According to Australia’s Attorney General’s office, thousands of websites across the globe have fallen victim to crypto-mining malware, after using a popular web tool designed to help people with vision impairment, dyslexia and low literacy.
Security researcher Scott Helme claims 4,275 websites have been hijacked worldwide, including in Australia.
In crypto-mining, the power and memory of your computer is used to generate cryptocurrency. If criminals gain access to your computer they can generate crypto-currency without your knowledge.
It is understood criminals secretly added a malicious program onto the website plug-in ‘Browsealoud’ which allowed them to mine cryptocurrency when the browser window was loaded.
Does it affect my business?
Businesses that rely on the digital accessibility tool ‘Browsealoud’ to deliver a text-to-speech web application are potentially affected.
Texthelp, the company that delivers ‘Browsealoud’ says it has taken the program offline while the company alerts its customers.
What do I need to do?
Install any security updates as they become available.
Make sure your organisation’s computers and applications are up to date.
What is crypto-mining?
Crypto-mining is when your computer is used to generate cryptocurrency, such as BitCoin and Monero.
Crypto-mining is a financially motivated activity. In this case, criminals are using malware to access computers and networks, to create currency or sell processing power to other people.
Visit government website, Stay Smart Online website for more information about software updates and protecting your business.
The information provided here is of a general nature. Everyone’s circumstances are different. If you require specific advice you should contact your local technical support provider.
Thank you to those subscribers who have provided feedback to our Alerts and Newsletters. We are very interested in your feedback and where possible take on board your suggestions or requests.
This information has been prepared by the Attorney General’s Department (‘the Department’). It was accurate and up to date at the time of publishing.
This information is general information only and is intended for use by private individuals and small to medium sized businesses. If you are concerned about a specific cyber security issue you should seek professional advice.
The Commonwealth and all other persons associated with this advisory accept no liability for any damage, loss or expense incurred as a result of the provision of this information, whether by way of negligence or otherwise.
Nothing in this information (including the listing of a person or organisation or links to other web sites) should be taken as an endorsement of a particular product or service.
Please note that third party views or recommendations included in this information do not reflect the views of the Commonwealth, or indicate its commitment to a particular course of action. The Commonwealth also cannot verify the accuracy of any third party material included in this information.