Government websites hit by cryptocurrency mining malware

 

Powered by Guardian.co.ukThis article titled “Government websites hit by cryptocurrency mining malware” was written by Patrick Greenfield, for The Guardian on Monday 12th February 2018 02.07 Asia/Kolkata

Thousands of websites, including those belonging to NHS services, the Student Loans Company and several English councils, have been infected by malware that forces visitors’ computers to mine cryptocurrency while using the site.

Late on Sunday, the website of the UK’s data protection watchdog, the Information Commissioner’s Office, was taken down to deal with the issue after it was reportedly infected by the malware.

The cryptojacking script was inserted into website codes through BrowseAloud, a popular plugin that helps blind and partially-sighted people access the web.

More than 5,000 websites have been flooded by the malware. Software known as Coinhive, which quietly uses the processing power of a user’s device to mine open source cryptocurrency Monero, appears to have been injected into the compromised BrowseAloud plugin.

Texthelp, which operates BrowseAloud, took its website down on Sunday while it tried to resolve the problem.

The National Cyber Security Centre confirmed the issue was being investigated, adding there was nothing to suggest members of the public were at risk after the malware attack.

Scott Helme, an IT security consultant, raised the alarm about the malware after he received a message from a friend whose antivirus software had detected an issue after visiting a UK government website.

“This type of attack isn’t new – but this is the biggest I’ve seen. A single company being hacked has meant thousands of sites impacted across the UK, Ireland and the United States,” Helme told Sky News.

“Someone just messaged me to say their local government website in Australia is using the software as well.”

A spokesperson for the National Cyber Security Centre said: “NCSC technical experts are examining data involving incidents of malware being used to illegally mine cryptocurrency.

“The affected services has been taken offline, largely mitigating the issue. Government websites will continue to operate securely. At this stage there is nothing to suggest that members of the public are at risk.”

guardian.co.uk © Guardian News & Media Limited 2010

Published via the Guardian News Feed plugin for WordPress.

Print Friendly, PDF & Email

Leave a comment

Government websites hit by cryptocurrency mining malware - NORTH INDIA KALEIDOSCOPE

Rajesh Ahuja

I am a veteran journalist based in Chandigarh India.I joined the profession in June 1982 and worked as a Staff Reporter with the National Herald at Delhi till June 1986. I joined The Hindu at Delhi in 1986 as a Staff Reporter and was promoted as Special Correspondent in 1993 and transferred to Chandigarh. I left The Hindu in September 2012 and launched my own newspaper ventures including this news portal and a weekly newspaper NORTH INDIA KALEIDOSCOPE (currently temporarily suspended).