Malwarebytes researcher Jerome Segura has discovered a new cryptojacking technique used by hackers called Pop-under. This is a trick that opens a pop-up window behind a website you have visited and unknowingly performs operations there to infect you.
The JavaScript code that is used is set by the website's own developer who can define the exact dimensions of the window as well as the position where it will be placed. Specifically:
Horizontal Position = Screen size – 100px (Where px are pixels)
Vertical Position = Screen size – 40px ( Where px are pixels)
This, for most users, results in the creation of a very small window behind the toolbar, at the bottom of their screen. The attacker loads a JavaScript file that contains a customized version of the Coinhive-In Browser Miner and uses your CPU resources to generate the Monero Coin.
Although this method deceives users, the way to deal with it is not difficult.
- A simple step is to make the bottom bar on the desktop transparent, locate the fake window and close it.
- A second one is to open the Task Manager by pressing, for example, Ctrl+Alt-Delete and see if your CPU is running at 100% without you performing any task. This should make you think that something malicious may be consuming your resources.
At the moment, the Pop-under Cryptojacking malware seems to only affect Chrome browsers, however, in any case, Malwarebytes experts recommend that you regularly scan your computers for malware
