Thousands of cryptocurrencycryptocurrency users have reportedly been the victim of cryptocrypto apps that were advertised as legitimate, but secretly contained malware that infiltrated users’ computers and stole information, including cryptocurrency walletwallet keys.
Security firm Intezer Labs discovered and extensively detailed the exploit, which it has dubbed ElectroRAT, in a report issued today. The malware was first discovered in December, although data from a pastebin used by the exploit suggests that it has been in the wild since at least January 8, 2020.
[1/7] Operation #ElectroRAT is a new campaign that takes sizable measures to steal crypto wallets. For more information about the operation - https://t.co/CWLnOevKir
The following is a technical analysis->@IntezerLabs
The sophisticated campaign involved a trio of cryptocurrency apps developed for Windows, macOS, and Linux called Jamm, eTrade (or Kintum), and DaoPoker. Intezer describes the exploit as “extremely intrusive,” capable of keylogging, downloading and executing files, uploading files, and taking screenshots without a user’s knowledge.
In its report, Intezer shows how the software applications were promoted and distributed via cryptocurrency forums and Twitter. All told, based on the number of unique users to the exploit’s pastebin, the firm believes that at least 6,500 users were impacted by the malware.
The fake software was created using app-building platform Electron and coded from scratch in the Go language, rather than using pre-built, off-the-shelf malware code. According to Intezer Labs, using Go likely made it easier for the creators to rapidly develop versions for multiple platforms, while ZDNet notes that the complexity of the language makes analyzing and detecting malware more difficult.
The Electrum malware scam has struck again. Today, 2 Bitcoin (32,876) was sent to a known scam address.
Malware refers to a collective of malicious software that includes ransomware and spyware. It is typically designed to cause extensive damage to infected computers or to gain access to private networks. Now, an address using a known Electrum wallet exploit has claimed another victim.
“A payment of 2.042 #BTC (32,876 USD) was just made to a confirmed Malware scam!” tweeted Whale Alert.
🚔 A...
“Writing the malware from scratch has also allowed the campaign to fly under the radar for almost a year by evading all antivirus detections,” Intezer Labs writes.
If you have used any of the fraudulent apps mentioned above, Intezer has a breakdown of how to detect the processes and clear your system using its software. The firm also suggests moving crypto assets to a different wallet and changing all of your passwords.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Crypto's best minds are heading east, and it's gaining at a pace that other regions are finding hard to catch up to.
Asia was responsible for 32% of global crypto developer activity in 2024, according to a report from venture firm Electric Capital. The firm recently published its comprehensive annual report, analyzing over 900 million code commits across the crypto industry.
The transformation represents a nearly threefold increase from Asia's 12% share in 2015, while North America's position de...
Google's announcement of its breakthrough Willow quantum processor has reignited debates about crypto security, with some observers suggesting quantum computers could break Bitcoin's encryption.
The tech giant claims its new quantum computing chip can complete certain calculations in five minutes, which would take traditional supercomputers an impractical amount of time to process.
Quantum computing is a new type of computing that uses the strange properties of quantum physics, where small part...
Dimo, a platform for developers to build apps and enable car drivers to monetize their data, is migrating between Ethereum scaling networks, the developers exclusively told Decrypt—from Polygon to Coinbase’s Base. Co-founder Rob Solomon believes the move opens doors for valuable partnerships ahead.
The project is a “global API layer for cars” that is aiming to make every car on earth smart and programmable. This could manifest, the company says, in a future full of AI car mechanics and smart par...