
Cybersecurity firm ESET has published a report describing a new malware Windows, which the company has named KryptoCibule.
ESET says the malware has been distributed since at least December 2018, but has now come to the attention of researchers.
According to the company, the KryptoCibule Windows malware targets users . The key features of the malware are:
- installation of cryptocurrency miner on victims' systems
- theft of files related to cryptocurrency wallets
- replacing wallet addresses in the operating system clipboard, to compromise cryptocurrency payments
The above features are the result of hard work by hackers, as they have added new elements to the KryptoCibule malware compared to its first version in late 2018.

According to ESET, malware has evolved into a complex threat with many features and capabilities.
Currently, the malware is distributed via torrent files for pirated software. ESET says that users who download these torrents will install the pirated software they wanted, but will also run the KryptoCibule Windows malware installer.
This installer tries to stay on the system and then installs the KryptoCibule malware core (the launcher), the OS clipboard hijacker, and Tor and torrent clients.
ESET says that KryptoCibule uses the Tor client to securely communicate with command-and-control (C&C) servers, hosted on the dark web, while the torrent client is used to load torrent files that will eventually be downloaded by other additional tools, such as proxy servers, crypto-mining tools, and HTTP and SFT servers, all useful for one or more tasks in the KryptoCibule Windows malware's modus operandi.

KryptoCibule is dangerous for cryptocurrency users, as it has been designed by people with knowledge of modern malware operations.
The good news is that for now the distribution of KryptoCibule has been limited to only two countries, the Czech Republic and Slovakia.
ESET researchers say that almost all malicious torrents distributing pirated software with KryptoCibule were only available on uloz.to, a popular file-sharing website in the two countries.
This limited distribution appears to be something that was planned from the beginning, as the KryptoCibule Windows malware contains a feature that checks for the presence of antivirus software on the victim's computer. This malware appears to only check for the presence of ESET, Avast, and AVG. All three security are based in either the Czech Republic or Slovakia and are likely present on the computers of most targeted users.
However, the malware is targeting a specific region right now, but that may change.
Users need to remain vigilant and the simplest way to avoid a threat like KryptoCibule Windows malware is to avoid installing pirated software. Most torrent files for pirated software are often bundled with malware.
