After The Closure Of Coinhive, The Number Of Crypto-jacking Attacks Decreased By 99%

✨ Megiddo

✨ President ✨
Staff member
Joined
May 15, 2016
Messages
14,120
Likes
2,643
Points
1,730
A group of researchers from the American University of Cincinnati and the Canadian University of Lakehead in calculated that after the closure of the mining service Coinhive, which occurred a year ago , browser mining (aka cryptojacking) almost disappeared. According to analysts, online advertising brings a much greater income. Let me remind you that Coinhive appeared in the fall of 2017 and was then positioned as an alternative to classic banner advertising. As a result, Coinhive only generated a large-scale phenomenon, which IB experts called crypto jacking, or browser mining. It became quite “unsuccessful” for users to enter any site that has special JavaScript Coinhive (or other similar service, of whichdozens soon appeared ), and the resources of the victims' machines were already used for mining the Monero cryptocurrency. Although Coinhive operators admitted that they did not want to create a tool to enrich cybercriminals at all and directly condemned the actions of attackers. Ultimately, in the spring of 2019, the service closed a year after the Monero hard fork, as the hash rate dropped by more than 50%. In addition, the decision of the Coinhive developers was influenced by the general “collapse” of the cryptocurrency market, since then XMR lost about 85% of the cost. Now, a year after these events, researchers say that after the closure of Coinhive, crypto jacking has almost disappeared. For their analysis, experts used a crypto jacking detector CMTracker, designed to search on mining code sites. Manually and automatically, experts examined 2770 sites that were marked by CMTracker even before Coinhive closed. It turned out that 99% of these resources are not mining anymore. The remaining percentage still uses eight different mining scripts:

cc / lib / minero.min.js
com / lib / base.js
win / 46B8.js
* / perfekt / perfekt.js
* / tkefrep / tkefrep.js
co / javas. js
xyz / sadig6.js
bid / jo / jo / miner_compressed / webmr.js

These scripts have been seen on 632 sites. And this is a significant improvement compared to 2017, when Coinhive alone can be found on more than 30,000 sites. In their report, experts cite another study2019, which studied the profitability of browser mining and related costs. That report stated that network advertising was 5.5 times more profitable than mining. Thus, mining-oriented resources need to keep the visitor's tab open for at least 5.53 minutes in order to receive a comparable or greater income than from online advertising. In a fresh analysis, experts note that attackers really try to place the mining code on free movie sites, as this can force victims to remain on one page for a long period of time.

“He [crypto-jacking] is still alive, but not as attractive as before,” the researchers conclude.
 
Top Bottom