CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Cryptojacking Resurfaces As Monero Miner Malware Hits 3,500+ Sites: Report
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Cryptojacking Resurfaces As Monero Miner Malware Hits 3,500+ Sites: Report
News

Cryptojacking Resurfaces As Monero Miner Malware Hits 3,500+ Sites: Report

CoinRSS
Last updated: July 22, 2025 8:57 pm
CoinRSS Published July 22, 2025
Share

Contents
In brief‘Stay low, mine slow’Daily Debrief Newsletter

In brief

  • At least 3,500 websites are running a hidden Monero mining script delivered through a malicious injection chain.
  • Attackers reused access from past campaigns, targeting unpatched sites and e-commerce servers.
  • The malware keeps a low profile, limiting resource use to avoid triggering suspicion or security scans.

Hackers have infected more than 3,500 websites with stealthy cryptomining scripts that quietly hijack visitors’ browsers to generate Monero, a privacy-focused crypto designed to make transactions more difficult to trace.

The malware doesn’t steal passwords or lock files. Instead, it quietly turns visitors’ browsers into Monero mining engines, siphoning small amounts of processing power without user consent.

The campaign, still active as of this writing, was first uncovered by researchers at cybersecurity firm c/side.

“By throttling CPU usage and hiding traffic in WebSocket streams, it avoided the telltale signs of traditional crypto jacking,” c/side disclosed Friday.

Crypto jacking, sometimes spelled as one word, is the unauthorized use of someone’s device to mine crypto, typically without the owner’s knowledge.

The tactic first gained mainstream attention in late 2017 with the rise of Coinhive, a now-defunct service that briefly dominated the cryptojacking scene before being shut down in 2019.

In the same year, reports on its prevalence have become conflicting, with some telling Decrypt it hasn’t returned to “previous levels” even as some threat research labs confirmed a 29% rise at the time.

‘Stay low, mine slow’

Over half a decade later, the tactic appears to be staging a quiet comeback: reconfiguring itself from noisy, CPU-choking scripts into low-profile miners built for stealth and persistence.

Rather than burning out devices, today’s campaigns spread quietly across thousands of sites, following a new playbook that, as c/side puts it, aims to “stay low, mine slow.”

That shift in strategy is no accident, according to an information security researcher familiar with the campaign who spoke to Decrypt on condition of anonymity.

The group appears to be reusing old infrastructure to prioritize long-term access and passive income, Decrypt was told.

“These groups most likely already control thousands of hacked WordPress sites and e-commerce stores from past Magecart campaigns,” the researcher told Decrypt.

Magecart campaigns are attacks where hackers inject malicious code into online checkout pages to steal payment information.

“Planting the miner was trivial, they simply added one more script to load the obfuscated JS, repurposing existing access,” the researcher said.

But what stands out, the researcher said, is how quietly the campaign operates, making it hard to detect with older methods.

“One way past cryptojacking scripts were detected was by their high CPU usage,” Decrypt was told. “This new wave avoids that by using throttled WebAssembly miners that stay under the radar, capping CPU usage and communicating over WebSockets.”

WebAssembly enables code to run faster inside a browser, while WebSockets maintain a constant connection to a server. Combined, these enable a crypto miner to work without drawing attention.

The risk isn’t “directly targeting crypto users, since the script doesn’t drain wallets, although technically, they could add a wallet drainer to the payload,” the anonymous researcher told Decrypt. “The real target is server and web app owners,” they added.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

Crypto in war crisis? Not Bitcoin – Here’s how BTC is holding up

UK Treasury Secretary Rules Out National Crypto Reserve: ‘Not the Plan for Us’

Bitcoin [BTC] accumulation rises as ETF outflows cool – Is a breakout coming?

Celestia eyes 184% rally to $9.8 – Assessing the odds of TIA’s rise

Crypto.com Relaunches US Institutional Exchange With Trump in White House

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Kaspa [KAS] soars 13% – But THIS resistance zone signals caution!
Next Article Michael Saylor’s Strategy IPO could raise $500M for Bitcoin – Here’s how
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Elon Musk’s SpaceX Moves Bitcoin Holdings for First Time in 3 Years
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?