A fake site that mimics the Pixelmon NFT projectlures users with free tokens and collectibles and infects them with password-stealing malware, with the aim of stealing cryptocurrency wallets.
See also: What are Non-Fungible Tokens (NFTs) that have become the new trend?

Pixelmon is a popular NFT project and has nearly 200,000 followers on Twitter and over 25,000 Discord members.
Some cybercriminals are taking advantage of the public's interest in the Pixelmon NFT project and have created a copy of the legitimate pixelmon.club site and a fake version at pixelmon[.]pw, for the purpose of distributing malware.
The malicious site is almost identical to the regular site, but instead of offering a demo of the project's game, it offers executables that install password-stealing malware on the device victim's The site offers a file called Installer.zip. This file contains an executable that appears to be corrupted and does not infect users with any malware.
See also: Yannis Andreou Live: Everything about Crypto, NFT, Metaverse and DeFi
However, MalwareHunterTeam , which first discovered the malicious website mimicking the Pixelmon NFT project, found other malicious files distributed by the website.

One of the files distributed by the malicious Pixelmon site is setup.zip, which contains the setup.lnk file. Setup.lnk is a Windows that will run a PowerShell command to download a system32.hta file from pixelmon[.]pw.
According to BleepingComputer, the System32.hta file downloads Vidar, a password-stealing malware that is now not as popular as it once was, to the device. This was confirmed by security researcher Fumik0_, who has analyzed the malware in the past.
See also: Instagram: The platform will test NFTs with selected creators
When executed, Vidar will connect to a Telegram channel and retrieve the IP address of the malware. The malware will then retrieve a configuration command from the C2 and download additional modules that will be used to steal data from the infected device.
Vidar malware, distributed by the Pixelmon NFT site, can steal passwords from browsers and applications and search the computer for files matching specific names. This data is then sent to the malware's operators.
According to BleepingComputer, the C2 instructs the password-stealing malware to search for and steal various files, such as text files, cryptocurrency wallets, backups, password files, and authentication files.
Since Pixelmon is an NFT site, it is expected that visitors will have cryptocurrency wallets installed on their computers. Thus, the attackers are focusing on searching for and stealing cryptocurrency.
The fake Pixelmon NFT site is not currently distributing a functional payload, but according to BleepingComputer, threat actors are constantly modifying it.
NFTs have been very popular recently and cybercriminals are taking advantage of this. You should keep in mind that NFT projects are flooded with scams that aim to steal your cryptocurrencies. Therefore, you should always check that the URL you are visiting is correct and that it is actually related to the project you are interested in.
Additionally, never run executables from unknown websites without first scanning them with antivirus software or VirusTotal.
Source: www.bleepingcomputer.com
