Virtual criminals have turned thousands of web pages into crypto mining machines without the owners' knowledge, illegally. Over 3,500 sites were infected just in July of last year in Latin America. The warning comes from the digital security company ESET, based on data collected throughout 2025.
The illegal operation occurs precisely when Brazil establishes stricter rules for the digital asset market under the supervision of the Central Bank.
Virus turns your computer into a crypto miner
The scam works like this: hackers install hidden codes on websites. When you access the page, your computer or phone starts working to generate digital coins for the criminals. You don’t see anything happening, but the device becomes slow, overheats, consumes more energy, and wears out faster. On phones, the battery can even swell.
The technique has a name: cryptojacking. It works like a digital parasite that drains the processing power of those who visit the infected site.
ESET's survey identified two groups of attacked sites. The first includes pages already known to be dangerous. The second includes trusted sites that have been compromised.
Anime pages, schools, and newspapers have become primary targets
Risky sites by nature lead the list. Pirate streaming platforms, illegal download pages, and anime portals concentrate users for a long time. They have invasive ads and run multiple codes simultaneously. Criminals take advantage of this chaos to include the miner.
But the problem doesn’t stop there. Serious sites have also become victims. Schools, small businesses, and media outlets have been compromised by basic security flaws. Outdated systems, weak passwords, and vulnerable plugins opened doors for attacks.
ESET mapped the five types of most affected sites: pirate download platforms, anime and manga pages, educational institutions, small businesses, and regional news portals.
The criminals' strategy prioritizes quantity, not time on site. Attacking hundreds of small sites yields more than focusing on a few large sites. Even pages with little traffic generate profit when summed up.
“Compromising many small domains, even with few visits, still generates profitability. In most cases, these pages have been affected by common flaws, such as outdated CMS, insecure plugins, weak credentials, or shared hosting environments. It is not an intentional action by the institutions, but the consequences of security gaps and lack of updates,” explains Daniel Barbosa, a security researcher at ESET in Brazil.
CMS are platforms like WordPress that make it easier to create websites without programming.
New laws from the Central Bank do not prevent this type of attack
Brazil approved stricter rules for the crypto market in November 2025. Resolutions 519, 520, and 521 from the Central Bank expanded the Legal Framework for Crypto Assets. Now exchanges need a license, follow anti-money laundering rules, and provide transparency in operations with stablecoins. These digital currencies maintain a fixed value by mirroring traditional currencies like the real and the dollar.
The rules started to take effect in February of this year. More requirements will come into effect in the coming months.
But these laws target financial fraud and investor protection. They do not cover technical attacks like cryptojacking. Criminals exploit gaps in websites, not in exchanges or digital wallets.
For those browsing, the result is slow computers and higher electricity bills. For website owners, their reputation goes down the drain and trust plummets. Worse: a compromised site can become an entry point for larger attacks.
Basic defenses block most attacks
Ordinary users should keep their browsers and systems always updated. Security programs can detect miners in real time. Be wary of sites full of flashing ads.
Companies, schools, and newsrooms need to constantly update website platforms and plugins. Reviewing third-party codes has become a requirement. Strong passwords are no longer enough—two-factor authentication is necessary. Security audits should be routine, not an exception.
“Malicious cryptocurrency mining has ceased to be an isolated threat or restricted to illegal sites. Today, it already affects legitimate organizations throughout Latin America through persistent and silent campaigns. A scenario that reinforces the importance of constant attention and continuous monitoring,” concludes Barbosa.
The article 'Hackers use 3,500 Latin sites for illegal crypto mining' was first seen on BeInCrypto Brazil.
