A cyber researcher warns of a serious malware on the Bitcoin Blockchain. Yesterday, it was reported in Forbes that the Bitcoin Blockchain has been hijacked by a new strain of the Glupteba malware.
Despite the unique decentralized and anonymous features that encryption – hackers and programmers are finding smarter ways to perform malicious actions.

The Glupteba malware was first discovered in 2011 as part of an advertising campaign, and in 2018 it was again spotted in a malicious campaign using the “Pay-per-Install” scheme, a system that was found to be responsible for adding all infected devices to the botnet controlled by the attacker. However, the latest version of the malware has been found to exploit bitcoin.
Monero seems to be the favorite cryptocurrency of hackers – as the report states, the malware can also mine privacy -focused cryptocurrency like Monero. It also causes problems with a user’s Instagram account and steals sensitive user browser data like passwords and cookies.
Glupteba includes two components, browser and router exploits, with the former component, the malware quickly accesses the browsing history of the “crypto owner” from browsers such as Chrome, Opera and Yandex. And the Glupteba malware strain exploits MicroTik routers that help attackers hide their real IP by configuring the router as a SOCKS proxy.
Specifically, the Glupteba malware uses the Electrum bitcoin wallet, which makes it easy for attackers to track bitcoin. Elaborating on more information about the malware, researchers at Trend Micro, a blog , explain the command and control server. It states that this server is a central computer that processes commands across an infected network of devices, saying more specifically the following:
“This technique (Glupteba malware) makes it more convenient for the hacker to replace command and control servers. If for some reason they lose control of a command and control server, they simply need to add a new bitcoin script and the infected machines get a new command and control server.
