HomeSecurityTsunami malware features Miners and Credential Stealers

Tsunami malware features Miners and Credential Stealers

A sophisticated malware called “Tsunami” has emerged as an active threat, targeting users through a complex infection chain and leveraging a wide range of capabilities for credential theft and cryptocurrency mining.

See also: New DslogdRAT malware is distributed via vulnerability in Ivanti Connect Secure

Tsunami malware

Security researchers have linked this malware to the ongoing “Contagious Interview” campaign, which is associated with North Korean threat actors, specifically the Lazarus Group. The campaign, which was first observed in the fall of 2024, is primarily focused on stealing cryptocurrency in software development environments. The attack begins with initial access via chaining a malicious BeaverTail from an external domain, “api.npoint.io,” via a compromised private GitHub.

Once executed, the loader activates the previously documented InvisibleFerret malware as an intermediate stage in the infection chain. This sophisticated social engineering approach targets victims via LinkedIn, where attackers pose as potential business partners in order to trick victims into executing code with an embedded backdoor .

HiSolutions researchers discovered the Tsunami malware during an investigation into cryptocurrency theft incidents. Their analysis revealed that the malware relies on both the TOR network and Pastebin for command and control (C2) functions, demonstrating cybercriminals’ efforts to maintain operational security while developing new tools.

See also: Lotus Panda hackers targeted Asian organizations with malware

Tsunami malware features Miners and Credential Stealers

The Tsunami malware uses a modular structure with over 25 different components, including various tools to steal credentials from browsers such as Chrome, Firefox, Brave, Edge , and OperaGX. In addition, it incorporates capabilities to compromise cryptocurrency wallets, primarily targeting Exodus and Ethereum wallets.

Two separate cryptocurrency mining programs — one for Monero and one for Ethereum — are installed on compromised systems for the purpose of financial exploitation, according to configuration files recovered during the analysis.

According to the research, the development of the malware appears to be ongoing, with some modules, such as the botnet function, still in the early stages of implementation, suggesting that attackers are continuing to enhance their capabilities.

See also: New XorDDoS malware allows creation of DDoS botnets

Based on the above, it is clear that the Tsunami malware is a highly targeted and evolving cyberattack tool, with the main goal of financial exploitation through cryptocurrency theft and software development system compromise. The use of social engineering techniques, such as through LinkedIn, shows how targeted these attacks are, while the use of the TOR network and services such as Pastebin highlights the perpetrators' effort to cover their tracks.

Source: cybersecuritynews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS