Security News

New Malware Targets 97 Browser Variants, 76 Crypto Wallets & 19 Password Managers
2023-07-06 18:51

Learn how the Meduza Stealer malware works, what it targets and how to protect your company from this cybersecurity threat. New malware dubbed Meduza Stealer can steal information from a large number of browsers, password managers and cryptocurrency wallets, according to a report from cybersecurity company Uptycs.

Evasive Meduza Stealer Targets 19 Password Managers and 76 Crypto Wallets
2023-07-03 09:38

In yet another sign of a lucrative crimeware-as-a-service ecosystem, cybersecurity researchers have discovered a new Windows-based information stealer called Meduza Stealer that's actively being developed by its author to evade detection by software solutions. "The Meduza Stealer has a singular objective: comprehensive data theft," Uptycs said in a new report.

Beware: New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer
2023-06-13 15:31

A novel multi-stage loader called DoubleFinger has been observed delivering a cryptocurrency stealer dubbed GreetingGhoul in what's an advanced attack targeting users in Europe, the U.S., and Latin America. "DoubleFinger is deployed on the target machine, when the victim opens a malicious PIF attachment in an email message, ultimately executing the first of DoubleFinger's loader stages," Kaspersky researcher Sergey Lozhkin said in a Monday report.

New Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets
2023-05-27 08:10

A new stealthy information stealer malware called Bandit Stealer has caught the attention of cybersecurity researchers for its ability to target numerous web browsers and cryptocurrency wallets. "It has the potential to expand to other platforms as Bandit Stealer was developed using the Go programming language, possibly allowing cross-platform compatibility," Trend Micro said in a Friday report.

New Atomic macOS Malware Steals Keychain Passwords and Crypto Wallets
2023-04-28 11:59

Threat actors are advertising a new information stealer for the Apple macOS operating system called Atomic macOS Stealer on Telegram for $1,000 per month, joining the likes of MacStealer. "The Atomic macOS Stealer can steal various types of information from the victim's machine, including Keychain passwords, complete system information, files from the desktop and documents folder, and even the macOS password," Cyble researchers said in a technical report.

New Atomic macOS info-stealing malware targets 50 crypto wallets
2023-04-27 14:34

A new macOS information-stealing malware named 'Atomic' is being sold to cybercriminals via private Telegram channels for a subscription of $1,000 per month. For this hefty price, buyers get a DMG file containing a 64-bit Go-based malware designed to target macOS systems and steal keychain passwords, files from the local filesystem, passwords, cookies, and credit cards stored in browsers.

BlackGuard stealer now targets 57 crypto wallets, extensions
2023-03-23 22:08

A new variant of the BlackGuard stealer has been spotted in the wild, featuring new capabilities like USB propagation, persistence mechanisms, loading additional payloads in memory, and targeting additional crypto wallets. BlackGuard was first spotted by Zscaler in March 2022, who reported that the malware was sold to cyber criminals on Russian-speaking forums as a MaaS for $200/month or a lifetime price of $700. The new stealer appeared shortly after the original Raccoon Stealer MaaS operation shut down, enjoying good adoption rates while offering extensive app-targeting capabilities.

These Dropper Apps On Play Store Targeting Over 200 Banking and Cryptocurrency Wallets
2022-10-28 13:30

Five malicious dropper Android apps with over 130,000 cumulative installations have been discovered on the Google Play Store distributing banking trojans like SharkBot and Vultur, which are capable of stealing financial data and performing on-device fraud. Targets of these droppers include 231 banking and cryptocurrency wallet apps from financial institutions in Italy, the U.K., Germany, Spain, Poland, Austria, the U.S., Australia, France, and the Netherlands.

Solana, Phantom blame Slope after millions in crypto-coins stolen from 8,000 wallets
2022-08-04 03:26

From what we can tell, and details are still light, somewhere between $4.5 million and $8 million in coins - including stablecoins USDC and USDT, and Solana's SOL - were taken from roughly 8,000 Slope and Phantom mobile app wallets. Phantom also makes a Solana-focused mobile wallet for Android and iOS. Coins were drained from some of its users' mobile wallets, though the majority of stolen funds were pulled from Slope wallets.

Thousands of Solana wallets drained in attack using unknown exploit
2022-08-03 11:26

An overnight attack on the Solana blockchain platform drained thousands of software wallets of cryptocurrency worth millions of U.S. dollars. In a statement today, Solana said that at 5 AM UTC the attack impacted more than 7,700 wallets, including Slope and Phantom.