Bitcoin Forum
May 24, 2024, 01:45:43 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Meet a racist malware targetting extension based wallets  (Read 174 times)
libert19 (OP)
Hero Member
*****
Offline Offline

Activity: 2506
Merit: 945



View Profile WWW
February 02, 2022, 01:04:17 PM
Merited by DdmrDdmr (3), NeuroticFish (2)
 #1

No, that wasn't a typo, this malware is indeed racist.

Named 'Mars Stealer' and as expected from malwares - it spreads through channels such as file-hosting websites, torrent clients, shady downloaders, etc.

The first thing it does is check the device language. If it matches the language ID of Kazakhstan, Uzbekistan, Azerbaijan, Belarus or Russia, the software leaves the system without any malicious action otherwise you are fucked.

Read complete story: https://cointelegraph.com/news/hodlers-beware-new-malware-targets-metamask-and-40-other-crypto-wallets


███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Little Mouse
Legendary
*
Offline Offline

Activity: 2058
Merit: 1998


Marketing Campaign Manager |Telegram ID- @LT_Mouse


View Profile WWW
February 02, 2022, 01:05:41 PM
 #2

Posted here too- https://bitcointalk.org/index.php?topic=5384035.0

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
NeuroticFish
Legendary
*
Offline Offline

Activity: 3682
Merit: 6406


Looking for campaign manager? Contact icopress!


View Profile
February 02, 2022, 05:18:11 PM
Last edit: February 02, 2022, 05:36:27 PM by NeuroticFish
 #3

The first thing it does is check the device language. If it matches the language ID of Kazakhstan, Uzbekistan, Azerbaijan, Belarus or Russia, the software leaves the system without any malicious action otherwise you are fucked.

This is somewhat funny, since I expect that like everywhere on the world, quite a lot of users from those countries will have their windoze in US English only.
So it's a rather stupid way to be "racist" Grin



It has to be the primary language or any?
It has occurred to me that maybe if we install one of those languages would this malware leave us alone?

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
BIT-BENDER
Hero Member
*****
Offline Offline

Activity: 1540
Merit: 702



View Profile
February 02, 2022, 09:04:21 PM
 #4

Wasted technology, for real how would an individual phantom the idea of creating such menace beats my imagination, it's good a thing this such Malware has been pointed out but how does it operate, apart from the fact that it has targeted citizens, and also how can so one with low or average tech knowledge protect themselves from such knowledge, I believe there are newbies who still doesn't understand how this malware stuff works.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
mk4
Legendary
*
Offline Offline

Activity: 2772
Merit: 3838


Paldo.io 🤖


View Profile
February 03, 2022, 09:27:53 AM
 #5

The first thing it does is check the device language. If it matches the language ID of Kazakhstan, Uzbekistan, Azerbaijan, Belarus or Russia, the software leaves the system without any malicious action otherwise you are fucked.

9000 IQ move: actually change your device's language ID to any of those language IDs, just to be sure.

Jokes aside — not sure if I would call this "racist" though, as it's not necessarily an attack on a certain race, but rather the hacker is just protecting his folks I guess(not to make him/her less of a criminal though, obviously).

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
aysg76
Legendary
*
Offline Offline

Activity: 1960
Merit: 2124



View Profile
February 03, 2022, 09:51:13 AM
 #6

This is somewhat funny, since I expect that like everywhere on the world, quite a lot of users from those countries will have their windoze in US English only.
So it's a rather stupid way to be "racist" Grin
I also thought of the same way as most of the devices have the in built option of default language as English and you can change it in the settings or boot up process but as you said mostly prefer English as it's easy to navigate in that language.So this attack will not protect all the citizens of those restricted malware attempts.Maybe it's racist attack but not fully planned by them.


But still you can protect yourself by using hardware wallets or cold storage and your seed phrases not being compromised then you could prefer any language and it won't affect you but most of us ignore the safety measures.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
lovesmayfamilis
Legendary
*
Offline Offline

Activity: 2100
Merit: 4316


✿♥‿♥✿


View Profile
February 03, 2022, 10:25:15 AM
Merited by libert19 (1)
 #7

Wasted technology, for real how would an individual phantom the idea of creating such menace beats my imagination, it's good a thing this such Malware has been pointed out but how does it operate, apart from the fact that it has targeted citizens, and also how can so one with low or average tech knowledge protect themselves from such knowledge, I believe there are newbies who still doesn't understand how this malware stuff works.

You just need to follow the most common safety precautions. It's not news when we hear that when using torrents and all sorts of cracks, there is a chance that some kind of malware will be embedded in them. Do not combine your work and entertainment on one device. Don't decorate your browser like a Christmas tree with extensions. Well, the most obvious, update your systems and use high-quality antivirus. Everything that is distributed on the Internet under the motto "free" always carries the connotation of deception.
Any beginner should understand this in our time

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
PrimeNumber7
Copper Member
Legendary
*
Offline Offline

Activity: 1624
Merit: 1899

Amazon Prime Member #7


View Profile
February 03, 2022, 10:25:54 AM
 #8

According to the article you cited, the malware is for sale to third parties who want to try to infect others for profit.

My speculation is that, whoever created the malware wanted to prevent themselves and their countrymen from getting infected, possibly due to legal concerns (for example, if people in their home country are getting infected, that country's law enforcement may devote more resources into trying to catch whoever created the malware). The langue setting could be broad enough such that it is unlikely that anyone in their home country will actually see their coin stolen, for example if people in their home country speaks a diverse set of languages.
jerry0
Full Member
***
Offline Offline

Activity: 1736
Merit: 186


View Profile
February 08, 2022, 09:24:51 PM
 #9

What is the exact reason for this again?  Is it because concern of issue with their own government?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!