Cryptojacking is a technique that cybercriminals use to mine cryptocurrency without permission by taking advantage of the processing capabilities of a victim’s device – active or inactive – by executing malicious code. Victims may not be aware that this is happening in the background, but may experience decreased performance, overheating, and increased fan activity (with noticeable noise). On Android devices, the workload can even “bloat” the battery and cause physical damage or destruction of the hardware. ESET, a leading company in the field of preventive threat detection, has identified with the help of its telemetry the main sites where malicious miners are most often detected in the region.
This threat was very present during 2025, for example in July the company compromised more than 3,500 websites for illegal mining. ESET telemetry data in Latin America for the second half of 2025 highlights two domain profiles associated with the detection of mining scripts:
- Sites with “expected” risk: These could be pirate pages, unofficial file downloads, and streaming sites. The common characteristics of these sites, which are monetized by cybercriminals, are long dwell times, the presence of aggressive advertising (malware), and the constant execution of third-party scripts.
- Compromised legitimate sites: such as schools, small and medium-sized businesses, local media, or any other sites that do not pose a particular risk. In these cases, the benefit for attackers is not the time spent by the visitor, but the volume of hacked sites.
The 5 types of sites with the highest number of detections according to ESET telemetry in the region during 2025:
1 – Pirate download sites via torrents/repacks (unofficial downloads): Although these sites may do direct mining, they usually show malicious ads that contain a script. These ads are usually very aggressive, with constant pop-ups, and also run third-party scripts.
Examples: piratebays.to (34.8%); thepiratebay3.to; thepiratebay2.to; switchtorrent.org or fitgirl-repacks.site
2 – Anime/manga: These are mediums of long-term consumption. Visitors spend a long time reading or watching sections, browsing the site and are used to a constant bombardment of pop-ups. This behavior makes them an ideal location for in-browser hacking.
Examples: Performer: Submo Horom, contreema or confile; this percle.— kwer.— this room.—my. avoocas is not in the world-cct. is permes.- alemvous.- main mass.-cct; with and prince.—- cm doctor—a-ma.-cm ; because of Sit alone.— Bamal.—
3 – Education: Among the sites with the highest number of detections are also many that appear to be educational institutions (private and public) in Colombia, Mexico, Brazil or Argentina, among other countries. According to discovery history, some of them were used for cryptojacking for two years.
“These types of sites are attractive to cyber attackers because of their scale, as the compromise of many small sites, with few visits, creates profitability. A typical characteristic of this profile is that they have had their CMS compromised (WordPress/Plugins, weak credentials, shared hosting) and thus end up being victims of JavaScript injection. That is, it is not the intention of the institution, but rather they are victims due to lack of security, unmonitored websites or limited resources”, comments Martina López, security researcher. ESET Latin America IT.
Examples: colfre—-.edu.co ; gimnasiosa—-.edu.co ; educational center—-.edu.co ; liceolos—–.edu.co; colgarcia—-.com; colmer—-.com ; colsanluis—-.com ; colmetro—-.com; liceodomingo—–.com; col—–bogota.com; colegio—-bga.com; colsan—–.com; quipux.gobierno—–.gob.ec ; education.polo—.pr.gov.br; oev.unm—.edu.pe; gd—.gob—.ve
4 – SMEs and local businesses: Many domains come from legitimate small businesses in various industries such as services, auto parts, metallurgy, logistics and accounting, among others. From ESET, they note that it is likely that the site has been compromised by third parties and that the owner does not know that it is on a cryptojacking service.
Examples: mar-pla—.com ; ceola—.com.mx; rvmmo—-.com.ar; nettocontab—-.com.br; tetrak—-.com.br ; metal—-.ind.br ; dietrich-log—-.com.co ; deauto—-.com ; octopus—.com ; shield—.com.br; tiagoromasarq—-.com.br
5 – Local media/news: ESET telemetry detections show several regional media and news sites with a focus on Mexico and Brazil. These types of sites usually get a lot of traffic, they use ads for monetization, and they use CMS, widgets, plugins, and other third-party tools. Although they have more visits, they are not as long as streaming ones, and although they use advertising, they are not as aggressive.
Examples: hidalgo.quad—-.com.mx ; tribunarib—-.com.br ; Jornalab—-.com.br; met—cmx.com; elacarig—-.com
Given this scenario, ESET shares various specific actions to avoid becoming a victim of cryptocurrency mining:
For users:
- Keep your operating system and browser updated as many companies exploit known vulnerabilities.
- Use a robust security solution that detects mining scripts in real-time on both desktop and mobile devices.
- Beware of sites with excessive pop-ups or invasive ads, especially on unofficial streaming platforms or pirated downloads.
- Close tabs that cause overheating, extreme slowness, or unusual CPU usage, even if the site looks legitimate.
For small and medium enterprises, educational institutions and mass media:
- Update your CMS, plugins, and themes and remove unused extensions.
- Periodically check your site’s code for suspicious JavaScript injections.
- Implement strong passwords and multi-factor authentication for administrative access.
- Choose hosting providers with security monitoring and incident support.
- Check for third-party scripts and ad networks, as many infections occur through compromised legitimate external services.
- Schedule periodic safety reviews.
- Restriction of user privileges and access to the administrative panel.
- Make frequent backups to be able to quickly restore your site in the event of a hack.
“Cryptocurrency mining is no longer a marginal threat and is not limited to illegal sites: today it affects legitimate organizations throughout Latin America and is supported by persistent and silent companies,” concludes Lopez of ESET Latin America.
Fountain. ESET

