Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for Cryptojacking
Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr
摘要
The release of an efficient browser-based cryptominer, as introduced by Coinhive in 2017, has quickly spread throughout the web either as a new source of revenue for websites or exploited within the context of hacks and malicious advertisements. Several studies have analyzed the Alexa Top 1M and found 380 -3,200 [5, 15, 18, 30, 31] (0.038% -0.32%) to be actively mining, with an estimated $41,000 per month revenue for the top 10 perpetrators [18] . While placing a cryptominer on a popular website supplies considerable returns from its visitors' web browsers, it only generates revenue while a client is visiting the page. Even though large popular websites attract millions of visitors, the relatively low number of exploiting websites limits the total revenue that can be made. In this paper, we report on a new attack vector that drastically overshadows all existing cryptojacking activity discovered to date. Through a firmware vulnerability in MikroTik routers, cyber criminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing web connection. Thus, every web page visited by any user behind an infected router would mine to profit the criminals. Based on NetFlows recorded in a Tier 1 network, semiweekly crawls and telescope traffic, we followed their activities over a period of 10 months, and report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, approximately 70% of all MikroTik devices deployed worldwide. We observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. Our results show that cryptojacking through MITM attacks is highly lucrative, a factor of 30 more than previous attack vectors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Examining Mirai's Battle over the Internet of ThingsHarm Griffioen, Christian DoerrCCS 2020 · 被引用 81 次
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 被引用 30 次
- Out of Sight, Out of Mind: Detecting Orphaned Web Pages at Internet-ScaleStijn Pletinckx, Kevin Borgolte, Tobias FiebigCCS 2021 · 被引用 11 次
- Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and CoverageGibran Gómez, Kevin van Liebergen, Juan CaballeroCCS 2023 · 被引用 10 次
- Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the WildZhenrui Zhang, Geng Hong, Xiang Li, Zhuoqun Fu 等CCS 2023 · 被引用 9 次
它引用的顶会 Paper3
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer 等CCS 2018 · 被引用 162 次
- How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldGeng Hong, Zhemin Yang, Sen Yang, Lei Zhang 等CCS 2018 · 被引用 120 次
- Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet ScaleHugo L. J. Bijmans, Tim M. Booij, Christian DoerrUSENIX Security 2019 · 被引用 46 次
相关 Paper
- Robbery on DevOps: Understanding and Mitigating Illicit Cryptomining on Continuous Integration Service PlatformsZhi Li, Weijie Liu, Hongbo Chen, XiaoFeng Wang 等S&P 2022 · 被引用 19 次
- A Lightweight IoT Cryptojacking Detection Mechanism in Heterogeneous Smart Home NetworksEge Tekiner, Abbas Acar, A. Selcuk UluagacNDSS 2022
- MinerRay: Semantics-Aware Analysis for Ever-Evolving Cryptojacking DetectionAlan Romano, Yunhui Zheng, Weihang WangASE 2020 · 被引用 30 次
- MineShark: Cryptomining Traffic Detection at ScaleShaoke Xi, Tianyi Fu, Kai Bu, Chunling Yang 等NDSS 2025
- The Poorest Man in Babylon: A Longitudinal Study of Cryptocurrency Investment ScamsMuhammad Muzammil, Abisheka Pitumpe, Xigao Li, Amir Rahmati 等WWW 2025 · 被引用 13 次
