Google Aims To Put An End To Secret Cryptojacking By Making In-Browser Permissions Necessary.
In-browser cryptocurrency mining has become the latest obsession among website operators as it is being deemed as the perfect alternative to display ads. However, the point of debate is that these miners are being deployed without asking or informing users. On the other hand, it is recommended in mining scripts that before making money through users’ resources, web operators must ask for user consent. It is also worth noting that the mining tools are being promoted as an alternative to online ads but the scripts so far have been used by hackers and cybercriminals for fulfilling their malicious objectives or secretly deployed by organizations and websites. Users are always kept in the dark, and hence, our CPUs are constantly helping them by providing them enough resources to mint money. A number of web operators also identified that their site was mining cryptocurrency while they were unaware of it while there are more than 500 sites knowingly or unknowingly running cryptocurrency miner and generating millions in digital money. The problem with cryptocurrency mining is that it infects the clients’ machine and extract power from the CPU, which negatively affects their computers. Previously users were urged by security firms to switch to browsers that were capable of blocking these scripts, such as Google Chrome’s extension AntiMiner. Some of the anti-virus software is also equipped with adblocker feature and can successfully block miners. The usability of these scripts and cryptocurrency mining as an alternate option of advertising cannot be overlooked. Therefore, tech giants are trying to identify ways of replacing ads in a legitimate manner, with the consent of users. Until that happens, Google’s engineers are thinking of adding a new feature of in-browser permissions to block cryptocurrency miners automatically. Chrome engineer Ojan Vafai stated that the company is looking to fix the issue of deploying cryptocurrency miners without notifying users. The most probable option is to block them automatically since the sites aggressively use CPU resources, which is not acceptable to Google. It is also noted by Vafai that Google is working on a feature which, if a website uses CPU resources for a predetermined timespan or percentage then the page will go into Battery Saver Mode and the user will be asked to manually opt out of this mode while when the battery saver mode runs in the background the tasks will be stopped entirely. “I think we’ll want measurement to figure out what values to use for XX and YY, but we can start with really egregious things like 100% and 60 seconds,” stated Vafai. The in-browser blocking feature is still in the process of development, but given the way cybercriminals and web operators using the cryptocurrency miners, we can expect a solution soon enough.
Who’s Currently Using Cryptocurrency Miners?
As mentioned above there are more than 500 websites secretly mining cryptocurrency using CPU of their visitors. However, some of them were exposed by cybersecurity researchers and include The Pirate Bay which was caught using cryptocurrency mining script twice in just one month, two websites belonging to ShowTime owned by CBS and torrent proxy site (ProxyBunker.online) which was later booted off by CloudFlare.
Last week, a hacking group was able to abuse the SWIFT (the Society for Worldwide Interbank Financial Telecommunications) banking network to steal $60 million after installing malware on a Taiwanese bank’s servers.
The Far Eastern International Bank has admitted that malware had been found on its machine systems, affecting PCs and servers, as well as its SWIFT terminal.
SWIFT is the system that enables banks to send money securely to each other around the world. It provides a network that allows financial organizations worldwide to send and receive data about financial transactions in a secure, standardized and reliable environment.
Most of the stolen funds have now been recovered, and the loss incurred by the bank due to the hacking incident is less than 500,000 US dollars, the governments have made two arrests in connection with the bank cyber-heist.
According to banking department deputy director Sherri Chuang, the Bank was able to recover $57 million that had been wired to Cambodia, $1 million sent to the United States, and $1.6 million sent to Sri Lanka.
‘Two suspects were arrested last week in Sri Lanka when they tried to withdraw the money, and police were looking for a third person.”
Anonymous hackers group "Motherboard" hack dark web hosting website "Freedom Hosting" which associated with child pornography.
Anonymous Hack Dark Web
According to The Verge, anonymous group says "Hello, Freedom Hosting II, you have been hacked," the message read. More than 10000 websites have been affected by anonymous group.
Anonymous member told that more than half of their hosting data store with child pornography. Anonymous group also told that they also offer data back to Freedom Hosting II for 0.1 bitcoin, or about $100, however The Verge said "it is unclear whether the offer is in earnest."
Freedom hosting is one of the largest hosting provider on the dark web.Most of onion website purchase their hosting form Freedom hosting.
Dark web is the world biggest platform, bigger then surface web, it's use for selling weapons, drugs, credit card details and other illicit goods,
A teenage hacker Adom Mudd from Kings Langley (UK) made a £400,000 pounds by his own hacking program.
Teen Hacker Earn £400,000 By Computer Virus
Adam creates this malware when he was 16 living with his family. He creates this harmful trojan "Titanium Stresser" which carry out 1.7 million attacks on websites after that website database flooded with data. This trojan work like a DDOS (Denial Of Distributed Service Attack).
Adams sell his trojan to cyber criminals and earn total pounds $307,298.35 and 259.81 bitcoins worth an overall£400,000. He also test this trojan and carried out 594 attacks by himself. When arrested in March 2015, Adom was on his computer, which he refused to unlock before his father intervened. Adom tried to hide his identity, but his IP address captured by cyber cell police. Court judgment told that he also transferred some amount to his father account.
Old Bailey also mentions in their statement, that Adom admits two computer hacking charges and one charge of concealing criminal property at a previous hearing.
Research proved that Anonymous hacktivists group is relatively much bigger than you anticipated and become quite popular among people all over the world. News about their existence first became public on social media, with members shown flaunting Guy Fawkes masks. It was all quite fitting, with the group calling themselvesAnonymousand wearing such masks in all over their demonstrations.
In an age where government oppression is becoming increasingly common, such groups have popped up everywhere. Anonymous is, arguably, the most famous of them. With the activity of such groups largely considered illegal but done in opposition to injustice by authorities as well as their donning such masks, Anonymous members are even considered as vigilantes by people.
We take a look at 8 of the best hacks done by the Anonymous group:
BART Attack (2011)
BART attackwas a repercussion to the shutting down of subterranean cellular services by the company when protesters were looking to organize protests due to BART police shooting an unarmed passenger. Protesters failed to organize their acts due to BART’s action, and Anonymous took things into their own hands.
First, they gained access to MYBART.org and posted personal details like names and account passwords of users. Then, when Linton Johnson, the company’s spokesperson, failed to admit this was a mistake, Anonymous took things a bit further by posting nude pictures of him online.
Project Chanology Attack (2008)
This was done as Anonymous believed theChurch of Scientologywas spreading misinformation about Scientology using internet censorship. Anonymous used Google bombing, linking the work Scientology to the cult or dangerous so that searching Scientology in Google would produce misleading and wayward results. One propaganda video was posted on YouTube, for which the Church sued the video website. Anonymous responded with a video of their own, generating 4.6 million views.
Federal Attack (2012)
The FBI shut down MegaUpload due to copyright infringement, and Anonymous retaliated with a tit-for-tat attack by shutting down Recording Industry and America and Motion Picture Association of America’s websites. The speed and gravity of theattack was a show of Anonymous’ power and intent.
Anyone familiar with the darknet would have heard of the Hidden Wiki, which is a guide to many underground websites that support illegal activities on the dark net.Anonymous gained access to Hidden Wiki, hunted down child pornography websites, and primarily attacked Lolita City, the file-sharing website that pedophiles used frequently.
They publicly posted the names of the 1,589 members of the website, showing that they would stand no such thing and are out to prevent the injustice of such notoriety. Anonymous also showed that they are willing to go anywhere for getting justice done, even the darknet, where law officials fail to get the job done at times as well.
Cybergate (2011)
HBGarry Federal’s CEO Aaron Barr claimed that his cyber security firm had succeeded in infiltrating Anonymous and would post details about the members publicly at a conference. That didn’t sit well with Anonymous, who showed them it isn’t wise to put one’s hand in a snake’s hole. Theyhijacked HBGarry’s website, changed the logo to Anonymous’ logo, posted the message that people should think twice before messing with Anonymous, took down their phone system and also extracted 70,000 messages from their email system.
What’s more, they posted a link to these messages on the internet through…..Barr’s twitter account. Yes, they hacked that too. The messages posted revealed how HBGarry aimed to act against WikiLeaks and how Hunton & Williams, the firm responsible for organizing the campaign against WikiLeaks, contacted HBGarry to target political organizations that were critical of the U.S Chamber of Commerce.
Donald Trump’s Website Hack (2015)
Donald Trump caught the attention of people all over the world when he said that he wanted all Muslims to be barred from entering the United States of America. Unfortunately for Mr. Trump, he also caught the attention of Anonymous, who immediately taught him a lesson. The website of Trump Towers subsequently went down for more than an hour, with A twitter account related to Anonymous broke the news of the hack, and a YouTube video released shortly afterward contained a member asking Donald Trump to think twice before he speaks.
WTO Hack (2015)
A hacker who was previously involved in hijacking two major Israeli arms dealers and leaking their client data claimed that he was with Anonymous after claiming to be the one behind theWTO hack in May 2015. The hacker hacked into WTO through their ecampus.wto.org domain and leaked personal information of many WTO officials. Details like phone numbers, email addresses, IP addresses, etc. of over 2,100 WTO officials from USA, Saudi Arabia, India, Pakistan, Brazil, and other nations was made public by this hacker belonging to Anonymous.
ISIS Website Attack (2015)
Ghost Sec, a group related to Anonymous, propaganda and placed the message to Calm Down along with an ad. The ad was related to an online pharmacy that sold drugs like Viagra and Prozac, with the message saying that there was too much ISIS. The full message was ‘Enhance your calm. Too many people are into this ISIS-stuff. Please gaze upon this lovely ad so we can upgrade our infrastructure to give you ISIS content you all do desperately crave.”Although many ISIS-supporting websites have been moving to the dark web in order to evade the authorities, they have been unable to keep out Anonymous, for they have no jurisdiction.
Anonymous has been gaining international reputation ever since the Project Chanology attack of 2008. Their activities have been applauded by the common masses, for they act in public interest.The Guy Fawkesmasks also work well with their popularity, for you can’t kill an idea.
The online hacktivist Anonymous along with its counterparts in Brazil hacked and defaced the official website of Boa Esporte, a second division football club in the state of Minas Gerais. The website was defaced not once but twice where hackers left a deface page along with a message explaining why they have been targeted the site.
The reason for targeting Boa Esporte was its recent initiative of hiring goalkeeper Bruno Fernandes das Dores de Souza who was sent to prison for not only brutally murdering his ex-girlfriend and mother of his kid Eliza Samudio in 2010 but also feeding her to his dogs.
Fernandes, more famous by his first name Bruno was sentenced to prison for 22 years, but due to a legal technicality, he was released last month after which Boa Esporte hired him. Bruno still claims to be innocent. However, the hacker community thought otherwise and decided to hack Esporte’s website with messages like “Has Bruno told where is Eliza’s body?”.
Deface page left by hackers on Boa Esporte’s website last Sunday
The site was then hacked for the second time in one day with messages against domestic violence against women in Brazil. The hackers also left pictures of Bruno and Eliza as a deface page along with statistics of women in Brazil killed since 2013.
Deface page left by Anonymous
The picture of Bruno is a magazine cover in which he’s urging people to “Let him play” while the picture of Eliza is a result of photoshop in which she’s shown saying “I would like to see my son grow.”
In must be noted that hackers are not the only community criticizing the hiring of Bruno. In fact, people on social media in Brazil also opposed the decision urging companies to stop sponsoring Boa Esporte. As a result, the food supplementing company Nutrends broke off its sponsorship of the club.
Nutrends’s officially confirming terminating the contract.
Another sponsor, Cardiocenter Varginha which provides medical evaluation services for Boa Esporte players, has also canceled its contract after the cyber attack and criticism. The company issued a statement on its official Facebook page saying it had requested that the brand should be removed from the club’s official website.
Cardiocenter Varginha’s post in Portuguese announcing the cancellation of its sponsorship
At the time of publishing this article, Boa Esporte website was down and unreachable for users. As far as Bruno, according to BBC, he’s still playing for Boa Esporte, seems like the club won’t back down from its decision.
DDoS attacks are increasing, calculate the cost and probability of a DDoS attack on your business withthis DDoS Downtime Cost Calculator.