Loading
Serviceteam IT
  • Infrastructure
  • Consultancy
  • Research
  • Case Studies
  • Contact Us
  • Blog
  • 0121 468 0101
  • Search
  • Menu Menu
  • Twitter
  • LinkedIn
  • Youtube
News

U.K. and U.S. Government Websites Among Thousands Infected by Cryptocurrency Miner

More than 4,200 websites, including many run the U.K. and U.S. governments, were infected on Feb. 11 by a Monero cryptocurrency miner delivered through Browsealoud, a hosted accessibility service that can read website content aloud for people with visual impairments.

Browsealoud developer Texthelp has taken the service offline temporarily while it works on a fix. The exploit was active for four hours and Texthelp had been preparing for such an attack for a while, CTO and data security officer Martin McKay said in a statement.

“Texthelp has in place continuous automated security tests for Browsealoud, and these detected the modified file and as a result the product was taken offline,” he wrote. “This removed Browsealoud from all our customer sites immediately, addressing the security risk without our customers having to take any action.”

No customer data was compromised or lost, and an investigation is underway, according to McKay. A list of the affected websites, which stands at 4,275, is available here.

The infection was first reported by security researcher Scott Helme. A friend of Helme’s told him that his antivirus software was issuing a warning when he visited the site of the U.K. Information Commissioner’s office, prompting Helme to investigate.

“They’re the people we complain to when companies do bad things with our data,” Helme wrote. “It was pretty alarming to realize that they were running a crypto miner on their site, their whole site, every single page. … I quickly realized though that this script, whilst present on the ICO website, was not being hosted by the ICO, it was included by a 3rd party library they loaded.”

That turned out to be Browsealoud, which had been compromised by attackers that altered one of its hosted JavaScript files, Helme said.

“This is not a particularly new attack and we’ve known for a long time that CDNs or other hosted assets are a prime target to compromise a single target and then infect potentially many thousands of websites,” Helme added.

The attack could have been averted if the sites had employed a simple technique called subresource integrity, Helme said. This tells web browsers to run an integrity check on anything being loaded from a third-party source.

Helme explained the technique in a previous blog post.

“By embedding the base64 encoded cryptographic hash digest that we expect for the asset into the script or link tag, the browser can download the asset and check its cryptographic hash digest against the one it was expecting,” he wrote. “If the hash of the downloaded asset matches the hash that we provided, then the content is what we were expecting to receive and the browser can safely include the script or style. If the hash doesn’t match then we know we can’t trust the data and it must be discarded.”

It’s not clear how much Monero the managed to generate, but crypto mining schemes have been coming into vogue among cybercriminals. The Smominru botnet, which infected more than half a million machines, has made up to $3.6 million worth of Monero since May, Proofpoint reported.

Last week, a Monero botnet showed up in China and South Korea, infecting Android devices through port 5555, which is associated with the OS’s Debug Bridge tool.

Source: ThreatPost

With over 20 years of experience, Serviceteam IT design and deliver sophisticated connectivity, communication, continuity, and cloud services, for organisations that need to stay connected 24/7. We take the time to fully understand your current challenges, and provide a solution that gives you a clear understanding of what you are purchasing and the benefits it will bring you.

To find out how we can help you, call us on 0121 468 0101, use the Contact Us form, or why not drop in and visit us at 49 Frederick Road, Edgbaston, Birmingham, B15 1HN.

We’d love to hear from you!

12 February, 2018/by serviceteamit
Tags: Browsealoud, crypto mining, Cryptocurrency, Hacks, Monero, Security News, Texthelp, Vulnerabilities, Web Security
Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
http://51.132.39.250/wp-content/uploads/2017/04/Squarelogotemplate.png 250 250 serviceteamit /wp-content/uploads/2020/05/ServiceteamITLogo250.png serviceteamit2018-02-12 18:00:182018-02-12 18:00:18U.K. and U.S. Government Websites Among Thousands Infected by Cryptocurrency Miner
You might also like
Serviceteam IT Security News I’m still on Windows 7 – what should I do?
Serviceteam IT Security News EUD Security Guidance: Chrome OS 65
Serviceteam IT Security News New Spider Ransomware Comes With 96-Hour Deadline
Serviceteam IT Security News Companies could be forced to delete customer data used to prove ID, Labor suggests
Serviceteam IT Security News Russia-based LockBit ransomware hackers attempt comeback
Serviceteam IT Security News TechScape: Why Twitter ending free access to its APIs should be a ‘wake-up call’

Serviceteam IT Research

Serviceteam IT ResearchServiceteam IT Research

Recent Posts

  • Six out of 10 UK secondary schools hit by cyber-attack or breach in past year
  • Starmer to unveil digital ID cards in plan set to ignite civil liberties row
  • Hackers reportedly steal pictures of 8,000 children from Kido nursery chain
  • Digital ID cards: a versatile and useful tool or a worrying cybersecurity risk?
  • Legal aid cyber-attack has pushed sector towards collapse, say lawyers
  • ‘Hacking is assumed now’: experts raise the alarm about added risk of surveillance cameras in childcare centres
  • Louis Vuitton says UK customer data stolen in cyber-attack
  • UK ‘woefully’ unprepared for Chinese and Russian undersea cable sabotage, says report
  • European journalists targeted with Paragon Solutions spyware, say researchers
  • ANU investigates possible hack after vice-chancellor’s account liked ‘highly offensive’ LinkedIn posts
  • Russian-led cybercrime network dismantled in global operation
  • What to do if you can’t get into your Facebook or Instagram account
  • ‘Source of data’: are electric cars vulnerable to cyber spies and hackers?
  • Ofcom closes technical loophole used by criminals to intercept mobile calls and texts
  • Birthday freebies: how to cash in on UK retailers’ gifts and discounts

Categories

  • 2FA
  • 5G
  • Active Directory
  • Active Directory Federated Services (ADFS)
  • Amazon Web Services
  • Apple Mac
  • Artificial Intelligence (AI)
  • AWS Direct Connect
  • Azure
  • Azure AD
  • Azure ExpressRoute
  • Backup
  • Big Data
  • Blockchain
  • Blockchain as a Service
  • Brexit
  • Business Continuity
  • Calendar App
  • Case Study
  • Cloud
  • Cloud Analytics
  • Cloud Connect
  • Collaboration
  • Communication
  • Compliance
  • Connectivity
  • Consultancy
  • Continuity
  • Cyber Fraud
  • Cyber Security
  • Data Centre
  • Data Sovereignty
  • Desktop-as-a-Service
  • Digital Transformation
  • Disaster Recovery
  • DNS
  • Edge Computing
  • EOL
  • Exchange Online
  • Exchange Online Protection
  • GDPR
  • Glossary
  • Google Cloud
  • High Availability
  • HowTo
  • HP Helion
  • Hybrid-Cloud
  • IBM
  • Identity and Access Management
  • Internet of Things (IoT)
  • IONOS
  • IP Telephony
  • Leased Line
  • Lock down client IP source
  • MFA
  • Microsoft Teams
  • Multi-Factor Authentication
  • MX Fallback
  • Networks
  • News
  • O365
  • OData
  • Office 365
  • Oracle
  • Outlook 2011 for Mac
  • Outlook 2016 for Mac
  • Outsourcing
  • Password Management
  • Phishing
  • PowerShell
  • Reporting
  • Research
  • Restricted Access
  • Robotic Process Automation (RPA)
  • Salesforce
  • Scam Emails
  • Security
  • Self-service
  • SharePoint Online
  • Single Sign-On
  • Skype for Business
  • Smart Network
  • Spoof Emails
  • SSO
  • Supplier Selection
  • Teams Direct
  • Unified Threat Management
  • VoIP

Serviceteam IT Limited, 49 Frederick Road, Edgbaston, Birmingham, B15 1HN.

Copyright © 2011 Serviceteam IT Limited. Registered in England 07578043.

  • Privacy
  • Resources
  • Terms
  • Portal
  • Fibre
  • Smart Network
  • Cloud Connect
  • IP Telephony
  • Teams Calling
  • Microsoft Teams
  • Office 365 Plans
Blockchain Utilities: Revolution in the Energy Sector Blockchain Utilities & Energy Sector Serviceteam IT Security News 4,500 young women race to complete CyberFirst Girls online challenge
Scroll to top