For three days between March 25 and March 27, a malicious actor has poisoned an important advertising network and used its services to deliver a cryptojacking script to multiple websites, including Microsoft’s MSN portal.
Trend Micro, the cyber-security firm which spotted the event, says that by planting their in-browser cryptocurrency miner on a high-trafficked site like MSN, crooks managed to double the number of cryptojacking scripts from March 24 to March 25, detections going up by 108%.
Fortunately, the event was contained only to MSN’s Japan portal, otherwise, the incident would have been much worse.
Cryptojacking script injected via AOL ad platform
“The malicious script was injected on advertising.aolp.jp, the AOL advertising platform,” said Trend Micro.
This domain contained an in-browser cryptocurrency miner that utilized users’ CPU resources to mine the Monero cryptocurrency. Users affected by the incident saw sudden spikes in CPU usage and their PC slowing down while visiting affected sites.
Over 500 sites affected
Experts said they tracked the malicious ads to more than 500 sites, with the most high-profile being the MSN Japan portal.
The malicious ads loaded the cryptojacking script from the domain www[.]jqcdn[.]download, registered a week before the attack.
“The web miner traffic was linked to the malicious domain www[.]jqcdn[.]download, which was created on March 18.”