YouTube is turning passive viewers into cryptocurrency miners, and Google isn't happy.
The issue became apparent earlier in the week as complaints surfaced on social media claiming that YouTube ads were raising red flags in anti-virus software. A service called Coinhive was hijacking a viewer's CPU and using its power to mine crypto.
SEE ALSO: CryptoCelebrities are the newest irritating kid on the blockchainA Friday blog post from Trend Micro, an international cybersecurity company, confirmed the sharp uptick in Coinhive use earlier in the week, pinning it to a "malvertising campaign" that subverted a Google ad service used on YouTube.
"Attackers abused Google’s DoubleClick, which develops and provides internet ad serving services, for traffic distribution," the post notes. Trend Micro's data pointed to Japan, France, Taiwan, Italy, and Spain as the countries affected by the campaign.
In a statement given to Ars Technica on Friday, Google confirmed the cryptojacking threat, noting that "[i]n this case, the ads were blocked in less than two hours and the malicious actors were quickly removed from our platforms."
Google's "blocked in less than two hours" timeline doesn't add up, however. Trend Micro's data suggests that "an increase in traffic to five malicious domains" from DoubleClick advertisements started on or sometime before Jan. 18. By Jan. 24, the company had detected "an almost 285% increase in the number of Coinhive miners."
Google didn't respond to any follow-up questions regarding the timeline.
Coinhive wasn't always used for nefarious purposes. The script was created originally to let website owners harness the processing power of a visitor's computer to mine Monero. So long as the site owner let people know about Coinhive up front and didn't let the script monopolize processing power, it was a relatively ethical way for website operators to turn traffic into income.
Then, in late December, users of a certain Chrome extension discovered that it was also secretly running CoinHive. This incident quickly turned into one of the higher profile examples of a relatively new phenomenon in the malware world: "cryptojacking," the practice of hijacking a PC user's CPU to mine cryptocurrency.
The spread of cryptojacking to YouTube is an alarming development. While it's good that Google eventually shut the activity down, this is a new wrinkle in the cryptocurrency craze that internet gatekeepers will have to better protect against in the future.
文章
1192
浏览
3
获赞
7
All the best signs from Women's March events around the country
The Women's March is back for its third year, and despite several layers of controversy surrounding15 memes that defined 2019
This year's memes were particularly cursed.As internet culture progresses, so do our collective braiThe pitfalls of being Too Online during the coronavirus
It's 2020: Nearly everyone is online in some form. But not everyone is capital-O Online — youYouTube to curb videos promoting 5G coronavirus conspiracy theories
Conspiracy theories that link 5G to the coronavirus are spreading fast on social media. It's resultiYou can transfer Facebook photos and videos to Google Photos now
If you have a treasure trove of memories on Facebook and want them to live elsewhere, today's a greaThe best music to help you sleep
Having trouble sleeping?Hit Snoozeis Mashable's deep dive into the many ways to achieve a more peaceMeghan Markle's husband speaks out about royal family split, kindly asks everyone to step off
"Harxit" may not really roll off the tongue the way "Megxit" does — but Prince Harry would likSomeone hired Mark McGrath and Anthony Scaramucci to break up with their boyfriend on Cameo
A man named Brayden has had a rollercoaster of a past few days. Bad news: His relationship ended. GoBeto O'Rourke livestreamed his haircut. Yes, his haircut.
You can't keep a streaming Beto down.If you didn't think livestreaming a dental appointment was mundTom Hanks is not really quarantined with Wilson, the ball from 'Cast Away'
We regret to inform you that although reports of Tom Hanks chilling in coronavirus quarantine with WiPhone vulnerability targets Apple's iOS Mail app
A newly disclosed iPhone vulnerability gives hackers yet another reason to love email. According toGet 25% off Under Armour Fleece activewear
TL;DR:Under Armour is having a 25% off saleon all of their warm and stylish Armour Fleece® gearReddit recruits black tech entrepreneur to join board
Reddit is honoring Alexis Ohanian’s request to fill his board seat with a black candidate by nGoogle and Apple team up to support coronavirus contact tracing
Who gave you the coronavirus, and how many people did you give it to?As a pandemic sweeps the globe,Latest Google Chrome update lets users sort tabs by groups and colors
Wrangling your numerous Google Chrome tabs is about to get a little easier.Google announced Wednesda