YouTube Ads Hijacked Visitors' Computers to Mine Cryptocurrency

EnlargeDiego Betto

EnlargeDiego Betto

The mining software briefly invaded the video platform in an attempt to secretly siphon the computing power from any YouTube viewers who encountered the ads.

Hackers are misusing Google's DoubleClick ad platform on YouTube to access users' computers to mine cryptocurrency, security research firm Trend Micro reported on Friday.

"Attackers abused Google's DoubleClick, which develops and provides internet ad serving services, for traffic distribution", the post notes. The bad actors seeded the advertisements with web scripts that'll run over your browser to mine the digital currency Monero.

A Friday blog post from Trend Micro, an global cybersecurity company, confirmed the sharp uptick in Coinhive use earlier in the week, pinning it to a "malvertising campaign" that subverted a Google ad service used on YouTube.

Trend Micro noticed the campaign on January 24 and informed Google about the problem.

Looks like the major motive of hackers for targeting YouTube is its popularity across the world. The more browsers the mining software can leverage, the more cryptocurrency it can generate. For some, mining is a great way to earn a passive income, but can often have a high start-up and maintenance cost. Apparently, these attackers were using Google's DoubleClick ad network to display these ads to YouTube users in select countries globally, including Japan, France, Taiwan, Italy, and Spain.

Google, which owns YouTube, has taken action. "In this case, the ads were blocked in less than two hours and the malicious actors were quickly removed from our platforms", he added.

Trump mentions Jews in Holocaust Remembrance Day message
Regretfully we are witnessing a rise of anti-Semitism related actions and speech in Europe and elsewhere that sow seeds of hate. Trump added: "As I have said: 'We will stamp out prejudice".

DACA-wall talks 'starting over,' Schumer says
The program now protects about 700,000 people, mostly Hispanic young adults, from deportation and provides them work permits. The Senate's Democratic leader, Chuck Schumer , is taking back his offer to President Trump to fund his "big lovely wall".

QEP Resources (QEP) Rating Reiterated by Piper Jaffray Companies
Mizuho set a $15.00 price objective on QEP Resources and gave the stock a "buy" rating in a report on Tuesday, January 16th. Welch Forbes Ltd Liability Corporation accumulated 270,671 shares or 0.55% of the stock. (NYSE:QEP) for 901,000 shares.

Mining cryptocurrency through ads is a relatively new form of abuse that violates our policies and one that we've been monitoring actively.

Unfortunately, cryptocurrency mining that creeps through your browser is probably here to stay. Crypto miners insert a code of JavaScript into websites and advertisements that use CPU's power to mine cryptocurrency for them. Even when users changed browsers and visited other websites, these warnings only popped up while on YouTube.

Most of the users have reported a common thing in these hacks and that is CoinHive a crypto mining service. In return, Coinhive takes a 30 percent cut.

The Coinhive service appeared last September and has described itself as a website monetization service that could be employed as an alternative to classic online ads. "The two web miners were configured with throttle 0.2, which means the miners will use 80% of the CPU's resources for mining".

The huge spike represents the moment when crooks chose to deliver the Coinhive-tainted ads on YouTube, the world's largest video hosting platform.

As cryptocurrencies become more prevalent the level of sophistication for mining malware will increase. Many anti-virus vendors including Trend Micro are starting to rank it as among the most pervasive malware threats circulating on the web.

Recommended News

We are pleased to provide this opportunity to share information, experiences and observations about what's in the news.
Some of the comments may be reprinted elsewhere in the site or in the newspaper.
Thank you for taking the time to offer your thoughts.