Skip to content

Over 3,500 Websites Compromised by Hidden Monero Miners

2025-07-22 16:40:29

Over 3,500 Websites Compromised by Hidden Monero Miners

Main Idea

Attackers have infected over 3,500 websites with covert cryptocurrency mining malware, which avoids detection by minimizing CPU usage and hiding traffic in WebSocket streams.

Key Points

1. More than 3,500 websites were infected with hidden cryptocurrency mining scripts, as reported by cybersecurity company c/side.

2. The malware does not steal passwords or lock files but uses a small miner that avoids suspicious, CPU-intensive payloads to evade detection.

3. Cryptojacking involves unauthorized use of devices to mine digital assets without the owners' knowledge, a tactic that emerged in 2017 with Coinhive.

4. The malware throttles CPU usage and hides traffic in WebSocket streams to avoid traditional cryptojacking detection methods.

5. Cryptojacking has resurfaced in a more covert form after the shutdown of Coinhive in 2019.

Description

Attackers have infected more than 3,500 websites with scripts for hidden cryptocurrency mining, cybersecurity company c/side reported. The malware does not steal passwords or lock files. Instead, it uses a small portion of users’ computing power without their consent to mine Monero. The miner avoids suspicious, CPU-intensive payloads, so it is difficult to detect. “By throttling CPU usage and hiding traffic in WebSocket streams, it avoided the telltale signs of traditional crypto jacking,” the a...

>> go to origin page
Tags:
News Crypto

More Reading