Hackers are “throwing” NFTs at Solana cryptocurrency owners pretending to be notifications for a new Phantom security update that leads to the installation of password-stealing malware and the theft of cryptocurrency wallets.

This ongoing attack began two weeks ago, with NFTs titled “PHANTOMUPDATE.COM” or “UPDATEPHANTOM.COM” being sent as warnings by Phantom’s developers.
Upon opening the NFTs, wallet holders are notified that a new security update has been released and that they should click on the enclosed link or visit the website to download and install.
See also: Intel: The source code for the BIOS of Alder Lake CPUs has been leaked and is authentic
“Phantom requires all users to update their wallets. This should be done as soon as possible,” the warning on the fake Phantom NFT update reads.
“Failure to do so may result in loss of funds due to hackers exploiting the Solana network. Visit www.updatePhantom.com to get the latest security update.”

When you visit these websites from any device (desktop or mobile), the website automatically downloads a Windows batch file named Phantom_Update_2022-10-08.bat [VirusTotal] from DropBox. Previous campaigns downloaded executables named Phantom_Update_2022-10-04.exe.
See also: Callback phishing: Social engineering methods are evolving
When the batch file is launched, it will check if it is running with administrator privileges and, if not, it will display a Windows UAC prompt asking for permissions.

If the UAC prompt is accepted, a PowerShell script will be launched that decrypts further commands to run on Windows.

Ultimately, this will result in downloading an executable windll32.exe [VirusTotal] from GitHub and running it from the C:\Users\ folder.<username> \AppData\Local.

According to VirusTotal, the windll32.exe file is a password-stealing malware that attempts to steal browser information, such as history, cookies, and passwords, as well as SSH keys and other information.
See also: BidenCash: Offers 1,221,551 stolen credit cards for free
While it is unclear which password-stealing trojan is currently spreading, previous campaigns distributed a file name lib64.exe [VirusTotal], which was identified as MarsStealer.

MarsStealer is an information-stealing malware released in 2020 that steals data from all popular web browsers, two-factor authentication plugins, and multiple extensions and cryptocurrency wallets.
The goal of this campaign is to steal cryptocurrency wallets and passwords that would allow the threat actors to steal all crypto funds and compromise other accounts belonging to the victim.
Victims who installed the fake Phantom security update should immediately scan their computer with an antivirus program and then transfer crypto funds and assets from their existing Phantom wallet to a new one.
Victims should then change their passwords on all websites they use, focusing on cryptocurrency trading platforms, online wallets, bank accounts, email , or other sensitive platforms.
Ultimately, victims should change their password to a unique one for each website they visit to prevent credential leakage on one website from affecting other websites.
Information source: bleepingcomputer.com
