Cryptojacking Script Makes It on the MSN Portal

Faybert

Level 24
Thread author
Verified
Top Poster
Well-known
Jan 8, 2017
1,318
or three days between March 25 and March 27, a malicious actor has poisoned an important advertising network and used its services to deliver a cryptojacking script to multiple websites, including Microsoft's MSN portal.
Trend Micro, the cyber-security firm which spotted the event, says that by planting their in-browser cryptocurrency miner on a high-trafficked site like MSN, crooks managed to double the number of cryptojacking scripts from March 24 to March 25, detections going up by 108%.
Fortunately, the event was contained only to MSN's Japan portal, otherwise, the incident would have been much worse.

Cryptojacking script injected via AOL ad platform
"The malicious script was injected on advertising.aolp.jp, the AOL advertising platform," said Trend Micro.
Crooks leveraged the platform to deliver malicious code inside ad slots that caused users' browsers to load another JavaScript file from the attacker's domain.
........
........
.........
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top