HomeSecurityCrypto theft campaign has infected 28,000 people

Crypto theft campaign has infected 28,000 people

Over 28,000 people from Russia, Turkey, Ukraine and other countries in the Eurasian region were targeted in a crypto theft.

crypto theft

The malware is disguised as legitimate software and is promoted via YouTube videos and fraudulent GitHub repositories. Victims are asked to download password-protected files, which are what ultimately cause the infection.

According to cybersecurity firm Dr. Web, the theft uses pirated office-related software, game cheats, hacks , and automated trading bots to trick users into downloading the malicious files.

Researchers said more than 28,000 people have been affected. Most are residents of Russia. Significant numbers of infections have also been observed in Belarus, Uzbekistan, Kazakhstan, Ukraine, Kyrgyzstan and Turkey.

See also: Lego: Its site was hacked to promote crypto scam

How does infection occur?

The infection begins by opening a self-extracting archive that evades antivirus scans as it is password-protected. After the victim enters the provided password ,the archive installs various obfuscated scripts, DLL files, and an AutoIT interpreter, which is used to launch the loader of the main malicious payload (which deals with crypto theft).

The malware checks for debug tools to see if it is running in an analyst environment. If it finds one, it terminates itself. It then extracts files required for the next stages of the attack and uses the Image File Execution Options (IFEO) technique to modify the Windows Registry and ensure persistence.

In essence, the malware involves legitimate Windows system services as well as the Chrome and Edge update processes with malicious actions so that malware files are executed when these processes are launched.

Researchers observed that the Windows Recovery Service is disabled and the “delete” and “modify” permissions on the malware’s files and folders are revoked to prevent cleanup attempts.

See also: Man confesses to stealing $37 million worth of crypto

From there, the Ncat network utility is used to establish communication with the command and control (C2) server.

Malware can also collect system information.

Crypto theft campaign has infected 28,000 people

Impacts

Ultimately, two main payloads are delivered to victims' machines. The first is “Deviceld.dll”, a modified .NET library used to execute SilentCryptoMiner, which mines crypto using the victim's computing resources.

The second payload is “7zxa.dll”, a modified 7-Zip library that acts as a clipper, monitoring the Windows clipboard for copied wallet addresses. The malware replaces the addresses with others under the attacker’s control.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Crypto protection

To avoid having your crypto stolen, download legitimate software only from a project's official website and block or skip sponsored results in Google Search.

Additionally, be careful with shared links on YouTube or GitHub and other platforms (social media etc) as cybercriminals exploit them to trick users.

See also: Linux malware “perfctl” used for cryptomining

Stay up-to-date on new types of scams and stay vigilant when engaging in crypto-related activities. Phishing attacks via email, fake websites, and social media are common methods used by scammers. Always check the URL of websites and never click on suspicious links or download attachments from unknown sources.

In general, protecting crypto requires taking preventative measures, such as using secure wallets, enabling authentication , keeping software updated, not disclosing personal information, and being vigilant against scams.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS