Hackers are increasingly exploiting cryptojacking malware without needing active browsers
Crypto malware is quickly extending to non-browser applications, says Checkpoint

Hackers are quickly finding ways to launch cryptomining campaigns without the need for an active web browser, according to new research from Checkpoint.
The security firm's latest Global Threat Index has revealed a surge of cryptocurrency malware attacks, specifically an endpoint variant called XMRig.
First discovered in May 2017, XMRig has quickly become one of the most popular types of cryptomining malware among cyber criminals.
Between the date of discovery in May 2017 and March 2018, the malware had a 70 per cent increase in global impact. XMRig is so effective because it operates through end-points devices such as PCs and smartphones, rather than the web browser.
With it, crooks can mine the Monero cryptocurrency on apps that are running in the background instead of a web browser. These attacks normally go unnoticed.
As well as the rise of XMRig, the threat index reveals that Coinhive is still the most popular cryptocurrency mining script to get integrated into 'cryptojacking' malware, with it impacting 18 per cent of organisations.
The Rig EK 'exploit kit' came in a close second, scoring 17 per cent. The kit lets hackers exploit Flash, Java, Silverlight and Internet Explorer to launch cryptomining campaigns.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Meanwhile, Cryptoloot is listed as the third most wanted cryptocurrency malware. It harvests the victim's GPU or GPU power to mine cryptocurrencies.
Checkpoint has also ranked the most common mobile malware, with Android banking trojan Lokibot at the top of the list. With it crooks can steal important business information and lock people's phones
Triada, which is a described as a "modular backdoor for Android", is second on the list. The malware backdoor gives hackers superuser privileges over an infected device allowing them to download further malware. Hiddad, which repackages popular apps and sends them to third-party stores, is in last place.
The security research firm analysed the most exploited cyber vulnerabilities as well, with an Oracle remote code execution vulnerability (CVE-2017-10271 sporting a global impact of 26 per cent, the SQL injection vulnerability at 19 per cent, and a Microsoft Windows flaw (CVE-2015-1635) at 12 per cent.
Maya Horowitz, threat intelligence group Manager of Check Point, said cryptomining campaigns have been a "success story" for cyber criminals.
"XMRig's rise indicates that they are actively invested in modifying and improving their methods in order to stay ahead of the curve," Horowitz explained.
"Besides slowing down PCs and servers, cryptomining malware can spread laterally once inside the network, posing a major security threat to its victims.
" It is therefore critical that enterprises employ a multi-layered cybersecurity strategy that protects against both established malware families and brand new threats."
As interest builds around Bitcoin and other cryptocurrencies, malware and hack attacks designed to illegitimately generate digital money are likely to become more prevalent in the cyber security world, something IT managers and security officers should take note of.
Nicholas Fearn is a freelance technology journalist and copywriter from the Welsh valleys. His work has appeared in publications such as the FT, the Independent, the Daily Telegraph, the Next Web, T3, Android Central, Computer Weekly, and many others. He also happens to be a diehard Mariah Carey fan. You can follow Nicholas on Twitter.
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Liquid cryptocurrency exchange loses $97 million after hack
News Amount lost includes $45 million in Ethereum tokens
By Rene Millman
-
False crypto-mining apps plague Google Play
News Apps deceive users into clicking on ads or buying non-existent mining subscriptions
By Rene Millman
-
Ohio resident pleads guilty to running Bitcoin “mixer” money laundering scheme
News More than $300 million went through Darknet-based bitcoin hashing (BTC) service
By Rene Millman
-
Study: Cryptocurrency value spikes encourage more illicit mining
News Researchers tracked Modero cryptocurrency and illicit mining for nearly three years
By Rene Millman
-
Crypto-mining hackers hit Kubernetes clusters
News New campaign abused Kubeflow dashboards to install malicious containers
By Rene Millman
-
FTC warns of rising cryptocurrency fraud
News Marked rise in cryptocurrency losses began just as pandemic took hold
By Danny Bradbury
-
Encrypted messaging site Privnote cloned to steal Bitcoin
News Criminals aim to redirect users’ Bitcoins using a phishing scam
By David Gargaro
-
US identifies and charges SamSam ransomware authors
News In a wave of attacks spanning three years, the US government has charged the people behind it, but getting them in handcuffs won't be easy
By Connor Jones