Security News > 2022 > May > Microsoft Warns of "Cryware" Info-Stealing Malware Targeting Crypto Wallets

Microsoft is warning of an emerging threat targeting internet-connected cryptocurrency wallets, signaling a departure in the use of digital coins in cyberattacks.
"Cryware are information stealers that collect and exfiltrate data directly from non-custodial cryptocurrency wallets, also known as hot wallets," Berman Enconado and Laurie Kirk of the Microsoft 365 Defender Research Team said in a new report.
"Because hot wallets, unlike custodial wallets, are stored locally on a device and provide easier access to cryptographic keys needed to perform transactions, more and more threats are targeting them."
Earlier this year, Kaspersky disclosed a financially-motivated campaign staged by the North Korea-based Lazarus Group, which involved targeting crypto companies with malware designed to drain funds out of hot wallets.
Such information-stealing attacks aim to extract hot wallet data such as private keys, seed phrases, and wallet addresses, thereby allowing the threat actor to initiate rogue transactions and move funds to another wallet.
To mitigate such threats, Microsoft is recommending users and organizations to lock hot wallets when not trading, disconnect sites connected to a wallet, avoid storing private keys in plaintext, and verify the value of the wallet address when copying and pasting the information.
News URL
https://thehackernews.com/2022/05/microsoft-warns-of-cryware-info.html
Related news
- Microsoft spots XCSSET macOS malware variant used for crypto theft (source)
- Decentralization is happening everywhere, so why are crypto wallets “walled gardens”? (source)
- Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware (source)
- Google Play, Apple App Store apps caught stealing crypto wallets (source)
- Crypto-stealing iOS, Android malware found on App Store, Google Play (source)
- Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign (source)
- New Microsoft script updates Windows media with bootkit malware fixes (source)
- SparkCat Malware Uses OCR to Extract Crypto Wallet Recovery Phrases from Images (source)
- Microsoft says attackers use exposed ASP.NET keys to deploy malware (source)
- Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play (source)