Top Cryptojackers are video streaming websites, and they do not use CoinHive

Back in December 2017, we added a mechanism that allowed users to optionally report websites whenever a cryptojacking script is detected by AdGuard. It proved useful right away and allowed us to discover the largest known cryptojacking campaign, which was being run by some popular video streaming websites. Since then we have received more than a million user reports, and now it's time to analyze them.

Over the last two months, we received over 1.3 Million reports on more than 120 thousand websites. It's important to notice that sometimes cryptojacking was detected on some legitimate websites (Google, Youtube, Instagram, etc) and this is most likely caused by malicious browser extensions or malvertising.

However, 40% (over half a million) of the reports came from just 50 domains. Let's take a deeper look into what the top cryptojackers do.

Cryptojacking is defined as the secret use of your computing device in the background to mine cryptocurrency. All that is needed is to open the page that contains the script of the miner, and you will begin (without knowing) to "mine" the cryptocurrency for the script owner. The CPU consumption, in this case, can reach very high values, almost completely occupying the resources of the computer.

Top Cryptojackers do not use CoinHive

The first and the most popular in-browser cryptocurrency miner - CoinHive - has become synonymous with cryptojacking. Interestingly enough, though, it appears that most of the top cryptojackers do not use it. One might be led to think that the reason for this is that CoinHive domains are blocked by ad blockers and antivirus software, but that's only part of the truth. A more significant reason is the fact that CoinHive takes a 30% commission, which is a substantial part of the mining earnings. The alternatives are to use one of the CoinHive clones which take a smaller commission or to set up a self-hosted mining proxy. The latter may sound complicated, but in reality, it is rather easy to do, and reasonable, given how much they earn.

Top Cryptojackers by mining scripts

Video Hosting Cryptojacking Services

Half of the top cryptojacking domains belong to popular video hosting services. Some of them were discussed in our previous research. Let's remember these and also hail the new ones. Openload.co, Rapidshare.com and Streamango.com have been testing mining since the middle of December, but it seems now that they are not doing it anymore. On the other side, an insanely popular (#113 in the world according to SimilarWeb) OnlineVideoConverter.com is still doing it. Two more websites worth mentioning are streamplay.top and thevideo.me (and their mirrors). These two are responsible for almost 9% of all the registered reports.

Top Cryptojackers by category

Cryptojacking Malware

Five of the top 50 cryptojacking domains are likely to be a part of some malicious operations. Hidden iframes that load pages from these domains are injected into legitimate websites like Google, Instagram, Facebook, etc. Unfortunately, we don't have enough data to find every piece of malware injecting them.

However, we were able to identify 11 malicious Chrome extensions with a total weekly user count of almost 37,000:

Personal Finder

The first one is the so-called "Personal Finder" with almost 10k weekly users.

Personal Finder Cryptojacker

It uses a standard technique - an iframe is created on the extension's background page. After a short period of time, a mining script is loaded to that page and at this point, cryptojacking begins.

Personal Finder Malicious Iframe

Hastalavista family

The family name is due to the "hastalavista.org" domain that is used by all these extensions. We found ten extensions of this "family" so far, and they use an interesting trick to avoid detection. These extensions' code does not contain anything suspicious. Once the user installs any of these extensions, it opens a "thank you" page; and the malicious script is then loaded into the extension using Chrome's messaging mechanism.

Hastalavista Malware

Conclusion

It has been almost five months since the problem of cryptojacking emerged, and all that time I had held a secret hope that it could bring something positive and maybe even provide an alternative to the advertising-based model. Unfortunately, I have to state that with time this technique floats ever farther over to the dark side; some even say that cryptojacking is now the most prevalent malware online. Although there is still a chance for it if publishers start using it legitimately.

How can you protect yourself? Use an ad blocker, an antivirus or one of the specialized extensions to combat in-browser mining. Also, there is some good news from Google Chrome developers. They have started work on a performance improvement that could potentially cripple cryptojacking scripts. The idea is to throttle Javascript service workers running in background tabs. As it happens, all the known cryptocurrency miners rely on these selfsame service workers. However, this cannot be considered to be a final solution. The top cryptojackers are video streaming websites that run cryptocurrency miners while the user is watching a video, and they will be working at full strength all during this time.

Vam je bila objava všeč?
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za Windows

AdGuard za Windows ni le še en zaviralec oglasov, je večnamensko orodje, ki združuje vse potrebne funkcije za najboljšo spletno izkušnjo. Onemogoča oglase in nevarne spletne strani, pospeši nalaganje strani in ščiti vaše otroke, ko so na spletu.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
AdGuard za Windows v7.21, 14-dnevno preizkusno obdobje
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za macOS

Za razliko od drugih zaviralcev oglasov je AdGuard zasnovan z upoštevanjem posebnosti macOS. Ne zagotavlja le obrambe pred oglasi v Safariju in drugih brskalnikih, ampak vas tudi ščiti pred sledenjem, lažnim predstavljanjem in goljufijami.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
AdGuard za macOS v2.17, 14-dnevno preizkusno obdobje
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za Android

AdGuard za Android je idealna rešitev za mobilne naprave Android. V nasprotju z drugimi zaviralci oglasov AdGuard ne potrebuje korenskega dostopa in ponuja širok spekter funkcij: filtriranje v aplikacijah, upravljanje aplikacij in še veliko več.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
Preglejte za prenos
Uporabite kateri koli razpoložljivi bralnik QR kod v vaši napravi
AdGuard za Android v4.11, 14-dnevno preizkusno obdobje
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za iOS

Najboljši blokator oglasov iOS za iPhone in iPad. AdGuard odstrani vse vrste oglasov v Safariju, ščiti vašo zasebnost in pospeši nalaganje strani. Tehnologija blokiranja oglasov AdGuard za iOS zagotavlja filtriranje najvišje kakovosti in omogoča uporabo več filtrov hkrati
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
Preglejte za prenos
Uporabite kateri koli razpoložljivi bralnik QR kod v vaši napravi
AdGuard za iOS v4.5
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Zaviralec vsebine

AdGuard Content Blocker odpravlja vse vrste oglasov v mobilnih brskalnikih, ki podpirajo tehnologijo blokiranja vsebine — in sicer Samsung Internet in Yandex Browser. Njegove funkcije so omejene v primerjavi z AdGuardom za Android, vendar je brezplačen, enostaven za namestitev in učinkovit
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
AdGuard Zaviralec vsebine v2.8
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Razširitev brskalnika

AdGuard je najhitrejša in najlažja razširitev za zaviranje oglasov, ki učinkovito onemogoča vse vrste oglasov na vseh spletnih straneh! Za brskalnik, ki ga uporabljate, izberite AdGuard in hitro ter varno brskajte brez oglasov.
AdGuard Razširitev brskalnika v5.1
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Pomočnik

Spremljevalna razširitev brskalnika za AdGuard namizno aplikacijo. Ponuja dostop do takšnih funkcij v brskalniku, kot so zaviranje elementov po meri, seznam dovoljenih spletnih strani ali pošiljanje poročila.
AdGuard Pomočnik v1.4
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Home

AdGuard Home je omrežna rešitev za blokiranje oglasov in sledilcev. Namestite ga enkrat na usmerjevalnik, da pokrijete vse naprave v domačem omrežju — dodatna programska oprema odjemalca ni potrebna. To je še posebej pomembno za različne naprave IoT, ki pogosto ogrožajo vašo zasebnost
AdGuard Home v0.107
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Pro za iOS

AdGuard Pro za iOS vključuje vse napredne funkcije zaščite pred oglasi z omogočeno blokado. Ponuja ista orodja kot plačljiva različica AdGuard za iOS. Odličen je pri blokiranju oglasov v Safari in omogoča prilagajanje DNS nastavitev za prilagojeno zaščito. Oglase blokira v brskalnikih in aplikacijah, vaše otroke ščiti pred neprimerno vsebino ter ohranja vaše osebne podatke varne.
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
AdGuard Pro za iOS v4.5
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za Safari

Naš blokator oglasov za Safari se je uspešno spopadel z izzivom Applea, ki je vse prisilil k uporabi novega SDK-ja. Cilj te razširitve AdGuard je vrniti visokokakovostno blokiranje oglasov v Safari
AdGuard za Safari v1.11
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za Android TV

AdGuard za Android TV je edina aplikacija, ki zavira oglase, varuje vašo zasebnost in deluje kot požarni zid za vaš Smart TV. Prejmite opozorila o spletnih grožnjah, uporabite varen DNS in izkoristite šifriran promet. Sprostite se in se potopite v svoje najljubše oddaje z vrhunsko varnostjo in brez oglasov!
AdGuard za Android TV v4.11, 14-dnevno preizkusno obdobje
19.644 19644 ocen uporabnikov
Odlično!

AdGuard za Linux

AdGuard za Linux je prvi sistemski zaviralec oglasov za Linux na svetu. Onemogočite oglase in sledilce na ravni naprave, izberite med vnaprej nameščenimi filtri ali dodajte svoje — vse preko ukazne lupine vmesnika
AdGuard za Linux v1.0
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Temp Mail

Brezplačen ustvarjalec začasnih elektronskih naslovov, ki vas ohranja anonimne in ščiti vašo zasebnost. Brez neželene pošte v vašem glavnem predalu!
19.644 19644 ocen uporabnikov
Odlično!

AdGuard VPN

66 lokacij svetovnega spleta

Dostop do katere koli vsebine

Močno šifriranje

Politika 'Brez dnevnikov'

Najhitrejša povezava

stalna podpora

Poskusite brezplačno
S prenosom programa sprejemate pogoje Licenčne pogodbe
Več o tem
19.644 19644 ocen uporabnikov
Odlično!

AdGuard DNS

AdGuard DNS je brezhiben način zaviranja internetnih oglasov, ki ne zahteva nameščanja nobenih aplikacij. Je preprost za uporabo, popolnoma brezplačen, enostavno nastavljiv na kateri koli napravi in vam zagotavlja minimalne potrebne funkcije za zaviranje oglasov, števcev, zlonamernih spletnih strani in vsebine za odrasle.
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Mail

Ščitite svoj identitet, izogibajte se neželeni pošti in ohranite svoj nabiralnik varno z našimi vzdevki in začasnimi e-poštnimi naslovi. Uživajte v naši brezplačni storitvi posredovanja e-pošte in aplikacijah za vse operacijske sisteme
19.644 19644 ocen uporabnikov
Odlično!

AdGuard Wallet

Varna in zasebna kripto denarnica, ki vam omogoča popoln nadzor nad vašimi sredstvi. Upravljaj več denarnic in odkrij tisoče kriptovalut za shranjevanje, pošiljanje in zamenjavo
Prenos AdGuarda Za namestitev AdGuarda kliknite gumb, označen s puščico Izberite 'Odpri' in kliknite na 'Vredu', nato pa počakajte, da se datoteka prenese. V odprtem oknu povlecite ikono AdGuarda in jo spustite v mapo 'Aplikacije'. Hvala, ker ste izbrali AdGuard! Izberite 'Odpri' in kliknite na 'Vredu', nato pa počakajte, da se datoteka prenese. V odprtem oknu kliknite na 'Namesti'. Hvala, ker ste izbrali AdGuard!
Namestite AdGuard na svojo mobilno napravo