Security firm Intezer Labs said it has uncovered a secret malware campaign. According to researchers, the criminals behind the campaign have created fake cryptocurrency apps to trick users into installing a new malware (ElectroRAT) on their systems. The goal is to steal money.

The campaign was discovered in December.
Intezer Labs said the hackers created three fake cryptocurrency apps, called Jamm, eTrade/Kintum , and DaoPoker , hosted on dedicated websites (jamm[.]to, kintum[.]io, and daopker[.]com, respectively).
The first two apps claim to provide a simple platform for exchanging cryptocurrency, while the third is a cryptocurrency poker app.
All three applications are available in versions for Windows, Mac, and Linux and were created based on Electron, an app-building framework.
However, according to researchers, the three cryptocurrency apps contain a malware, which was named ElectroRAT (by the research team).
“ ElectroRAT is highly intrusive,” the researchers said . “It has various capabilities such as keylogging, taking screenshots, uploading files from disk, downloading files, and executing commands on the victim’s console .”
Intezer believes the malware is used to collect cryptocurrency wallet keys so hackers empty victims' accounts.

The criminals attempted to find victim users by advertising the three fake apps and their sites on specialized cryptocurrency forums and social media.
Based on some evidence it has uncovered, Intezer believes that this malware campaign has infected approximately 6,500 cryptocurrency users.
Cryptocurrency users who have lost money and have not discovered the source of the breach should check if they have downloaded and installed any of the above three apps.
Finally, Intezer Labs pointed out that ElectroRAT is written in Go, a programming language that has become quite popular among malware creators in the last year.
Source: ZDNet
