Cryptomining (Notice 2018-003)

This is a Fast-Air Tech Talk security notice. The Tech Talk security notice is a free service for all Fast-Air customers. Please suggest security notice topics.

Cryptomining is an activity where people try to create revenues through digital currencies. The activity requires significant computer CPU and GPU muscle. The more CPUs and GPUs involved the higher the potential profits.

Shady cryptomining advocates are resorting to “cryptojacking” other people’s computers. These malicious users covertly run scripts and programs on other people’s computers to use that computer and electricity to participate in the overall cryptomining scheme. Often this causes a user’s computer CPU and GPU to run at maximum speed, which often results in the respective fans running at full speed.

Cryptojackers use web browsers and phone apps to steal CPU and GPU cycles, but also use known software vulnerabilities to hack into computers to run their scripts and programs.

Users who notice their computers running at maximum speed while performing normal tasks might want to look if their computer has been cryptojacked, especially when visiting certain web sites.

Always keep computers updated with the latest security patches.

A simple option to avoid cryptojacking is avoiding shady or malicious web sites.

Users can check anti-malware software to see if cryptomining blocking options are available.

Add-ons are available for popular web browsers, but exercise caution that the add-on itself is not malware. Firefox, Chrome, and Chromium users might look at the No Coin add-on or use a trusted ad-blocker add-on. Firefox users can benefit by learning to use the NoScript add-on, which is a tool to create JavaScript white lists for trusted web sites. Any site not in the white list is prevented from running JavaScript scripts, which is the common way to cryptojack web browsers.

For those a bit more tech savvy another protection is to add known cryptomining web sites to their operating system’s host file. Such a list is available online.

Latest posts by Backwoods Geek (see all)