• About Us
  • Privacy Policy
  • Contact Us
CryptoInfonet
  • News
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Regulation
No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Regulation
No Result
View All Result
CryptoInfonet
No Result
View All Result
Home Blockchain

This Elusive Malware Has Targeted Crypto Wallets for a Year

January 7, 2021
in Blockchain
0
This Elusive Malware Has Targeted Crypto Wallets for a Year
Discover This New Unique Trading Pattern This Powerful Tool Spots Over And Over Again With Precision Accuracy. You Could Double Or Triple Your Account This Year With These Signals!
Click here
to sign up


Operating for a year now, insidious malware ElectroRAT is bringing 2020 into 2021 and targeting crypto wallets.

A researcher at cybersecurity firm Intezer has identified and documented the inner workings of ElectroRAT, which has been targeting and draining victims’ funds.

According to the researcher, Avigayil Mechtinger, the malware operation includes a variety of detailed tools that dupes victims, including a “marketing campaign, custom cryptocurrency-related applications and a new Remote Access Tool (RAT) written from scratch.”

The malware is called ElectroRAT because it’s a remote access tool that was embedded in apps built on Electron, an app-building platform. Hence, ElectroRAT.

“It’s unsurprising to see novel malware being published, especially during a bull market in which the value of cryptocurrency is shooting up and making such attacks more profitable,” said Jameson Lopp, chief technology officer (CTO) at crypto custody startup Casa.

Over the past few months, bitcoin and other cryptocurrencies have entered a bull market, seeing prices skyrocket across the industry.

What is ElectroRAT?

ElectroRat malware is written in the open-source programming language Golang, which is good for cross-platform functionality and is targeted at multiple operating systems, including macOS, Linux, and Windows.

As part of the malware operation, the attackers set up “domain registrations, websites, trojanized applications and fake social media accounts,” according to the report.

In the report, Mechtinger notes that while attackers commonly try to collect private keys used to access people’s wallets, seeing original tools like ElectroRAT and the various apps written “from scratch” and targeting multiple operating systems is quite rare.

A visual summary of the scope of ElectroRAT
(Intezer)

“Writing the malware from scratch has also allowed the campaign to fly under the radar for almost a year by evading all antivirus detections,” wrote Mechtinger in the report.

Lopp echoed these comments, and said it’s particularly interesting the malware is being compiled for and targeting all three major operating systems.

“The value majority of malware tends to be Windows-only due to the wide install base and the weaker security of the operating system,” said Lopp. “In the case of bitcoin, malware authors may reason that a lot of early adopters are more technical people who run Linux.”

How it works

To lure in victims, the ElectroRat attackers created three different domains and apps operating on multiple operating systems.

The pages to download the apps were created specifically for this operation and designed to look like legitimate entities.

The associated apps specifically appeal to and target cryptocurrency users. “Jamm” and “eTrade” are trade management apps; “DaoPoker” is a poker app that uses cryptocurrency.

Using fake social media and user profiles, as well as paying a social media influencer for their advertising, the attacker pumped the apps, including promoting them in targeted cryptocurrency and blockchain forums like bitcointalk and SteemCoinPan. The posts encouraged readers to look at the professional-looking websites and download the apps when, in reality, they were also downloading the malware.

Screen Shot 2021 01 06 at 9.24.06 AM

The front end of the eTrade app
(Intezer)

For example, the DaoPoker Twitter page had 417 followers while a social media advertiser with over 25,000 followers on Twitter promoted eTrade. As of writing, the DaoPoker twitter page is still live.

While the apps look legitimate at first glance on the front end, they are running nefarious background activities, targeting users’ cryptocurrency wallets. They are also still active.

“Hackers want to get your cryptocurrency, and they are willing to go far with it – spend months of work to create fake companies, fake reputation and innocent-looking applications that hide malware to steal your coins,” said Mechtinger.

What it does

“ElectroRAT has various capabilities,” said Mechtinger in an email. “It can take screenshots, key logs, upload folders/files from a victim’s machine and more. Upon execution, it establishes commands with its command-and control-server and waits for commands.”

The report suggests the malware specifically targets cryptocurrency users for the purpose of attacking their crypto wallets, noting that victims were observed commenting on posts related to the popular Ethereum wallet app Metamask. Based on the researchers’ observations of the malware’s behaviors, it’s possible more than 6.5 thousand people had been compromised.

How to avoid it

The first step is the best step and that’s not to download any of these apps, full stop.

In general, when you’re looking into new apps, Lopp suggests avoiding shady websites and forums. Only install software that is well-known and properly reviewed; look for apps with lengthy reputation histories and sizable install bases.

“Don’t use wallets that store the private keys on your laptop/desktop; private keys should be stored on dedicated hardware devices,” said Lopp.

This point reinforces the importance of storing your crypto in cold hardware wallets and writing down seed phrases rather than just storing them on your computer. Both of these techniques make them inaccessible to malware that trolls your online activity.

Screen Shot 2021 01 06 at 9.27.04 AM

A victim commenting on the malicious activity of one of the ElectroRAT apps
(Intezer)

There are secondary steps that can be taken if you think your computer might have already been compromised.

“To make sure you are not infected we recommend [you] take proactive action and scan your devices for malicious activity,” said Mechtinger.

In the report, Mechtinger suggests that if you think you’re a victim of this scam, you need to kill the processes running and delete all files related to the malware. You also need to make sure your machine is clean and running non-malicious code. Intezer has created Endpoint Scanner for Windows environments and Intezer Protect, a free community tool for Linux users. More detailed information about detection can be found in the original report.

And, of course, you should move your funds to a new crypto wallet and change all your passwords.

A higher bitcoin price attracts more malware

With the price of bitcoin continuing to rise, Mechtinger doesn’t see attacks like this slowing down. In fact, they’re likely to increase.

“There are high capitals at stake, which is classic for financially motivated hackers,” she said.

Lopp said we will see attackers devote greater and greater resources to coming up with new ways to part people from their private keys.

“While a novel attack takes much greater effort to develop, the rewards are also potentially higher because it’s more likely to fool people because the knowledge of that style of attack has not been disseminated through the user base,” he said.  “That is, people are more likely to expose themselves to the attack unknowingly.”



Forex Trading can be risky, to cut the risk. Sign up to FX Delta for consistent results. The Best Forex trading signals for an average of 8% gains. Click here to sign up.



Source link

Tags: cryptoElusiveMalwareTargetedWalletsYear
Share76Tweet47

Related Posts

Libra Co-Creator's VC Firm Co-Leads $12M Round in ‘Decentralized GitHub’

Libra Co-Creator’s VC Firm Co-Leads $12M Round in ‘Decentralized GitHub’

by CryptoInfoNet
February 18, 2021
0

In retrospect, it was inevitable: A team of blockchain developers has forked GitHub and come up with a system...

How Crypto Transforms Prediction Markets

How Crypto Transforms Prediction Markets

by CryptoInfoNet
February 18, 2021
0

Prediction markets are speculative platforms where traders can place bets on the outcome of future events, such as “Will...

Robinhood to Allow Deposits, Withdrawals for Cryptos Including Dogecoin

Robinhood to Allow Deposits, Withdrawals for Cryptos Including Dogecoin

by CryptoInfoNet
February 18, 2021
0

Online brokerage app Robinhood says it plans to enable withdrawals and deposits of cryptocurrencies including dogecoin.In a tweet Wednesday,...

Cosmos Upgrades to Stargate: Another 2017 ICO Very Nearly Completes Its Vision

Cosmos Upgrades to Stargate: Another 2017 ICO Very Nearly Completes Its Vision

by CryptoInfoNet
February 17, 2021
0

At 6:00 UTC Thursday, the Stargate upgrade of Cosmos will go live. The Cosmos community recommends that interested observers...

Bitcoin Taproot Upgrade Expected to Begin Activation in July

Bitcoin Taproot Upgrade Expected to Begin Activation in July

by CryptoInfoNet
February 17, 2021
0

A release date and activation timeline are set for Bitcoin’s Taproot upgrade, but developers and other stakeholders are still...

Load More

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

We have all the latest updated and legitimate information related to Blockchain, Cryptocurrency, latest market rates & trends, prices, new regulations along with every other thing that somehow related to crypto or digital currency market. Our main idea is to provide the kind of news that is original and at the same time, it can prove to be beneficial for our audience.

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Litecoin
  • Market
  • Regulation

Archives

  • March 2021
  • February 2021
  • January 2021
  • About Us
  • Privacy Policy
  • Contact Us

© 2021 cryptoinfonet.com

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Regulation

© 2020 cryptoinfonet.com

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Go to mobile version