Loading
Serviceteam IT
  • Infrastructure
  • Consultancy
  • Research
  • Case Studies
  • Contact Us
  • Blog
  • 0121 468 0101
  • Search
  • Menu Menu
  • Twitter
  • LinkedIn
  • Youtube
News

U.K. and U.S. Government Websites Among Thousands Infected by Cryptocurrency Miner

More than 4,200 websites, including many run the U.K. and U.S. governments, were infected on Feb. 11 by a Monero cryptocurrency miner delivered through Browsealoud, a hosted accessibility service that can read website content aloud for people with visual impairments.

Browsealoud developer Texthelp has taken the service offline temporarily while it works on a fix. The exploit was active for four hours and Texthelp had been preparing for such an attack for a while, CTO and data security officer Martin McKay said in a statement.

“Texthelp has in place continuous automated security tests for Browsealoud, and these detected the modified file and as a result the product was taken offline,” he wrote. “This removed Browsealoud from all our customer sites immediately, addressing the security risk without our customers having to take any action.”

No customer data was compromised or lost, and an investigation is underway, according to McKay. A list of the affected websites, which stands at 4,275, is available here.

The infection was first reported by security researcher Scott Helme. A friend of Helme’s told him that his antivirus software was issuing a warning when he visited the site of the U.K. Information Commissioner’s office, prompting Helme to investigate.

“They’re the people we complain to when companies do bad things with our data,” Helme wrote. “It was pretty alarming to realize that they were running a crypto miner on their site, their whole site, every single page. … I quickly realized though that this script, whilst present on the ICO website, was not being hosted by the ICO, it was included by a 3rd party library they loaded.”

That turned out to be Browsealoud, which had been compromised by attackers that altered one of its hosted JavaScript files, Helme said.

“This is not a particularly new attack and we’ve known for a long time that CDNs or other hosted assets are a prime target to compromise a single target and then infect potentially many thousands of websites,” Helme added.

The attack could have been averted if the sites had employed a simple technique called subresource integrity, Helme said. This tells web browsers to run an integrity check on anything being loaded from a third-party source.

Helme explained the technique in a previous blog post.

“By embedding the base64 encoded cryptographic hash digest that we expect for the asset into the script or link tag, the browser can download the asset and check its cryptographic hash digest against the one it was expecting,” he wrote. “If the hash of the downloaded asset matches the hash that we provided, then the content is what we were expecting to receive and the browser can safely include the script or style. If the hash doesn’t match then we know we can’t trust the data and it must be discarded.”

It’s not clear how much Monero the managed to generate, but crypto mining schemes have been coming into vogue among cybercriminals. The Smominru botnet, which infected more than half a million machines, has made up to $3.6 million worth of Monero since May, Proofpoint reported.

Last week, a Monero botnet showed up in China and South Korea, infecting Android devices through port 5555, which is associated with the OS’s Debug Bridge tool.

Source: ThreatPost

With over 20 years of experience, Serviceteam IT design and deliver sophisticated connectivity, communication, continuity, and cloud services, for organisations that need to stay connected 24/7. We take the time to fully understand your current challenges, and provide a solution that gives you a clear understanding of what you are purchasing and the benefits it will bring you.

To find out how we can help you, call us on 0121 468 0101, use the Contact Us form, or why not drop in and visit us at 49 Frederick Road, Edgbaston, Birmingham, B15 1HN.

We’d love to hear from you!

12 February, 2018/by serviceteamit
Tags: Browsealoud, crypto mining, Cryptocurrency, Hacks, Monero, Security News, Texthelp, Vulnerabilities, Web Security
Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
http://51.132.39.250/wp-content/uploads/2017/04/Squarelogotemplate.png 250 250 serviceteamit /wp-content/uploads/2020/05/ServiceteamITLogo250.png serviceteamit2018-02-12 18:00:182018-02-12 18:00:18U.K. and U.S. Government Websites Among Thousands Infected by Cryptocurrency Miner
You might also like
Serviceteam IT Security News Origin stories
Serviceteam IT Security News Phishing: guidance for political parties and their staff
Serviceteam IT Security News The Guardian view on cybercrime: the law must be enforced | Editorial
Serviceteam IT Security News Cryptomining Gold Rush: One Gang Rakes In $7M Over 6 Months
Serviceteam IT Security News Intel AMT Loophole Allows Hackers to Gain Control of Some PCs in Under a Minute
Serviceteam IT Security News Cyber Security Schools Programme

Serviceteam IT Research

Serviceteam IT ResearchServiceteam IT Research

Recent Posts

  • ‘Source of data’: are electric cars vulnerable to cyber spies and hackers?
  • Ofcom closes technical loophole used by criminals to intercept mobile calls and texts
  • Birthday freebies: how to cash in on UK retailers’ gifts and discounts
  • ‘The bot asked me four times a day how I was feeling’: is tracking everything actually good for us?
  • Apple removes advanced data protection tool in face of UK government request
  • Global ransomware payments plunge by a third amid crackdown
  • DeepSeek blocked from some app stores in Italy amid questions on data use
  • Threat of cyber-attacks on Whitehall ‘is severe and advancing quickly’, NAO says
  • ‘Security through obscurity’: the Swedish cabin on the frontline of a possible hybrid war
  • Alder Hey children’s hospital explores ‘data breach’ after ransomware claims
  • Passwords are giving way to better security methods – until those are hacked too, that is
  • Wire cutters: how the world’s vital undersea data cables are being targeted
  • Is your air fryer spying on you? Concerns over ‘excessive’ surveillance in smart devices
  • Chinese believed to have targeted Trump’s and Vance’s phones in US telecommunications breach
  • The run-up to my prostate examination | Brief letters

Categories

  • 2FA
  • 5G
  • Active Directory
  • Active Directory Federated Services (ADFS)
  • Amazon Web Services
  • Apple Mac
  • Artificial Intelligence (AI)
  • AWS Direct Connect
  • Azure
  • Azure AD
  • Azure ExpressRoute
  • Backup
  • Big Data
  • Blockchain
  • Blockchain as a Service
  • Brexit
  • Business Continuity
  • Calendar App
  • Case Study
  • Cloud
  • Cloud Analytics
  • Cloud Connect
  • Collaboration
  • Communication
  • Compliance
  • Connectivity
  • Consultancy
  • Continuity
  • Cyber Fraud
  • Cyber Security
  • Data Centre
  • Data Sovereignty
  • Desktop-as-a-Service
  • Digital Transformation
  • Disaster Recovery
  • DNS
  • Edge Computing
  • EOL
  • Exchange Online
  • Exchange Online Protection
  • GDPR
  • Glossary
  • Google Cloud
  • High Availability
  • HowTo
  • HP Helion
  • Hybrid-Cloud
  • IBM
  • Identity and Access Management
  • Internet of Things (IoT)
  • IONOS
  • IP Telephony
  • Leased Line
  • Lock down client IP source
  • MFA
  • Microsoft Teams
  • Multi-Factor Authentication
  • MX Fallback
  • Networks
  • News
  • O365
  • OData
  • Office 365
  • Oracle
  • Outlook 2011 for Mac
  • Outlook 2016 for Mac
  • Outsourcing
  • Password Management
  • Phishing
  • PowerShell
  • Reporting
  • Research
  • Restricted Access
  • Robotic Process Automation (RPA)
  • Salesforce
  • Scam Emails
  • Security
  • Self-service
  • SharePoint Online
  • Single Sign-On
  • Skype for Business
  • Smart Network
  • Spoof Emails
  • SSO
  • Supplier Selection
  • Teams Direct
  • Unified Threat Management
  • VoIP

Serviceteam IT Limited, 49 Frederick Road, Edgbaston, Birmingham, B15 1HN.

Copyright © 2011 Serviceteam IT Limited. Registered in England 07578043.

  • Privacy
  • Resources
  • Terms
  • Portal
  • Fibre
  • Smart Network
  • Cloud Connect
  • IP Telephony
  • Teams Calling
  • Microsoft Teams
  • Office 365 Plans
Blockchain Utilities: Revolution in the Energy Sector Blockchain Utilities & Energy Sector Serviceteam IT Security News 4,500 young women race to complete CyberFirst Girls online challenge
Scroll to top