Bitcoin Forum
November 09, 2024, 02:28:40 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Mispadu - banking trojan and infostealer target crypto exchanges across LATAM  (Read 99 times)
Jating (OP)
Hero Member
*****
Offline Offline

Activity: 3108
Merit: 884


DGbet.fun - Crypto Sportsbook


View Profile
April 04, 2024, 10:36:53 AM
Merited by DdmrDdmr (4), hugeblack (2)
 #1

Mispadu, a supposedly banking trojan and infostealer that targets LATAM has evolved itself and now venturing not just in that region but other European as well and it also includes crypto exchanges in their crosshair.

Sample phishing email sent by the threat actor, which include a PDF attachment that contains the malware as it will download a ZIP file through a URL shortener service.




Below are the target crypto exchanges,



And this is the two Bitcoin addresses associated with the cyber criminals,

  • bc1qn5fwarp0wesjahyaavj3zpzawsh3mp0mpuw94n
  • bc1qzcdrhp30eztexrmyvz5dwuyzzqyylq5muuyllf

The first address has close to 1 BTC already.

Quote
This address has transacted 62 times on the Bitcoin blockchain. It has received a total of 0.82939740 BTC $55,022.77 and has sent a total of 0.82937010 BTC $55,020.96 The current value of this address is 0.00002730 BTC $1.81.

https://blog.morphisec.com/mispadu-infiltration-beyond-latam

Aanuoluwatofunmi
Sr. Member
****
Offline Offline

Activity: 770
Merit: 434



View Profile
April 04, 2024, 11:00:25 AM
 #2

Any form of attack can spread across the world, mostly on regions where it is not being predominant, this will make them achieve their goals in seeing that they have a larger coverage to the areas being affected of their evil activities, we should have the intention of getting informations from reliable sources daily, in other to help us get informed on the recent mode of attack scammers are using to steal from people, information is our first security measures.

████████▄▄▄▄▄▄▀▀▀▀▀▀▄
███▄▀▀▀▀▀███████████
███▐▌████████████▀█▀▐▌
███▐▌███▄█▀█████████████████▄▄▄▄
▄▀█████▐█████████▄▄▄▐█▌▄█▌██▀▀
██████▐███▐██▌▄█▀▀▀▐█████▀███▄
▐█
██▐▌██▐████▌█▌█▌███▐█▌█▄▄▄▄██
▐██
▐▌██▐█▌▐█▀█▌▀█▄▄█▐███▀▀▀▀▀▀
████████▐█▌█▌▀▀▀██▀▀████▄▌████▄
███▄███▌▐████▄██▌█▌██▐████▌█▌▄█▀
██▐█▄▄▄▄██████████▌██▐████▌█▌▐██
███▀███▀▀████▌█████▄▄▐█▄▄█▌██▀▀
████████████▀███▌▀▀▀▀██▀▀
▄███████████████████████▄
█▌▐▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▌▐█
█▌▐█████▌▐█████▌▐█████▌▐█
█▌▐█▄▄▄█▌▐█▄▄▄█▌▐█▄▄▄█▌▐█
█▌▐██▀▄█▌▐██▀▄█▌▐██▀▄█▌▐█
█▌▐██░██▌▐██░██▌▐██░██▌▐█
█▌▐█████▌▐█████▌▐█████▌▐█
█▌▐▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▌▐█
█████████████████████████
▀██████████▀▀▀██████████▀
███████
▄███████████▄
IN-HOUSE
SLOTS
LIVE GAMES
TABLE
NO FEES ON
BITCOIN WITHDRAWALS

▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████▄
█████████████████████████
████████████████████████
█████████████████████████
▀██████████████████████▀
▀█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀

▀███████████▀
[
[
RELOAD
BONUS
 

RAKEBACK
BONUS
]
]
[
[
FREE
COINS
 

VIP
REWARDS
]
]
[ 
 Play Now
]
promise444c5
Sr. Member
****
Online Online

Activity: 462
Merit: 293


Learning never stops!


View Profile
April 04, 2024, 03:18:32 PM
 #3

~
In short, if i could interpret this clearly that this phishing attack is being done through electronic mail , then i think we would all agree that we need to stop(if we are used to it )  downloading  attachment  from an unknown or unverified source  as it could  be an attack and my cost you fortune or maybe debt  Tongue



██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
hugeblack
Legendary
*
Offline Offline

Activity: 2688
Merit: 3969



View Profile WWW
April 05, 2024, 02:06:46 AM
 #4

I think that most cryptocurrency exchanges require two-factor authentication, so even if this trojan was able to obtain information such as email and password, it still needs a two-factor authentication code to log into the account. Therefore, I think that it aims to collect more data about users than stealing their balances. It is better to have a separate device that you use it to conduct banking transactions/connect to cryptocurrency exchanges and not to click on unknown links or download any file.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
promise444c5
Sr. Member
****
Online Online

Activity: 462
Merit: 293


Learning never stops!


View Profile
April 05, 2024, 10:12:03 AM
 #5

I think that most cryptocurrency exchanges require two-factor authentication, so even if this trojan was able to obtain information such as email and password, it still needs a two-factor authentication code to log into the account. Therefore, I think that it aims to collect more data about users than stealing their balances. It is better to have a separate device that you use it to conduct banking transactions/connect to cryptocurrency exchanges and not to click on unknown links or download any file.
Yes  cryptocurrency  exchanges require two-facto authentication  for confirmation  of every  transaction made , so if it  only  get information about user password and email  then I will consider it as a phisher but I don't  think this 2-facto authentication is compulsory  so advice and awareness should also be created towards the usage of two-facto authentication which should  not be limited  to Exchange in the first place.



██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
Dave1
Hero Member
*****
Offline Offline

Activity: 1484
Merit: 553



View Profile
April 05, 2024, 10:25:11 AM
 #6

I think that most cryptocurrency exchanges require two-factor authentication, so even if this trojan was able to obtain information such as email and password, it still needs a two-factor authentication code to log into the account. Therefore, I think that it aims to collect more data about users than stealing their balances. It is better to have a separate device that you use it to conduct banking transactions/connect to cryptocurrency exchanges and not to click on unknown links or download any file.

Yes, but we all know that this scammers might as well get over the 2FA, How Attackers Bypass Two-factor Authentication (2FA).

So there is still a possibility that we can lose our money with this infostealer that goes after our exchanges data.

But I do agree, we can't stress that enough, we should have at least separate device for our crypto and banking transactions so prevent this kind of attack.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
joniboini
Legendary
*
Offline Offline

Activity: 2366
Merit: 1805



View Profile WWW
April 05, 2024, 01:36:11 PM
 #7

Therefore, I think that it aims to collect more data about users than stealing their balances. It is better to have a separate device that you use it to conduct banking transactions/connect to cryptocurrency exchanges and not to click on unknown links or download any file.
Based on the article above, the main payload allows the malware to collect data from browsers and e-mail messages. So the goal is definitely to steal sensitive data. 2FA might help but if they use a browser add-on to manage their 2FA it might be useless. Not to mention if the services they use only support verification from e-mail messages. Using a different device to manage 2FA probably helps a little bit, but it is still a waste since your passwords and other sensitive data might already be in the attacker's hands. CMIIW.

▄▄███████████████████▄▄
▄███████████████████████▄
████████▀░░░░░░░▀████████
███████░░░░░░░░░░░███████
███████░░░░░░░░░░░███████
██████▀░░░░░░░░░░░▀██████
██████▄░░░░░▄███▄░▄██████
██████████▀▀█████████████
████▀▄██▀░░░░▀▀▀░▀██▄▀███
███░░▀░░░░░░░░░░░░░▀░░███
████▄▄░░░░▄███▄░░░░▄▄████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 CHIPS.GG 
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
███▀░▄░▀▀▀▀▀░▄░▀███
▄███
░▄▀░░░░░░░░░▀▄░███▄
▄███░▄░░░▄█████▄░░░▄░███▄
███░▄▀░░░███████░░░▀▄░███
███░█░░░▀▀▀▀▀░░░▀░░░█░███
███░▀▄░▄▀░▄██▄▄░▀▄░▄▀░██
▀███
░▀░▀▄██▀░▀██▄▀░▀░██▀
▀███
░▀▄░░░░░░░░░▄▀░██▀
▀███▄
░▀░▄▄▄▄▄░▀░▄███▀
▀█
███▄▄▄▄▄▄▄████▀
█████████████████████████
▄▄███████▄▄
███
████████████▄
▄█▀▀▀▄
█████████▄▀▀▀█▄
▄██████▀▄▄▄▄▄▀██████▄
▄█████████████▄████████▄
████████▄███████▄████████
█████▄█████████▄██████
██▄▄▀▀▀▀█████▀▀▀▀▄▄██
▀█████████▀▀███████████▀
▀███████████████████▀
██████████████████
▀████▄███▄▄
████▀
████████████████████████
3000+
UNIQUE
GAMES
|
12+
CURRENCIES
ACCEPTED
|
VIP
REWARD
PROGRAM
 
 
  Play Now  
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!