HomeSecuritySolana: NFTs impersonating the Phantom security update are spreading malware

Solana: NFTs impersonating the Phantom security update are spreading malware

Hackers are “throwing” NFTs at Solana cryptocurrency owners pretending to be notifications for a new Phantom security update that leads to the installation of password-stealing malware and the theft of cryptocurrency wallets.

Phantom

This ongoing attack began two weeks ago, with NFTs titled “PHANTOMUPDATE.COM” or “UPDATEPHANTOM.COM” being sent as warnings by Phantom’s developers.

Upon opening the NFTs, wallet holders are notified that a new security update has been released and that they should click on the enclosed link or visit the website to download and install.

See also: Intel: The source code for the BIOS of Alder Lake CPUs has been leaked and is authentic

“Phantom requires all users to update their wallets. This should be done as soon as possible,” the warning on the fake Phantom NFT update reads.

“Failure to do so may result in loss of funds due to hackers exploiting the Solana network. Visit www.updatePhantom.com to get the latest security update.”

Solana: NFTs impersonating the Phantom security update are spreading malware

When you visit these websites from any device (desktop or mobile), the website automatically downloads a Windows batch file named Phantom_Update_2022-10-08.bat [VirusTotal] from DropBox. Previous campaigns downloaded executables named Phantom_Update_2022-10-04.exe.

See also: Callback phishing: Social engineering methods are evolving

When the batch file is launched, it will check if it is running with administrator privileges and, if not, it will display a Windows UAC prompt asking for permissions.

Phantom

If the UAC prompt is accepted, a PowerShell script will be launched that decrypts further commands to run on Windows.

Solana: NFTs impersonating the Phantom security update are spreading malware

Ultimately, this will result in downloading an executable windll32.exe [VirusTotal] from GitHub and running it from the C:\Users\ folder.<username> \AppData\Local.

Phantom

According to VirusTotal, the windll32.exe file is a password-stealing malware that attempts to steal browser information, such as history, cookies, and passwords, as well as SSH keys and other information.

See also: BidenCash: Offers 1,221,551 stolen credit cards for free

While it is unclear which password-stealing trojan is currently spreading, previous campaigns distributed a file name lib64.exe [VirusTotal], which was identified as MarsStealer.

Phantom
Solana: NFTs impersonating the Phantom security update are spreading malware

MarsStealer is an information-stealing malware released in 2020 that steals data from all popular web browsers, two-factor authentication plugins, and multiple extensions and cryptocurrency wallets.

The goal of this campaign is to steal cryptocurrency wallets and passwords that would allow the threat actors to steal all crypto funds and compromise other accounts belonging to the victim.

Victims who installed the fake Phantom security update should immediately scan their computer with an antivirus program and then transfer crypto funds and assets from their existing Phantom wallet to a new one.

Victims should then change their passwords on all websites they use, focusing on cryptocurrency trading platforms, online wallets, bank accounts, email , or other sensitive platforms.

Ultimately, victims should change their password to a unique one for each website they visit to prevent credential leakage on one website from affecting other websites.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS