Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 CryptoClippy: New Malware Targeting Users for Cryptocurrency Theft

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 CryptoClippy: New Malware Targeting Users for Cryptocurrency Theft


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

CryptoClippy: New Malware Targeting Users for Cryptocurrency Theft

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

CryptoClippy malware

Portuguese users have recently become the target of a new form of malware, codenamed CryptoClippy. This particular malware is capable of stealing cryptocurrency as part of a malvertising campaign that entices users searching for “WhatsApp web” to rogue domains hosting the malware, according to a new report by Palo Alto Networks Unit 42.

CryptoClippy is a type of cryware known as clipper malware, which monitors a victim’s clipboard for content matching cryptocurrency addresses and replaces them with a wallet address under the control of the threat actor. The malware uses regular expressions to identify what type of cryptocurrency the address pertains to and then replaces the clipboard entry with a visually similar but adversary-controlled wallet address for the appropriate cryptocurrency. This means that when the victim pastes the address from the clipboard to conduct a transaction, they are unknowingly sending cryptocurrency directly to the threat actor.

Clipper Malware

The illicit scheme has reportedly netted the operators around $983 so far, with victims found across several industries including manufacturing, IT services, and real estate.

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Sophisticated Malware Delivery Tactics Increase Threat to Portuguese Users

To deliver the malware to potential victims, the campaign leverages SEO poisoning techniques and traffic direction systems (TDS). The TDS checks whether the user’s preferred browser language is Portuguese and if so, redirects them to a rogue landing page, where they can become infected with CryptoClippy. Users who do not meet this criteria are simply redirected to the legitimate WhatsApp Web domain, without any malicious activity taking place, thus avoiding detection.

It’s worth noting that the use of poisoned search results to deliver malware has been adopted by other threat actors, most notably those associated with the GootLoader malware. This trend demonstrates a growing sophistication and effectiveness of these tactics in bypassing security measures and delivering malware to unsuspecting victims.

Users urged to remain vigilant against growing threats to personal data security

The findings come just days after SecurityScorecard reported on another form of malware called Lumma, which is capable of harvesting data from web browsers, cryptocurrency wallets, and various apps, including AnyDesk, FileZilla, KeePass, Steam, and Telegram.

As always, it’s crucial for users to remain vigilant and cautious when browsing the internet, especially when searching for popular services like WhatsApp Web. They should be careful not to click on suspicious links or download any suspicious files, and always use reputable anti-malware software to protect themselves against potential threats.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: thehackernews.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post CryptoClippy: New Malware Targeting Users for Cryptocurrency Theft first appeared on Black Hat Ethical Hacking. ...



📌 CryptoClippy: New Malware Targeting Users for Cryptocurrency Theft


📈 77.31 Punkte

📌 CryptoClippy: New Clipper Malware Targeting Portuguese Cryptocurrency Users


📈 66.91 Punkte

📌 New Laplas Clipper Malware Targeting Cryptocurrency Users via SmokeLoader


📈 31.6 Punkte

📌 Warning: Cross-Platform ElectroRAT Malware Targeting Cryptocurrency Users


📈 28.68 Punkte

📌 New ElectroRAT employed in a wide-ranging operation targeting cryptocurrency users


📈 27 Punkte

📌 New “Address Poisoning” Cryptocurrency Scam Is Targeting MetaMask Users


📈 27 Punkte

📌 New Android Malware Gustuff Targeting 100+ Banking, 32 Cryptocurrency and Messengers apps such as WhatsApp


📈 26.34 Punkte

📌 New Android Malware Gustuff Targeting 100+ Banking, 32 Cryptocurrency and Messengers apps such as WhatsApp


📈 26.34 Punkte

📌 New shc-based Linux Malware Targeting Systems with Cryptocurrency Miner


📈 26.34 Punkte

📌 New shc-based Linux Malware Targeting Systems with Cryptocurrency Miner


📈 26.34 Punkte

📌 New Rilide Malware Targeting Chromium-Based Browsers to Steal Cryptocurrency


📈 26.34 Punkte

📌 New Migo Malware Targeting Redis Servers for Cryptocurrency Mining


📈 26.34 Punkte

📌 Cryptocurrency theft malware is now an economy worth millions


📈 24.47 Punkte

📌 Researchers Detail How Cyber Criminals Targeting Cryptocurrency Users


📈 24.07 Punkte

📌 IDIQ Joins Identity Theft Resource Center in Releasing New Report on Trends in Identity Theft and Scams


📈 23.74 Punkte

📌 Cryptocurrency Mining Malware Discovered Targeting Seagate NAS Hard Drives


📈 23.41 Punkte

📌 Cryptocurrency Mining Malware Discovered Targeting Seagate NAS Hard Drives


📈 23.41 Punkte

📌 Recently discovered OSX.Dummy mac malware is targeting the cryptocurrency community


📈 23.41 Punkte

📌 BabyShark Malware Targeting Nuclear and Cryptocurrency Industries


📈 23.41 Punkte

📌 BabyShark Malware Targeting Nuclear and Cryptocurrency Industries


📈 23.41 Punkte

📌 Clipsa Malware Steals Cryptocurrency By Targeting Unsecured WordPress Sites


📈 23.41 Punkte

📌 Lazarus Group’s AppleJeus MacOS malware targeting cryptocurrency exchanges


📈 23.41 Punkte

📌 New Report Finds Nearly 50% of 2021 Phishing Targeting Gov’t Workers Aimed at Credential Theft


📈 22.69 Punkte

📌 New KryptoCibule Windows malware is a triple threat for cryptocurrency users


📈 22.25 Punkte

📌 Hackers target cryptocurrency users with new ElectroRAT malware


📈 22.25 Punkte

📌 New S1deload Malware Hijacking Users' Social Media Accounts and Mining Cryptocurrency


📈 22.25 Punkte

📌 Hackers Target Cryptocurrency Users With New ElectroRAT Malware


📈 22.25 Punkte

📌 New espionage malware found targeting Russian-speaking users in Eastern Europe


📈 22.14 Punkte

📌 New NetWire RAT Campaigns Use IMG Attachments to Deliver Malware Targeting Enterprise Users


📈 22.14 Punkte

📌 MacStealer: The new info-stealing malware targeting Mac users


📈 22.14 Punkte

📌 New ZenRAT Malware Targeting Windows Users via Fake Password Manager Software


📈 22.14 Punkte

📌 New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam


📈 22.14 Punkte

📌 Warning: New Undetectable DNS Hijacking Malware Targeting Apple macOS Users


📈 22.14 Punkte

📌 New Malware “MosaicLoader” Targeting Users Searching for Pirated Software


📈 22.14 Punkte

📌 Kimsuky Hacker Group Targeting Mobile Users With New Android Malware


📈 22.14 Punkte











matomo