Security News

Hackers use new, fake crypto app to breach networks, steal cryptocurrency
2022-12-03 15:12

The North Korean 'Lazarus' hacking group is linked to a new attack spreading fake cryptocurrency apps under the made-up brand, "BloxHolder," to install the AppleJeus malware for initial access to networks and steal crypto assets. A new report by Volexity has identified new, fake crypto programs and AppleJeus activity, with signs of evolution in the malware's infection chain and abilities.

Researchers 'Accidentally’ Crash KmsdBot Cryptocurrency Mining Botnet Network
2022-12-01 09:48

An ongoing analysis into an up-and-coming cryptocurrency mining botnet known as KmsdBot has led to it being accidentally taken down. The botnet strikes both Windows and Linux devices spanning a wide range of microarchitectures with the primary goal of deploying mining software and corralling the compromised hosts into a DDoS bot.

Malware Authors 'Accidentally' Crash KmsdBot Cryptocurrency Mining Botnet
2022-12-01 09:48

An ongoing analysis into an up-and-coming cryptocurrency mining botnet known as KmsdBot has led to it being accidentally taken down. The botnet strikes both Windows and Linux devices spanning a wide range of microarchitectures with the primary goal of deploying mining software and corralling the compromised hosts into a DDoS bot.

U.S. Authorities Seize Domains Used in 'Pig butchering' Cryptocurrency Scams
2022-11-22 09:10

The fraudulent scheme, which operated from May to August 2022, netted the actors over $10 million from five victims, the DoJ said. The criminals encounter potential victims on dating apps, social media sites, and SMS messages.

Google Chrome extension used to steal cryptocurrency, passwords
2022-11-21 18:24

An information-stealing Google Chrome browser extension named 'VenomSoftX' is being deployed by Windows malware to steal cryptocurrency and clipboard contents as users browse the web. This Chrome extension is being installed by the ViperSoftX Windows malware, which acts as a JavaScript-based RAT and cryptocurrency hijacker.

New Laplas Clipper Malware Targeting Cryptocurrency Users via SmokeLoader
2022-11-08 13:40

Cryptocurrency users are being targeted with a new clipper malware strain dubbed Laplas by means of another malware known as SmokeLoader. Observed in the wild since circa 2013, SmokeLoader functions as a generic loader capable of distributing additional payloads onto compromised systems, such as information-stealing malware and other implants.

Open-source repository SourceHut to remove all cryptocurrency-related projects
2022-11-02 19:14

Open-source repository SourceHut is pulling the plug on software projects that tap into cryptocurrency and blockchain. In a post published on Monday, Oct. 31, SourceHut founder and creator Drew DeVault said he would ban projects associated with these technologies, citing their use in "Get-rich-quick" schemes and other types of scams.

Scams targeting cryptocurrency enthusiasts are getting more prevalent
2022-10-31 04:30

Crypto giveaway scams have evolved into an illicit market segment with multiple services that aim to facilitate fraudulent operations. The growth of fake crypto giveaways can be explained by a significantly enhanced arsenal and availability of tools for crypto scammers, even with low technical skills.

These Dropper Apps On Play Store Targeting Over 200 Banking and Cryptocurrency Wallets
2022-10-28 13:30

Five malicious dropper Android apps with over 130,000 cumulative installations have been discovered on the Google Play Store distributing banking trojans like SharkBot and Vultur, which are capable of stealing financial data and performing on-device fraud. Targets of these droppers include 231 banking and cryptocurrency wallet apps from financial institutions in Italy, the U.K., Germany, Spain, Poland, Austria, the U.S., Australia, France, and the Netherlands.

Purpleurchin cryptocurrency miners spotted scouring free GitHub, Heroku accounts
2022-10-27 07:27

A stealthy cryptocurrency mining operation has been spotted using thousands of free accounts on GitHub, Heroku and other DevOps outfits to craft digital tokens. Sysdig estimated each of those 30 free GitHub accounts cost the Microsoft-owned giant $15 per month, and the free tier accounts from Heroku, Buddy and others cost providers between $7 and $10 per month.