April 14, 2026

Capitalizations Index – B ∞/21M

Monero Cryptomining Attack Affects Over 200,000 ISP-Grade Routers Globally

Monero cryptomining attack affects over 200,000 isp-grade routers globally

Monero Cryptomining Attack Affects Over 200,000 ISP-Grade Routers Globally


Monero cryptomining attack affects over 200,000 isp-grade routers globally
Advertisement

Four months after a security patch for MikroTik routers was released, some of the users of the devices who ignored fixing the vulnerability have now been turned into unwitting miners of Monero.

Known as CVE-2018-14847 the security flaw in MikroTik routers is being exploited with a view of installing the Coinhive cryptocurrency mining script in websites that users of the devices visit. According to cybersecurity researchers at SpiderLabs, tens of thousands of unpatched routers in Brazil were initially affected though the number is rapidly rising and spreading across the globe.

The vulnerability in the MikroTik Ethernet and Wi-Fi routers allows the bypassing of authentication by remote attackers who are then able to read and modify arbitrary files. It was discovered in April this year and the router manufacturer issued a patch shortly after.

Started in Brazil

Initially, the first Coinhive site key was found to have been used on 175,000 routers mainly in Brazil but a new key of the same mining script was injected in the routers and has so far affected an additional 25,000 routers in the eastern European country of Moldova, according to security researcher Troy Mursch. It is not clear whether it is the same attacker responsible for the newest phase of the attack or a copycat.

https://twitter.com/bad_packets/status/1024963272355676160

Originally, the Coinhive scripts were being injected into all the web pages visited by a user. However, in a bid to reduce the chances of detection the attacker turned to only installing the cryptocurrency mining scripts in custom error pages. Other techniques being used by the attacker to avoid detection include issuing cleanup commands after compromising routers in order to leave as small a footprint as possible.

Large Number of Unpatched MikroTik Routers

Though the cryptojacking campaign is mainly targeting Brazil, it is also spreading across the globe with the potential to compromise many more MikroTik routers. It is estimated that a significant number of MikroTik routers around the world have not been patched four months after the security fix was released.

“There are hundreds of thousands of these devices around the globe, in use by ISPs and different organizations and businesses, each device serves at least tens if not hundreds of users daily,” Simon Kenin, a security researcher at SpiderLabs, wrote in a blog post.

Additionally, the attack works both ways. Since it is aimed at vulnerable MikroTik routers it also affects websites hosted on servers using compromised devices and will thus users who are not directly connected to the infected devices from any geo-location are also vulnerable.

“As mentioned, servers that are connected to infected routers would also, in some cases, return an error page with Coinhive to users that are visiting those servers, no matter where on the internet they are visiting from,” notes Kenin.

Featured image from Shutterstock.

Follow us on Telegram or subscribe to our newsletter here.
Join CCN’s crypto community for $9.99 per month, click here.
Want exclusive analysis and crypto insights from Hacked.com? Click here.
Open Positions at CCN: Full Time and Part Time Journalists Wanted.

Advertisement


Published at Mon, 06 Aug 2018 13:14:16 +0000

bitcoin Scams

Previous Article

Jamie Dimon Still a Member of the ‘Blockchain Not Bitcoin’ Brigade

Next Article

Stratis Technical Analysis (STRAT/BTC) : Comin’ Down Again… [08/01/2018]

You might be interested in …

Bitcoin Sign Guy

The man behind the sign steps into the light to reveal his motives. In a year beset by savage infighting, bitcoin Sign Guy took a stand, with a small action that not only broke the internet, but raised the spirits of a beleaguered bitcoin community then ravaged by a years-long intellectual war. Were we all Satoshi? Maybe not in 2017. But, we were all “bitcoin Sign Guy.”

Read more:

Roger Ver Confirms He’ll Sell His Bitcoin: 130K BTU Trade a ‘Great Deal’

Roger Ver has received a pre-hard fork trade offer worth “up to” 130,000 bitcoins in a bargain receiving heavy publicity.


Ver: Up To 130k Trade ‘Sounds Like Great Deal’

According to a post of the Bitcointalk forum, a bitcoin bagholder known as “Loaded” signed a message from a wallet containing 40,000 BTC.

In the message, Loaded challenges Ver to a one-to-one BTC/BTU trade in the event of a hard fork occurring.

“@RogerVer lets make a deal, 1 for 1 trade. At least 60k, possibly up to 130k, my BTU for your BTC,” the message reads.

“The offer is open to Jihan Wu as well,” Loaded continued in a further post.

Consider it primarily as a vote of no confidence in the bitcoin Unlimited software and development team as it currently stands. I’ll add the contingency that the deal is null and void if there are major changes to either.

Responding to the offer, Ver seemed enthusiastic.

Roger Ver Bitcoin Uncensored block size

“This sounds like a great deal for both of us.  I look forward to ironing out the exact details and terms,” he said, adding he was too busy to confirm for the next two days.

Ver to Dump BTC Stash as Foreboding Grips bitcoin

While the trade cannot go ahead unless or until bitcoin Unlimited becomes a separate chain, Ver has already signaled his own vote of no confidence in Core, stating in an interview with MadBitcoins at the weekend that he would dump his BTC holdings.

Rumored to have a total of around 300,000 coins, the trade would produce significant downward pressure on the price of BTC, though it seems that some “whales” will be ready to scoop up Ver’s coins in no time.

Uncertainty over the future and its consequences is meanwhile filtering through the rest of bitcoin’s best-known names.

Rhetoric first over the so-called UASF, then later changing bitcoin’s proof-of-work algorithm, is now increasingly concerned with value protection.

vinny-lingham-640

In his latest blog post titled “For the Love of bitcoin,” entrepreneur and veteran commentator Vinny Lingham cited the “old adage” in investment that “markets will stay irrational longer than you can stay liquid.”

“Roger Ver confirmed exactly what I wrote in [a previous post] ‘A Fork in the Road’ — that he will be dumping his BTC. That will send the market spinning, for sure,” he added.

bitcoin Unlimited meanwhile suffered another denial of service attack Tuesday, with its node count plummeting in minutes due to a bug occurring “just six lines above” the previous one, which halved node numbers last week.

coin-dance-unlimitednodes

Also predicting the forked future is Bitfinex, which is currently offering BTU futures at a rate of $351 per coin at press time. BTC futures, with the ticker BCC, are trading at $720.

What do you think about Roger Ver’s trade? Let us know in the comments below!


Images courtesy of Twitter, Shutterstock, Coin.dance

The post Roger Ver Confirms He’ll Sell His Bitcoin: 130K BTU Trade a ‘Great Deal’ appeared first on Bitcoinist.com.

Bitcoin Core 0.17.1 Released

bitcoin Core 0.17.1 Released bitcoin Core version 0.17.1 is now available for download containing several bug fixes and minor improvements. For a complete list of changes, please see the release notes. If have any questions, […]