Search

Millions of Android Phones Hijacked to Mine Monero Cryptocurrency: Malwarebytes

Advertisement
Highlights
  • Hackers have been mining Monero coins via smartphones for months
  • Users presented with CAPTCHA to solve while browser mines Monero
  • Android phone users should use web filters, security software
Millions of Android Phones Hijacked to Mine Monero Cryptocurrency: Malwarebytes

Millions of Android smartphones have reportedly been hijacked in a drive-by cryptocurrency mining campaign. As per security researchers, over the past few months, hackers have secretly been mining Monero coins via smartphones. According to Malwarebytes researchers, the campaign was first observed in January though it had started around November last year.

According to the report, millions of Android mobile users have been redirected to a specifically designed page "performing in-browser cryptomining." Though the method, the report says, is "automated, without user consent, and mostly silent," visitors are presented with a CAPTCHA to solve to prove that they are human and not a bot.

The warning message reads as "Your device is showing suspicious surfing behaviour. Please prove that you are human by solving the captcha. Until you verify yourself as human, your browser will mine the Cryptocurrency Monero for us in order to recover the server costs incurred by bot traffic." Until a user enters the code, the smartphone or tablet continues mining Monero, damaging the device's processor.

Also see: How to Stop Websites From Using Your Phone or Computer to Mine Bitcoin and Other Cryptocurrencies 

Interestingly, upon clicking entering the code, users are redirected to the Google home page, the report says. Also, the code is static and hardcoded in the page's source, making the process appear malicious. The researchers at Malwarebytes say that victims may face the forced redirection during regular browsing sessions or via infected apps with malicious ads.

"It's possible that this particular campaign is going after low-quality traffic-but not necessarily bots -and rather than serving typical ads that might be wasted, they chose to make a profit using a browser-based Monero miner," Jerome Segura, lead malware intelligence analyst at Malwarebytes, wrote in the blog post.

Malwarebytes identified five domains using the same captcha code and Coinhive site keys used for the campaign. According to the data posted on the blog, at least two websites had more than 30 million visits per month, and the domains combined yielded around 800,000 visits per day.

Unsurprisingly, Web filtering or security applications on smartphones have been highly recommended by the researchers, to prevent such hijacks. They say that forced cryptomining is now affecting mobile phones and tablets not only via Trojanised apps but also via redirects and pop-unders. Meanwhile, here is a guide on how to stop websites from using your phone or computer to mine cryptocurrencies.

Also seeCryptocurrency Prices across Indian exchanges

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Razr 60 Ultra, Edge 60 and Edge 60 Pro Price Leaked Online
  2. Nothing's Essential Space Feature Might Soon Require a Subcription
  3. Infinix Note 50X 5G With Dimensity 7300 Ultimate SoC Launched in India
  4. Motorola Razr 60 Spotted Online; Design, Key Specifications Leaked
  5. OpenAI Adds Image Generation to GPT-4o, But Free Tier Will Have to Wait
  6. Apple iPhone 16e Review: When You Just Need an iPhone
  7. Airtel Launches IPTV Services With Bundled OTT Apps in India
  8. Qualcomm Could Launch 2nm Flagship Chipsets Next Year
  9. IPL 2025 Live Streaming for Free: How to Watch SRH vs LSG IPL Match Online?
  10. Instagram Discontinues Content Notes Feature for Posts and Reels
  1. Alibaba Qwen 2.5 Omni AI Model With Real-Time Speech Generation Released
  2. Canon PowerShot V1 and EOS R50 V for Video Creators Launched: Price, Specifications
  3. iPhone 17 Series to Reportedly Get 8K Video Recording Support
  4. Infinix Note 50X 5G With MediaTek Dimensity 7300 Ultimate Chipset Launched in India: Price, Specifications
  5. PS Plus Monthly Games for April Announced: RoboCop: Rogue City, The Texas Chain Saw Massacre and Digimon Story
  6. Nothing Could Introduce Subscription Model for Essential Space Features on Nothing Phone 3a Series: Report
  7. OpenAI Close to Finalising $40 Billion SoftBank-Led Funding
  8. OpenAI Adds Image Generation Capability to GPT-4o, Can Render Text and Offers Prompt-Based Editing
  9. Instagram Pulls Back Content Notes Feature for Posts and Reels Due to Low Adoption
  10. Samsung Galaxy S25 Edge Official-Looking Renders Show Off Design, Three Colourways
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »