HomeSecurityFake Atomic Wallet website pushes Mars Stealer malware

Fake Atomic Wallet website pushes Mars Stealer malware

A fake website impersonating the official portal for Atomic wallet, a popular decentralized wallet that also functions as a cryptocurrency exchange portal, is actually distributing copies of the information-stealing malware Mars Stealer.

Atomic Wallet

The fake website was uncovered by a malware researcher known as Dee on Monday.

See also: SSU: Removes huge farm with 1 million disinformation bots

Looking at the two websites side by side, he discovered that the second one is not a carbon copy of the first one, but still uses the official logos, themes, marketing images, and structure. The fake website even has a contact form, email , and FAQ section.

However, those unfamiliar with the legitimate Atomic wallet website could easily believe that the fake is the authentic one.

See also: Woody RAT: Malware attacks Russian organizations

Fake Atomic Wallet website pushes Mars Stealer malware

As for how people end up there, it could be due to malicious advertising on social media, direct messages on various platforms, SEO poisoning, or spam emails.

Visitors attempting to download the software see three buttons for Windows, iOS , and Android.

Fake Atomic Wallet website pushes Mars Stealer malware

Clicking on iOS does nothing, and clicking on the Google Play redirects to the actual Atomic Wallet app on the Play Store.

However, clicking the Windows button will download a ZIP file named “Atomic Wallet.zip”, which contains malicious code that installs the Mars Stealer infection.

Mars Stealer is a recently emerged info-stealer program that targets account credentials stored in web browsers, cryptocurrency extensions, and wallets.

In March, we reported that Mars Stealer is distributed by malicious Google Ads campaigns that misuse the OpenOffice brand.

Avoiding detection

According to a technical report published yesterday by Cyble, the delivery mechanism in the ongoing Mars Stealer campaign features a notable effort to avoid detection.

The ZIP contains a batch file (AtomicWallet-Setup.bat) that calls a PowerShell command to elevate privileges on the host.

The bat file then copies the PowerShell executable (powershell.exe) to the directory, renames and hides it , and finally uses it to execute a base64-encoded PowerShell content.

Fake Atomic Wallet website pushes Mars Stealer malware

This code decrypts an AES-encoded and GZip-compressed Base64 code, which executes the final PowerShell code that acts as a malware loader.

Atomic Wallet

The loader downloads a copy of Mars Stealer from a Discord server and drops it into %LOCALAPPDATA% on the host machine. After installation, the malware launches and begins stealing data from the now-infected device.

Fake Atomic Wallet website pushes Mars Stealer malware

How to stay safe

When downloading cryptocurrency wallets, it is vital to make sure you use the project's and never trust links provided on social media or instant messaging platforms.

See also: Windows 11 Smart App Control: Blocks files that promote malware

Also, beware of SEO poisoning and malicious Google Ads campaigns that can cause malicious websites to rank higher than official websites in Google Search results, so skip all results marked as ads .

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS