Even after the famous Bitcoin exchange Mt.Gox fell victim to an online heist, cryptocurrencies continue to be popular. The rapid increase in the value of virtual cryptocurrencies like Bitcoin makes them quite attractive to thieves, and of course it is now necessary for users to start taking additional measures to secure their online/offline wallets.
There are currently more than 100 different malware families targeting users’ wallets and transactions to steal Bitcoins and 40 other cryptocurrencies like Litecoin, Flexcoin, and others, Dell SecureWorks researchers reported during the RSA Conference last week. About 80 of them emerged over the past year, when Bitcoin’s value reached $1,000.
While there are some types of malware specifically designed to steal digital currencies, most of them are based on generic malware designed to steal currencies and modified depending on the type of cryptocurrency the developer wants to steal, said Joe Stewart, director of malware research at Dell SecureWorks. While malware can already steal login credentials for online banking sites, modifying it to grab online wallet credentials and transactions is not technically difficult. Most of the thieves who write them are “script kiddies,” the researcher said.
In fact, the malware and the tools that can be used to build it are not overly complex and are widely available. For example, the most popular malware PredatorPain, which is responsible for a third of all Bitcoin theft attempts, costs just $35 on underground forums. “A novice programmer could create something that would steal Bitcoins,” said Pat Litke, a consulting security analyst with Dell SecureWorks’ Counter Threat Unit.
Why are they targeting Bitcoins?
Bitcoin is an open-source form of cryptocurrency that has been around since 2009 by a shadowy figure (until recently) named Satoshi Nakamoto. Often the preferred payment method for buying drugs and other illegal services, Bitcoin is now accepted by over 3,000 legitimate merchants. Every transaction is recorded on a blockchain, a publicly viewable global ledger, but the names of the participants are not stored. People send and receive the virtual currencies through online purchases, or “transactions.” Until recently, Mt. Gox was the largest Bitcoin exchange.
Thieves steal Bitcoins and other forms of cryptocurrencies with wallet-stealing malware, credential-stealing malware, and man-in-the-browser attacks, Stewart and Litke said.
“While it takes a lot of effort to launder money from credit cards and bank accounts, it doesn’t take any effort to launder Bitcoins,” Stewart said. It’s much easier to cash out stolen wallets than it is to move money from compromised bank accounts.
When Malware Attacks
Since Bitcoins are stored in a digital wallet, which can exist either in the cloud or on a user’s computer, the most common and effective types of malware are wallet-stealers. This type of malware looks for the “wallet.dat” file or other common file names commonly used on the user’s computer and then transfers them to a remote server. The thieves then extract the user’s key from the wallet and transfer the funds to a different wallet that they own.
Exchanges are also notoriously easy to crack with credential-stealing malware that tracks and records login credentials as the user attempts to log in to the exchange. Even if the website has two-factor authentication, Stewart and Litke said that more advanced forms of the malware can intercept the One-Time-Passowrd as it is being used, securitywatch.pcmag.com reports.
With the man-in-the-browser attack, the malware monitors the computer’s clipboard. When the user copies a Bitcoin address to paste it, the malware replaces the string with the thief’s Bitcoin address, Litke said. Since no one can catch wallet identifiers at first glance, most users won’t notice that the address has changed and send the coins to the wrong recipient. Unfortunately, there’s no way to reverse the transaction.
Keeping coins safe
When Mt.Gox, the oldest and perhaps most well-known Bitcoin exchange, declared bankruptcy on February 26, it revealed that thieves had taken about 744,000 Bitcoins, an amount valued at about $475 million.
In case you think you can rely on your antivirus alone to keep malware at bay, Dell SecureWorks experts said the average detection rate for these malware families across all antivirus tools in the market was just 48%. Users will simply need to learn to operate as they would if their system was not clean of malware and continually take extra steps to secure their wallets and accounts.
SecureWorks recommends that users use hardware wallets, on USB sticks or on computers that are not connected to the internet. Transactions this way may be slow, but it is better to have a slow transaction than a transaction that will lead to the theft of your coins.

