September and centered on Coinhive, a legitimate business that let website owners make money by allowing customers to mine virtual currency instead of relying on advertising revenue. Hackers quickly began to use the service to infect vulnerable sites with miners, most notably YouTube and nearly 50,000 Wordpress websites, according to research conducted by Troy Mursch, a researcher on crypto-jacking.
Mr Mursch says Monero is the most popular virtual currency among cyber-criminals. A report by cybersecurity company Palo Alto Networks estimates that over 5 per cent of Monero was mined through crypto-jacking. That is worth almost $150 million dollars and doesn't count mining that occurs through browsers.
In the majority of attacks, hackers infect as many devices as possible, a method experts calls "spray and pray."
"Basically, everyone with a (computer processing unit) can be targeted by crypto-jacking," says Ismail Belkacim, a developer of an application that prevents websites from mining virtual currencies.
As a result, some hackers target organisations with large computing power. In what they believe might be the biggest crypto-jacking attack so far, Checkpoint discovered in February that a hacker had been exploiting a vulnerability in a server that over several months generated over $3m in Monero.
Crypto-jackers have also recently targeted organisations that use cloud-based services, in which a network of servers is used to process and store data, providing more computing power to companies who haven't invested in extra hardware.
Abusing this service, crypto-jackers use as much power as the cloud will allow them to, maximising their gains. For businesses, this results in slower performance and higher energy bills.
Martin Hron, a security researcher at Avast, says that besides the rise in interest in virtual currencies, there are two main reasons for the rise in attacks.
First, crypto-jacking scripts require little skill to implement. Ready-made computer code that automates crypto-mining is easy to find with a Google search, along with tips on the vulnerabilities of devices.
Second, crypto-jacking is harder to detect and is more anonymous than other hacks. Unlike ransomware, in which victims have to transfer money to regain access to their computers blocked by hackers, a victim of crypto-jacking might never know their computer is being used to mine currency. And as currency generated by crypto-jacking goes straight into a hacker's encrypted wallet, the cyber-criminal leaves less of a trail.
Both Apple and Google have started to ban applications that mine virtual currencies on their devices. But Mr Hron, the Avast researcher, warns that the risk is growing as more everyday devices are connected to the internet - from ovens to home lighting systems - and that these are often the least secure. Mr Hron says that cheaply made Chinese devices were particularly easy to hack.
Some experts say new techniques like artificial intelligence can help get a faster response to suspicious software.
That's what Texthelp, an education technology company, used when it was infected with a crypto-jacker, says Martin McKay, the company's chief technology officer. "The risk was mitigated for all customers within a period of four hours."
But security researcher Mr Mursch says that these precautions won't be enough.
"They might reduce the impact," he says, "But I don't think we're going to stop it."
COMPANY PROFILE
Name: Rain Management
Year started: 2017
Based: Bahrain
Employees: 100-120
Amount raised: $2.5m from BitMex Ventures and Blockwater. Another $6m raised from MEVP, Coinbase, Vision Ventures, CMT, Jimco and DIFC Fintech Fund
The Transfiguration
Director: Michael O’Shea
Starring: Eric Ruffin, Chloe Levine
Three stars
Specs
Engine: Dual-motor all-wheel-drive electric
Range: Up to 610km
Power: 905hp
Torque: 985Nm
Price: From Dh439,000
Available: Now
At a glance
Global events: Much of the UK’s economic woes were blamed on “increased global uncertainty”, which can be interpreted as the economic impact of the Ukraine war and the uncertainty over Donald Trump’s tariffs.
Growth forecasts: Cut for 2025 from 2 per cent to 1 per cent. The OBR watchdog also estimated inflation will average 3.2 per cent this year
Welfare: Universal credit health element cut by 50 per cent and frozen for new claimants, building on cuts to the disability and incapacity bill set out earlier this month
Spending cuts: Overall day-to day-spending across government cut by £6.1bn in 2029-30
Tax evasion: Steps to crack down on tax evasion to raise “£6.5bn per year” for the public purse
Defence: New high-tech weaponry, upgrading HM Naval Base in Portsmouth
Housing: Housebuilding to reach its highest in 40 years, with planning reforms helping generate an extra £3.4bn for public finances
Get Out
Director: Jordan Peele
Stars: Daniel Kaluuya, Allison Williams, Catherine Keener, Bradley Whitford
Four stars
Our legal columnist
Name: Yousef Al Bahar
Advocate at Al Bahar & Associate Advocates and Legal Consultants, established in 1994
Education: Mr Al Bahar was born in 1979 and graduated in 2008 from the Judicial Institute. He took after his father, who was one of the first Emirati lawyers
2025 Fifa Club World Cup groups
Group A: Palmeiras, Porto, Al Ahly, Inter Miami.
Group B: Paris Saint-Germain, Atletico Madrid, Botafogo, Seattle.
Group C: Bayern Munich, Auckland City, Boca Juniors, Benfica.
Group D: Flamengo, ES Tunis, Chelsea, (Leon banned).
Group E: River Plate, Urawa, Monterrey, Inter Milan.
Group F: Fluminense, Borussia Dortmund, Ulsan, Mamelodi Sundowns.
Group G: Manchester City, Wydad, Al Ain, Juventus.
Group H: Real Madrid, Al Hilal, Pachuca, Salzburg.
THREE
%3Cp%3EDirector%3A%20Nayla%20Al%20Khaja%3C%2Fp%3E%0A%3Cp%3EStarring%3A%20Jefferson%20Hall%2C%20Faten%20Ahmed%2C%20Noura%20Alabed%2C%20Saud%20Alzarooni%3C%2Fp%3E%0A%3Cp%3ERating%3A%203.5%2F5%3C%2Fp%3E%0A
Roll%20of%20Honour%2C%20men%E2%80%99s%20domestic%20rugby%20season
%3Cp%3E%3Cstrong%3EWest%20Asia%20Premiership%3C%2Fstrong%3E%0D%3Cbr%3EChampions%3A%20Dubai%20Tigers%0D%3Cbr%3ERunners%20up%3A%20Bahrain%0D%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EUAE%20Premiership%3C%2Fstrong%3E%0D%3Cbr%3EChampions%3A%20Jebel%20Ali%20Dragons%0D%3Cbr%3ERunners%20up%3A%20Dubai%20Hurricanes%0D%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EUAE%20Division%201%3C%2Fstrong%3E%0D%3Cbr%3EChampions%3A%20Dubai%20Sharks%0D%3Cbr%3ERunners%20up%3A%20Abu%20Dhabi%20Harlequins%20II%0D%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EUAE%20Division%202%3C%2Fstrong%3E%0D%3Cbr%3EChampions%3A%20Dubai%20Tigers%20III%0D%3Cbr%3ERunners%20up%3A%20Dubai%20Sharks%20II%0D%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EDubai%20Sevens%3C%2Fstrong%3E%0D%3Cbr%3EChampions%3A%20Dubai%20Tigers%0D%3Cbr%3ERunners%20up%3A%20Dubai%20Hurricanes%3C%2Fp%3E%0A
Infobox
Western Region Asia Cup Qualifier, Al Amerat, Oman
The two finalists advance to the next stage of qualifying, in Malaysia in August
Results
UAE beat Iran by 10 wickets
Kuwait beat Saudi Arabia by eight wickets
Oman beat Bahrain by nine wickets
Qatar beat Maldives by 106 runs
Monday fixtures
UAE v Kuwait, Iran v Saudi Arabia, Oman v Qatar, Maldives v Bahrain
UAE currency: the story behind the money in your pockets
Real estate tokenisation project
Dubai launched the pilot phase of its real estate tokenisation project last month.
The initiative focuses on converting real estate assets into digital tokens recorded on blockchain technology and helps in streamlining the process of buying, selling and investing, the Dubai Land Department said.
Dubai’s real estate tokenisation market is projected to reach Dh60 billion ($16.33 billion) by 2033, representing 7 per cent of the emirate’s total property transactions, according to the DLD.
Ms Yang's top tips for parents new to the UAE
- Join parent networks
- Look beyond school fees
- Keep an open mind
WHAT IS A BLACK HOLE?
1. Black holes are objects whose gravity is so strong not even light can escape their pull
2. They can be created when massive stars collapse under their own weight
3. Large black holes can also be formed when smaller ones collide and merge
4. The biggest black holes lurk at the centre of many galaxies, including our own
5. Astronomers believe that when the universe was very young, black holes affected how galaxies formed
How to apply for a drone permit
- Individuals must register on UAE Drone app or website using their UAE Pass
- Add all their personal details, including name, nationality, passport number, Emiratis ID, email and phone number
- Upload the training certificate from a centre accredited by the GCAA
- Submit their request
What are the regulations?
- Fly it within visual line of sight
- Never over populated areas
- Ensure maximum flying height of 400 feet (122 metres) above ground level is not crossed
- Users must avoid flying over restricted areas listed on the UAE Drone app
- Only fly the drone during the day, and never at night
- Should have a live feed of the drone flight
- Drones must weigh 5 kg or less
The specs
Engine: 2.0-litre 4-cyl turbo
Power: 201hp at 5,200rpm
Torque: 320Nm at 1,750-4,000rpm
Transmission: 6-speed auto
Fuel consumption: 8.7L/100km
Price: Dh133,900
On sale: now
The studios taking part (so far)
- Punch
- Vogue Fitness
- Sweat
- Bodytree Studio
- The Hot House
- The Room
- Inspire Sports (Ladies Only)
- Cryo
What is the FNC?
The Federal National Council is one of five federal authorities established by the UAE constitution. It held its first session on December 2, 1972, a year to the day after Federation.
It has 40 members, eight of whom are women. The members represent the UAE population through each of the emirates. Abu Dhabi and Dubai have eight members each, Sharjah and Ras al Khaimah six, and Ajman, Fujairah and Umm Al Quwain have four.
They bring Emirati issues to the council for debate and put those concerns to ministers summoned for questioning.
The FNC’s main functions include passing, amending or rejecting federal draft laws, discussing international treaties and agreements, and offering recommendations on general subjects raised during sessions.
Federal draft laws must first pass through the FNC for recommendations when members can amend the laws to suit the needs of citizens. The draft laws are then forwarded to the Cabinet for consideration and approval.
Since 2006, half of the members have been elected by UAE citizens to serve four-year terms and the other half are appointed by the Ruler’s Courts of the seven emirates.
In the 2015 elections, 78 of the 252 candidates were women. Women also represented 48 per cent of all voters and 67 per cent of the voters were under the age of 40.
The Al Barzakh Festival takes place on Wednesday and Thursday at 7.30pm in the Red Theatre, NYUAD, Saadiyat Island. Tickets cost Dh105 for adults from platinumlist.net
Fixtures
Sunday, December 8, Sharjah Cricket Stadium – UAE v USA
Monday, December 9, Sharjah Cricket Stadium – USA v Scotland
Wednesday, December 11, Sharjah Cricket Stadium – UAE v Scotland
Thursday, December 12, ICC Academy, Dubai – UAE v USA
Saturday, December 14, ICC Academy, Dubai – USA v Scotland
Sunday, December 15, ICC Academy, Dubai – UAE v Scotland
Note: All matches start at 10am, admission is free
UAE currency: the story behind the money in your pockets
THE SPECS
Engine: 6.75-litre twin-turbocharged V12 petrol engine
Power: 420kW
Torque: 780Nm
Transmission: 8-speed automatic
Price: From Dh1,350,000
On sale: Available for preorder now
Company%20Profile
%3Cp%3E%3Cstrong%3EName%3A%3C%2Fstrong%3E%20Raha%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%202022%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Kuwait%2FSaudi%3Cbr%3E%3Cstrong%3EIndustry%3A%3C%2Fstrong%3E%20Tech%20Logistics%3Cbr%3E%3Cstrong%3EFunding%3A%3C%2Fstrong%3E%20%2414%20million%3Cbr%3E%3Cstrong%3EInvestors%3A%3C%2Fstrong%3E%20Soor%20Capital%2C%20eWTP%20Arabia%20Capital%2C%20Aujan%20Enterprises%2C%20Nox%20Management%2C%20Cedar%20Mundi%20Ventures%3Cbr%3E%3Cstrong%3ENumber%20of%20employees%3A%3C%2Fstrong%3E%20166%3C%2Fp%3E%0A
Specs
Engine: 51.5kW electric motor
Range: 400km
Power: 134bhp
Torque: 175Nm
Price: From Dh98,800
Available: Now
Warlight,
Michael Ondaatje, Knopf
COMPANY PROFILE
Name: Kumulus Water
Started: 2021
Founders: Iheb Triki and Mohamed Ali Abid
Based: Tunisia
Sector: Water technology
Number of staff: 22
Investment raised: $4 million