• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Tuesday, September 26, 2023
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

This Elusive Malware Has Targeted Crypto Wallets for a Year

6 January 2021
in Blockchain
Reading Time: 8 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT


Operating for a year now, insidious malware ElectroRAT is bringing 2020 into 2021 and targeting crypto wallets.

A researcher at cybersecurity firm Intezer has identified and documented the inner workings of ElectroRAT, which has been targeting and draining victims’ funds.

According to the researcher, Avigayil Mechtinger, the malware operation includes a variety of detailed tools that dupes victims, including a “marketing campaign, custom cryptocurrency-related applications and a new Remote Access Tool (RAT) written from scratch.”

The malware is called ElectroRAT because it’s a remote access tool that was embedded in apps built on Electron, an app-building platform. Hence, ElectroRAT. 

“It’s unsurprising to see novel malware being published, especially during a bull market in which the value of cryptocurrency is shooting up and making such attacks more profitable,” said Jameson Lopp, chief technology officer (CTO) at crypto custody startup Casa. 

Over the past few months, bitcoin and other cryptocurrencies have entered a bull market, seeing prices skyrocket across the industry.

What is ElectroRAT?

ElectroRat malware is written in the open-source programming language Golang, which is good for cross-platform functionality and is targeted at multiple operating systems, including macOS, Linux, and Windows. 

As part of the malware operation, the attackers set up “domain registrations, websites, trojanized applications and fake social media accounts,” according to the report. 

In the report, Mechtinger notes that while attackers commonly try to collect private keys used to access people’s wallets, seeing original tools like ElectroRAT and the various apps written “from scratch” and targeting multiple operating systems is quite rare. 

A visual summary of the scope of ElectroRAT
(Intezer)

“Writing the malware from scratch has also allowed the campaign to fly under the radar for almost a year by evading all antivirus detections,” wrote Mechtinger in the report. 

Lopp echoed these comments, and said it’s particularly interesting the malware is being compiled for and targeting all three major operating systems. 

“The value majority of malware tends to be Windows-only due to the wide install base and the weaker security of the operating system,” said Lopp. “In the case of bitcoin, malware authors may reason that a lot of early adopters are more technical people who run Linux.”

How it works

To lure in victims, the ElectroRat attackers created three different domains and apps operating on multiple operating systems.

The pages to download the apps were created specifically for this operation and designed to look like legitimate entities. 

The associated apps specifically appeal to and target cryptocurrency users. “Jamm” and “eTrade” are trade management apps; “DaoPoker” is a poker app that uses cryptocurrency. 

Using fake social media and user profiles, as well as paying a social media influencer for their advertising, the attacker pumped the apps, including promoting them in targeted cryptocurrency and blockchain forums like bitcointalk and SteemCoinPan. The posts encouraged readers to look at the professional-looking websites and download the apps when, in reality, they were also downloading the malware. 

The front end of the eTrade app
(Intezer)

For example, the DaoPoker Twitter page had 417 followers while a social media advertiser with over 25,000 followers on Twitter promoted eTrade. As of writing, the DaoPoker twitter page is still live. 

While the apps look legitimate at first glance on the front end, they are running nefarious background activities, targeting users’ cryptocurrency wallets. They are also still active. 

“Hackers want to get your cryptocurrency, and they are willing to go far with it – spend months of work to create fake companies, fake reputation and innocent-looking applications that hide malware to steal your coins,” said Mechtinger. 

What it does

“ElectroRAT has various capabilities,” said Mechtinger in an email. “It can take screenshots, key logs, upload folders/files from a victim’s machine and more. Upon execution, it establishes commands with its command-and control-server and waits for commands.” 

The report suggests the malware specifically targets cryptocurrency users for the purpose of attacking their crypto wallets, noting that victims were observed commenting on posts related to the popular Ethereum wallet app Metamask. Based on the researchers’ observations of the malware’s behaviors, it’s possible more than 6.5 thousand people had been compromised. 

How to avoid it

The first step is the best step and that’s not to download any of these apps, full stop. 

In general, when you’re looking into new apps, Lopp suggests avoiding shady websites and forums. Only install software that is well-known and properly reviewed; look for apps with lengthy reputation histories and sizable install bases. 

“Don’t use wallets that store the private keys on your laptop/desktop; private keys should be stored on dedicated hardware devices,” said Lopp. 

This point reinforces the importance of storing your crypto in cold hardware wallets and writing down seed phrases rather than just storing them on your computer. Both of these techniques make them inaccessible to malware that trolls your online activity. 

A victim commenting on the malicious activity of one of the ElectroRAT apps
(Intezer)

There are secondary steps that can be taken if you think your computer might have already been compromised. 

“To make sure you are not infected we recommend [you] take proactive action and scan your devices for malicious activity,” said Mechtinger.

In the report, Mechtinger suggests that if you think you’re a victim of this scam, you need to kill the processes running and delete all files related to the malware. You also need to make sure your machine is clean and running non-malicious code. Intezer has created Endpoint Scanner for Windows environments and Intezer Protect, a free community tool for Linux users. More detailed information about detection can be found in the original report. 

And, of course, you should move your funds to a new crypto wallet and change all your passwords. 

A higher bitcoin price attracts more malware

With the price of bitcoin continuing to rise, Mechtinger doesn’t see attacks like this slowing down. In fact, they’re likely to increase. 

“There are high capitals at stake, which is classic for financially motivated hackers,” she said. 

Lopp said we will see attackers devote greater and greater resources to coming up with new ways to part people from their private keys. 

“While a novel attack takes much greater effort to develop, the rewards are also potentially higher because it’s more likely to fool people because the knowledge of that style of attack has not been disseminated through the user base,” he said.  “That is, people are more likely to expose themselves to the attack unknowingly.”





Source link

Related articles

Arbitrum Users Can Now Trade Bitcoin Mining Power With Each Other

Arbitrum Users Can Now Trade Bitcoin Mining Power With Each Other

26 September 2023
Coinbase (COIN) Registers With Central Bank of Spain

Coinbase (COIN) Registers With Central Bank of Spain

26 September 2023
Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: cryptoElusiveMalwareTargetedwalletsYear
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Coinbase Is Down, Experiencing ‘Connectivity Issues’

Next Post

Price analysis 1/6: BTC, ETH, XRP, LTC, ADA, DOT, BCH, XLM, LINK, BNB – Cointelegraph

Related Posts

Arbitrum Users Can Now Trade Bitcoin Mining Power With Each Other

Arbitrum Users Can Now Trade Bitcoin Mining Power With Each Other

26 September 2023
0

The Lumerin Hashpower Marketplace allows Bitcoin miners to easily buy and sell capacity to interested peers and non-miners, allowing purchasers...

Coinbase (COIN) Registers With Central Bank of Spain

Coinbase (COIN) Registers With Central Bank of Spain

26 September 2023
0

The global economy may not be ready to face the worst-case scenario of the U.S. interest rate rising as high...

Inside the Prison Digs for FTX Founder SBF

Inside the Prison Digs for FTX Founder SBF

26 September 2023
0

MDC Brooklyn is a large prison complex encompassing two buildings and housing more than 1,600 male and female prisoners, many...

Crypto Fund Management Opportunity Could Be Worth as Much as $50B, Bernstein Says

Crypto Fund Management Opportunity Could Be Worth as Much as $50B, Bernstein Says

26 September 2023
0

The crypto industry is expected to transition from a "cottage industry" with $50 billion of managed assets to a "formal,...

Celsius Creditors Approve Reorganization Plan, Which May Return Up to 85% Funds

Celsius Creditors Approve Reorganization Plan, Which May Return Up to 85% Funds

26 September 2023
0

The overwhelming vote marks another step towards the end of Celsius' bankruptcy and the return of funds to customers. Celsius...

Load More
Next Post

Price analysis 1/6: BTC, ETH, XRP, LTC, ADA, DOT, BCH, XLM, LINK, BNB - Cointelegraph

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Can the Bitcoin Price Pump to $30,000 This Week? Traders Eye New Crypto Presale Bitcoin Minetrix With Stake to Mine Utility Instead
  • New owners plan a complete makeover of Marriott hotel in Westlake
  • NFT Brand Pudgy Penguins Debuts Toy Collection in 2,000 Walmart Stores

Newsletter

  • About Us
  • Privacy Policy
  • Contact Us

© 2022 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$26,122.00-0.40%
  • ethereumEthereum(ETH)$1,583.43-0.03%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$210.960.94%
  • rippleXRP(XRP)$0.500.38%
  • usd-coinUSDC(USDC)$1.000.10%
  • staked-etherLido Staked Ether(STETH)$1,581.29-0.28%
  • cardanoCardano(ADA)$0.244916-0.04%
  • dogecoinDogecoin(DOGE)$0.060515-0.85%
  • solanaSolana(SOL)$19.17-1.96%
  • tronTRON(TRX)$0.0845290.27%
  • ToncoinToncoin(TON)$2.16-0.46%
  • Wrapped stETHWrapped stETH(WSTETH)$1,864.880.36%
  • polkadotPolkadot(DOT)$4.01-1.38%
  • matic-networkPolygon(MATIC)$0.520.03%
  • litecoinLitecoin(LTC)$63.92-1.16%
  • shiba-inuShiba Inu(SHIB)$0.000007-0.46%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$26,104.00-0.56%
  • bitcoin-cashBitcoin Cash(BCH)$212.970.47%
  • chainlinkChainlink(LINK)$7.33-0.75%
  • daiDai(DAI)$1.00-0.03%
  • true-usdTrueUSD(TUSD)$1.00-0.07%
  • leo-tokenLEO Token(LEO)$3.64-3.37%
  • uniswapUniswap(UNI)$4.23-0.70%
  • avalanche-2Avalanche(AVAX)$8.920.75%
  • stellarStellar(XLM)$0.111126-0.53%
  • moneroMonero(XMR)$143.67-0.52%
  • okbOKB(OKB)$43.070.56%
  • binance-usdBUSD(BUSD)$1.00-0.01%
  • ethereum-classicEthereum Classic(ETC)$15.11-1.02%
  • cosmosCosmos Hub(ATOM)$6.97-0.76%
  • hedera-hashgraphHedera(HBAR)$0.049602-1.90%
  • GGTKNGGTKN(GGTKN)$0.1121180.75%
  • filecoinFilecoin(FIL)$3.18-1.43%
  • crypto-com-chainCronos(CRO)$0.049945-0.68%
  • internet-computerInternet Computer(ICP)$2.93-2.15%
  • lido-daoLido DAO(LDO)$1.45-1.26%
  • AptosAptos(APT)$5.39-2.00%
  • MantleMantle(MNT)$0.389468-0.71%
  • quant-networkQuant(QNT)$85.86-3.17%
  • vechainVeChain(VET)$0.016609-0.23%
  • makerMaker(MKR)$1,337.143.93%
  • ArbitrumArbitrum(ARB)$0.810.41%
  • nearNEAR Protocol(NEAR)$1.09-2.10%
  • optimismOptimism(OP)$1.271.54%
  • EdgecoinEdgecoin(EDGT)$1.00-0.03%
  • KaspaKaspa(KAS)$0.046259-1.21%
  • Rocket Pool ETHRocket Pool ETH(RETH)$1,717.67-0.07%
  • BSCEXBSCEX(BSCX)$237.190.34%
  • aaveAave(AAVE)$60.83-2.67%