HomeSecurityPhorpiex botnet: New Twizt variant makes it easier to steal cryptocurrencies

Phorpiex botnet: New Twizt variant makes it easier to steal cryptocurrencies

Check Point Research has discovered new attacks targeting cryptocurrency owners in Ethiopia, Nigeria, India, and 93 other countries. The cybercriminals behind the attacks are using a variant of the Phorpiex botnet, which the researchers have dubbed “Twizt.” The goal is to steal cryptocurrencies through a process called “crypto clipping.”

Phorpiex Twizt botnet

The botnet first appeared in 2016 and quickly amassed a huge “army of devices” (over 1 million during those years).

The malware generates revenue for its developers by exchanging cryptocurrency addresses copied to the Windows clipboard with addresses under the attackers' control. In other cases, criminals send sextortion emails to scare people into paying money.

See also: Dark Mirai botnet targets popular TP-Link router with RCE

However, after more than five years of development, the operators of the Phorpiex botnet shut down their infrastructure and attempted to sell the source code on a hacking forum.

Check Point researchers saw the infrastructure reactivated in September, about two weeks after the source code was posted for sale.

This time, however, the command and control servers distributed a new variant of the Phorpiex botnet, Twizt, which includes some new tricks to make it more difficult to find the operators or take down the infrastructure.

Phorpiex botnet: Introducing the “Twizt” variant

When Phorpiex resurfaced in September, Check Point saw it distributing the new “Twizt” variant, which allows the botnet to operate without centralized command and control servers.

Instead, the new Twizt Phorpiex variant has added a peer-to-peer command and control system that allows various infected devices to relay commands to each other, even if the static command and control servers are offline.

“This means that each of the infected computers can act as a server and send commands to other bots in a chain,” the company said.

This new P2P infrastructure also allows operators to change the IP address of the main C2 servers.

See also: 300,000 MikroTik devices still vulnerable to botnets

According to Check Point, new features of the Twizt Phorpiex variant include:

  • A peer-to-peer operation mode (not C2).
  • A data integrity verification system.
  • A custom binary protocol (TCP or UDP) with two levels of RC4 encryption.

Twizt Phorpiex can also download additional payloads via a list of hard-coded base URLs and paths.

Phorpiex Twizt botnet

From sextortion to crypto-clipping

Phorpiex was previously known for distributing sextortion spam emails, which allowed threat actors to send over 30,000 sextortion emails per hour.

The botnet operators were making around $100,000 a month by tricking people into sending them cryptocurrencies.

As we mentioned above, however, the Phorpiex botnet now uses crypto-clipping, or a clipboard hijacker, which replaces cryptocurrency wallet addresses copied to the Windows clipboard with ones controlled by the threat actors. So, when the victim attempts to send cryptocurrency to another address, it sends it to the criminals.

Due to the botnet's ability to operate without a C2 or any centralized management, the infected machines will continue to direct transactions to the wrong wallets, even if the botnet operators are caught and the infrastructure is taken down.

See also: Moobot botnet spreads via vulnerability in Hikvision cameras

Check Point researchers saw that Bitcoin wallets, Ethereum, Dogecoin, Dash, Monero and Zilliqa were affected.

Regarding the wallets supported by the latest Phorpiex clipper version, these are:

LISK, POLKADOT, BITCOIN, WAVES, DASH, DOGECOIN, ETHEREUM, LITECOIN, RIPPLE, BITTORRENT, ZCASH, TEZOS, ICON, QTUM, RAVENCOIN, NEM, NEO, SMARTCASH, ZILLIQA, BITTORRENT, ZCASH, TEZOS, CARDANO, GROESTLCOIN, STELLAR, BITCOIN GOLD, BAND PROTOCOL, PERFECT MONEY USD, PERFECT MONEY EURO, PERFECT MONEY BTC.

cryptocurrency

How to protect yourself?

To protect yourself from threats like the Phorpiex botnet and the new Twizt variant, Check Point offers the following advice:

  • When transacting with cryptocurrencies, make sure that the wallet address is indeed the correct one.
  • Make a small test transaction before sending a large amount to avoid losing a lot of money.
  • Update your operating systems and installed applications to fix vulnerabilities.
  • Be careful not to click on ads when searching for cryptocurrency wallets and tools, as these ads usually lead to scams.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS