Share this article

Monero Mining Malware Attack Linked to Egyptian Telecom Giant

Thousands of devices allegedly affected by malware across Egypt, Turkey and Syria.

Updated Sep 13, 2021, 7:40 a.m. Published Mar 12, 2018, 6:00 a.m.
Egypt

Unidentified entities at a telecom company connected to the Egyptian government are using malware to trick Middle Eastern Web users into unwittingly mining monero, according to a new report.

Internet users in Turkey and Syria who downloaded Windows applications such as Avast Antivirus, CCleaner, Opera, or 7-Zip were unknowingly redirected to malicious versions with malware, the University of Toronto's Citizen Lab claimed in a study published Friday.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The report

– which calls this scheme "AdHose – explained:

"We found that a series of middleboxes on Türk Telekom's network were being used to redirect hundreds of users attempting to download certain legitimate programs to versions of those programs bundled with spyware....We found similar middleboxes at a Telecom Egypt demarcation point. The middleboxes were being used to redirect users across dozens of ISPs to affiliate ads and browser cryptocurrency mining scripts."

Telecom Egypt

is a major state-owned telecommunications company, and the middleboxes in question include Sandvine PacketLogic devices, which have been associated with government surveillance in Turkey and Syria. The researchers' regional network sweep in January found 5,700 devices affected by AdHose.

When reached for comment, Sandvine pushed back against the report's findings, telling CoinDesk:

"Based on a preliminary review of the report, certain Citizen Lab allegations are technically inaccurate and intentionally misleading....We have never had, directly or indirectly, any commercial or technology relationship with any known malware vendors, and our products do not and cannot inject malicious software. While our products include a redirection feature, HTTP redirection is a commodity-like technology that is commonly included in many types of technology products."

The spokesperson also said that an investigation into the allegations is being undertaken because the company is "deeply committed to ethical technology development."

The idea of cryptocurrency-fueled government spyware may seem far-fetched. However, researchers involved with the Tor Project’s Open Observatory of Network Interference noted a similar malware epidemic – minus the cryptocurrency mining element – in 2016. Tor researchers found the Telecom Egypt-owned internet provider TE Data, which controls the majority of Egyptian internet bandwidth, facilitated a man-in-the-middle attack with both malware and affiliate advertising.

Egyptian flag and bitcoin image via Shutterstock

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Zcash Floats Dynamic Fee Plan to Ensure Users Won’t Be Priced Out

(Christian Dubovan/Unsplash, modified by CoinDesk)

ZEC zoomed 12% amid the fee discussion, beating gains across all major tokens.

What to know:

  • A new proposal by Shielded Labs suggests a dynamic fee market for Zcash to address rising transaction costs and network congestion.
  • The proposed system uses a median fee per action observed over the prior 50 blocks, with a priority lane for high-demand periods.
  • The changes aim to maintain Zcash's privacy features while avoiding complex protocol redesigns.