{"id":13588,"date":"2019-02-18T13:26:03","date_gmt":"2019-02-18T00:26:03","guid":{"rendered":"https:\/\/8bitisland.co.nz\/?p=13588"},"modified":"2019-02-18T13:26:05","modified_gmt":"2019-02-18T00:26:05","slug":"symantec-finds-cryptojacking-apps-on-microsoft-store","status":"publish","type":"post","link":"https:\/\/8bitisland.co.nz\/symantec-finds-cryptojacking-apps-on-microsoft-store\/","title":{"rendered":"Symantec Finds Cryptojacking Apps on Microsoft Store"},"content":{"rendered":"\r\n

In alarming news, Symantec has revealed that they have found eight apps on Microsoft’s app store that mine the cryptocurrency Monero without the user’s knowledge.<\/p>\r\n\r\n\r\n\r\n

In January, Symantec discovered several potentially unwanted applications (PUAs) on the Microsoft Store that surreptitiously use the victim\u2019s CPU power to mine cryptocurrency. Symantec reporting these apps to Microsoft and they subsequently removed them from their store.<\/p>\r\n\r\n\r\n\r\n

The apps \u2014 which included those for computer and battery optimisation tutorial, and video viewing and download \u2014 came from three developers: DigiDream, 1clean, and Findoo. In total, we discovered eight apps from these developers that shared the same risky behaviour. After further investigation, it is believed that all these apps were likely developed by the same person or group. Possessing these cryptocurrencies can be a very lucrative practice to become involved in, as you can then begin to trade these virtual commodities on online trading platforms such as cryptoevent.io<\/a>. However, it is usually very costly to mine these cryptocurrencies, which is why many people will revert to less conventional means of mining them. <\/p>\r\n\r\n\r\n\r\n

<\/figure>\r\n\r\n\r\n\r\n

Users may get introduced to these apps through the top free apps lists on the Microsoft Store or through keyword search. The samples found run on Windows 10, including Windows 10 S Mode.<\/p>\r\n\r\n\r\n\r\n

As soon as the apps are downloaded and launched, they fetch a coin-mining JavaScript library by triggering Google Tag Manager (GTM) in their domain servers. The mining script then gets activated and begins using the majority of the computer\u2019s CPU cycles to mine Monero for the operators. Although these apps appear to provide privacy policies, there is no mention of coin mining on their descriptions on the app store. If you own any cryptocurrencies and you’re worried that yours may be hacked and stolen from you, you may want to look into your own personal cryptocurrency offline wallet<\/a> as an added layer of security.<\/p>\r\n\r\n\r\n\r\n

Mitigation<\/strong><\/p>\r\n\r\n\r\n\r\n

Stay protected from online threats and risks by taking these precautions:<\/p>\r\n\r\n\r\n\r\n