HomeSecurityCrypto-stealing OpcJacker malware targets users with fake VPN service

Crypto-stealing OpcJacker malware targets users with fake VPN service

Since the summer of 2022, hackers have launched a malicious malvertising attack with OpcJacker – a sneaky malware that steals personal information.

OpcJacker

Our initial campaign strategy involved a web of fake websites advertising fake cryptocurrency-related software and apps. The February 2023 campaign specifically targeted users in Iran under the guise of offering a VPN service.

See also: Pinduoduo: Chinese app spies on users and competitors

OpcJacker's installation files act as a delivery method for the malicious tool. It is also capable of delivering further payloads such as the NetSupport RAT and a disguised version of virtual network computing (hVNC) to provide attackers with remote access.

OpcJacker is hidden through the use of a cryptographer known as Babadeda and relies on a configuration file to initiate its data-stealing capabilities. It also has the ability to launch arbitrary shellcode and executable files.

Crypto-stealing OpcJacker malware targets users with fake VPN service

See also: Hackers exploit bug in Elementor Pro WordPress plugin

Undoubtedly, this malware is financially motivated due to its ability to steal crypto funds from wallets. However, OpcJacker's reusability also makes it a prime candidate as a malware loader.

According to Securonix, an ongoing cyberattack campaign dubbed TACTICAL#OCTOPUS is underway in the United States. Using malicious tax-, this attack aims to implant backdoors that can give criminals access to systems they have access, as well as obtain confidential data, such as clipboard contents and keystrokes.

In a related development, Italian and French users searching for cracked versions of computer maintenance software, such as EaseUS Partition Master and Driver Easy Pro on YouTube, are being redirected to Blogger pages distributing the NullMixer dropper.

See also: Western Digital: Announces network breach

NullMixer has been identified as the perpetrator of large-scale malware infections due to the development of various ready-made viruses, such as PseudoManuscrypt, Raccoon Stealer, GCleaner, Fabookie, and Crashtech Loader.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS