In recent days, many Bitcoin owners have reported to BitcoinTalk that they have received suspicious emails designed to somehow steal their Bitcoins. Security researchers have analyzed the attack and provide us with more details.
According to LogRythm, the attack begins with an email message with the subject line “Wallet Backup.” The message states:
“Hi David
I did exactly what you told me to do, but the problem remains: importing the private key doesn't work and it's driving me crazy!
Last time I checked blockchain.info it still had 30.28020001 BTC in my account. But the bitcoinqt client is not loading the key so I can't access my BTCs.
Thanks for your help. I'm sending you the wallet.dat with my password [shortened URL]. If you need anything else, let me know. If you can finally enter the key, send me the BTC to the account: 1DxFvJ6up9jXAZ9pkUmWVdiMTWvsjgB5Ea
You will be very helpful. Thanks David!”
The link leads to a website set up to “serve” a file named “Backup.zip.” The file contains several other files, but only two of them are visible: Password.txt.lnk and wallet.dat.
When the link file is executed, it appears to open a txt file containing a password. However, a malicious executable file has started running in the background.
The malware waits for its victim to open their Bitcoin wallet using the Bitcoin-Qt. While victims believe they will “get their hands on” 30 BTC, in reality, they will empty their own wallets.
LogRythm found that the shortened URL has been run by at least 1,674 people. Most of the victims of this attack are located in the United States.
For more technical details about the attack and the malware used by the attackers, see the LogRythm blog.

