Cryptocurrency miners found on Microsoft Store

Eight potentially unwanted applications (PUAs) found to contain code that secretly mines for Monero


Around eight potentially unwanted applications (PUAs) have been discovered on the Microsoft Store that use a victim's computer to mine cryptocurrency.

The apps, which included those for computer and battery optimisation, internet search, web browsers, and video viewing and download and came from three developers: DigiDream, 1clean, and Findoo, according to a blog post by security researchers at Symantec,

Advertisement - Article continues below

The researchers said that as soon as the apps are downloaded and launched, they fetch a coin-mining JavaScript library by triggering Google Tag Manager (GTM) in their domain servers.

"The mining script then gets activated and begins using the majority of the computer's CPU cycles to mine Monero for the operators. Although these apps appear to provide privacy policies, there is no mention of coin mining on their descriptions on the app store," researchers said.

When each app is launched, a web domain is silently visited in the background and triggers GTM with the key GTM-PRFLJPX, which is shared across all eight applications.

Researchers said that while GTM is a legitimate tool that allows developers to inject JavaScript dynamically into their applications, these malicious developers abused this to conceal malicious or risky behaviours.

The apps were put on the app store between April and December 2018, the investigation found. And while the apps were only on the store for a short time, a significant number of users may have downloaded them. Researchers said that there were almost 1,900 ratings posted for these apps.

Advertisement - Article continues below
Advertisement - Article continues below

The apps in question are Fast-search Lite, Battery Optimizer (Tutorials), VPN Browsers+, Downloader for YouTube Videos, Clean Master+ (Tutorials), FastTube, Findoo Browser 2019, and Findoo Mobile & Desktop Search apps. Researchers said that they have informed Microsoft and Google about these apps, and they have since been removed from the store. 

The mining JavaScript has also been removed from Google Tag Manager.

The news comes at a time when app stores are coming under increased pressure to improve the effectiveness of their app vetting procedures. Google's Play Store has long been criticised for hosting malicious applications, including those that host so-called 'cryptojacking' code and spyware.

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now



University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020
Policy & legislation

Senators propose a bill aimed at ending warrant-proof encryption

24 Jun 2020

Most Popular


How to find RAM speed, size and type

24 Jun 2020
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020

The road to recovery

30 Jun 2020