{"id":11575,"date":"2018-02-23T10:10:04","date_gmt":"2018-02-23T18:10:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/02\/23\/news-5346\/"},"modified":"2018-02-23T10:10:04","modified_gmt":"2018-02-23T18:10:04","slug":"news-5346","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/02\/23\/news-5346\/","title":{"rendered":"Deepfakes FakeApp tool (briefly) includes cryptominer"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 23 Feb 2018 17:20:00 +0000<\/strong><\/p>\n<p>A few weeks ago, we took a look at a forum dedicated to Deepfake clips where the site was pushing <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/02\/new-deepfakes-forum-goes-mining-with-coinhive\/\" target=\"_blank\" rel=\"noopener\">Coinhive mining scripts<\/a> in the website&#8217;s HTML code.<\/p>\n<p>As it turns out, there&#8217;s been another mining blow-out in the form of one of the apps used to make the fakes. That&#8217;s right\u2014a tool designed to push CPU\/GPU hard in order to create movie files\u00a0<em>also<\/em> wanted you to push the GPU that much further and do a spot of mining in the background at the same time.<\/p>\n<p>The developer of one of the most popular Deepfake movie makers, FakeApp (previously mentioned on <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/bjye8a\/reddit-fake-porn-app-daisy-ridley\" target=\"_blank\" rel=\"noopener\">Motherboard<\/a>\u00a0as a &#8220;user-friendly version&#8221; of the Deepfakes technology), decided to add an optional mining function into the latest release of their program. The reception to this was, to be fair, a complete disaster and it wasn&#8217;t long before said developer realised everything had gone a bit wrong and pulled the miner.<\/p>\n<p>The majority of the posts online made about this range from lengthy rants to angry swearing to the occasional passing insult and a lot of &#8220;download the old version or use something else.&#8221; If you want to foster a complete sense of mistrust in your app then this is definitely the way to do it:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-1.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21829\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-1-300x150.jpg\" alt=\"Mining? In my faker tool?\" width=\"300\" height=\"150\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-1-300x150.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-1-600x301.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-1.jpg 1151w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<blockquote>\n<h3><em>The Developer just announced he is removing the miner. I don&#8217;t know if that means you&#8217;ll have to wait for a new version or if it&#8217;s remotely disabled immediately.<\/em><\/h3>\n<\/blockquote>\n<p>According to the above poster, the mining free version was 100KB smaller than the previous file, so if you weighed in at 70.58MB you were fine, but if you tallied up at 70.68MB you might have wanted to abandon ship. Here&#8217;s a <a href=\"https:\/\/www.reddit.com\/r\/SFWdeepfakes\/comments\/7yov8p\/fakeapp_22_downloadable_now_has_miner_included\/\" target=\"_blank\" rel=\"noopener\">rather angry Reddit thread<\/a>\u00a0about it:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-2.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21830\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-2-300x80.jpg\" alt=\"A mining we will go\" width=\"300\" height=\"80\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-2-300x80.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-2-600x160.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-post-2.jpg 808w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<p>On another popular Deepfake forum, they&#8217;re specifically highlighting the two different versions:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-included.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21833\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-included-300x115.jpg\" alt=\"miner included\" width=\"300\" height=\"115\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-included-300x115.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-included-600x230.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-included.jpg 848w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<blockquote>\n<h3><em>Make sure you have the version without the cryptominer:<\/em><\/h3>\n<h3><em>Download from &#8211; (may have miner):<\/em><br \/> <em>Download from &#8211; (no miner):<\/em><\/h3>\n<\/blockquote>\n<p>According to the Reddit post up above, the app only &#8220;mined when you were training&#8221; (training being the process of making the computer learn how to draw faces) so you &#8220;wouldn&#8217;t notice the extra load.&#8221; After the hostile reception to the mining, FakeApp v2.2 was taken down by the app developer after a day and re-uploaded sans miner:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/removed.jpg\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21832\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/removed-300x34.jpg\" alt=\"removed!\" width=\"300\" height=\"34\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/removed-300x34.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/removed-600x68.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/removed.jpg 1240w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<blockquote>\n<h3><em>The donation miner was introduced and removed in one day. The rest is totally clean as has been seen by everyone who&#8217;s used it. I&#8217;m not doing this to make money.<\/em><\/h3>\n<\/blockquote>\n<p>Regardless of the reasoning, it turns out people do not like miners on their computer\u2014especially when they&#8217;re already entrusting a good chunk of heavy duty usage to the app developer as it is. No amount of experiments in funding will make up for this kind of damage limitation exercise:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/accusations.jpg\" data-rel=\"lightbox-4\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21834\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/accusations-300x129.jpg\" alt=\"accusations\" width=\"300\" height=\"129\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/accusations-300x129.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/accusations-600x258.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/accusations-195x85.jpg 195w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/accusations.jpg 1308w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<blockquote>\n<h3><em>I am not counting on anyone accidentally mining $0.004 cents for me, this is an oversight that has happened for every setting since release. I&#8217;m not playing &#8220;innocent and transparent&#8221; I am trying to help people like I have since the beginning. In fact, I am in the process of putting in code to specially turn it off permanently after people have requested [to turn off the miner].<\/em><\/h3>\n<\/blockquote>\n<p>Miners are a touchy enough subject without additional controversy over the mining function springing back to life every time you restart the program. Worse still, users felt there were also disclosure issues regarding the miner being onboard. In the below screenshot, the developer is having to point out they included a non-skippable disclaimer in the app changelog while admitting they forgot to add it to the changelog on the website:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/forgot.jpg\" data-rel=\"lightbox-5\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21835\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/forgot-300x74.jpg\" alt=\"I forgot\" width=\"300\" height=\"74\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/forgot-300x74.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/forgot-600x149.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/forgot.jpg 1344w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<p>Frankly, it&#8217;s all a bit of a mess in fake pornography movie land, and this developer is immediately reaping the whirlwind of &#8220;probably shouldn&#8217;t have gone with a miner after all.&#8221; As for what kind of mining was taking place, it was <a href=\"https:\/\/www.reddit.com\/r\/SFWdeepfakes\/comments\/7yov8p\/fakeapp_22_downloadable_now_has_miner_included\/dui8px2\/\" target=\"_blank\" rel=\"noopener\">our old friend Coinhive<\/a>\u2014humorously, the exact type of mining we spotted being used on that Deepfake forum from a fortnight ago.<\/p>\n<p>As for the developer, they&#8217;re left firefighting and posting <a href=\"https:\/\/www.reddit.com\/r\/SFWdeepfakes\/comments\/7yrj84\/fakeapp_optional_donation_miner_removed\/\" target=\"_blank\" rel=\"noopener\">apologetic rambles<\/a> on Reddit:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-removed.jpg\" data-rel=\"lightbox-6\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-21837\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-removed-300x129.jpg\" alt=\"miner removed\" width=\"300\" height=\"129\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-removed-300x129.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-removed-600x259.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-removed-195x85.jpg 195w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/miner-removed.jpg 1267w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\">Click to enlarge<\/p>\n<blockquote>\n<h3><em>I didn&#8217;t do it in an attempt to secretly make a profit of users using FakeApp\u2014mining is neither secret nor profitable. I made an effort to be as upfront about it as I could possibly be, putting notices everywhere I could put them, and on the forum the reaction seemed to be mainly positive.<\/em><\/h3>\n<h3><em>Making a voluntary $10\/week to help speed up development off willing donors is not a scam; this was a donation feature that many liked, many were politely uncomfortable with, and a handful seemed intent to read malicious intent into. I have been here since the beginning and anyone who knows my work knows I care about making this tool accessible not making a profit, and that&#8217;s why I&#8217;ve spent so much of my free time on it.<\/em><\/h3>\n<\/blockquote>\n<p>It is honestly surprising to me that, in the middle of news stories galore about <a href=\"https:\/\/www.theregister.co.uk\/2018\/02\/21\/salon_site_mines_monero_ad_blocker\/\" target=\"_blank\" rel=\"noopener\">mining being annoying<\/a>, someone thought squeezing extra juice out of an <em>already<\/em> juice-squeezed PC for some digital coin generation couldn&#8217;t possibly go wrong. The Deepfakes industry has already branched out into multiple tools and programs, and there&#8217;s a fair bit of choice out there\u2014one mistake is all it takes, and the fanbase developers have built up will quickly disappear.<\/p>\n<p>One of the most well-known Deepfake programs around has (temporarily) succumbed to the lure of mining, and between this huge reputation blow to arguably the most popular DIY app out there, and the long list of supposed Deepfake sites pushing mining scripts and dubious adverts all over the place, it&#8217;s entirely possible that the fake pornography clip industry has started to show signs of a slow, relentless collapse into &#8220;We&#8217;re not really into this anymore.&#8221;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2018\/02\/deepfakes-fakeapp-tool-briefly-includes-cryptominer\/\">Deepfakes FakeApp tool (briefly) includes cryptominer<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2018\/02\/deepfakes-fakeapp-tool-briefly-includes-cryptominer\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 23 Feb 2018 17:20:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/security-world\/2018\/02\/deepfakes-fakeapp-tool-briefly-includes-cryptominer\/' title='Deepfakes FakeApp tool (briefly) includes cryptominer'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/02\/shutterstock_691346062.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>We take a look at what happens when one of the most popular DIY Deepfakes programs decides to monetise with a spot of coin mining. Surprise: it doesn&#8217;t end well.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/\" rel=\"category tag\">Security world<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/technology\/\" rel=\"category tag\">Technology<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/coin-mining\/\" rel=\"tag\">coin mining<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/coinhive\/\" rel=\"tag\">coinhive<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/crypto\/\" rel=\"tag\">crypto<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/deepfake\/\" rel=\"tag\">deepfake<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/deepfakes\/\" rel=\"tag\">deepfakes<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fake\/\" rel=\"tag\">fake<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fakeapp\/\" rel=\"tag\">fakeapp<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/miner\/\" rel=\"tag\">miner<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mining\/\" rel=\"tag\">mining<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/security-world\/2018\/02\/deepfakes-fakeapp-tool-briefly-includes-cryptominer\/' title='Deepfakes FakeApp tool (briefly) includes cryptominer'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2018\/02\/deepfakes-fakeapp-tool-briefly-includes-cryptominer\/\">Deepfakes FakeApp tool (briefly) includes cryptominer<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[17607,15078,10537,17608,17473,11539,17228,16398,901,10497,1331],"class_list":["post-11575","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-coin-mining","tag-coinhive","tag-crypto","tag-deepfake","tag-deepfakes","tag-fake","tag-fakeapp","tag-miner","tag-mining","tag-security-world","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11575"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11575\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}