Bitcoin Forum
May 02, 2024, 12:47:47 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Evrial Trojan Switches Bitcoin Addresses Copied to Windows Clipboard  (Read 139 times)
Crytptohack (OP)
Member
**
Offline Offline

Activity: 126
Merit: 15

HodL!


View Profile WWW
February 07, 2018, 07:31:35 PM
 #1

This is just for those that haven't heard of this issue. It appears that the virus is from Russian hackers and it changes the send BTC address to their own.

The easiest way to prevent it is what most people do already which is to check the first 3 digits/letters and the last 3 and make sure they match.

1714654067
Hero Member
*
Offline Offline

Posts: 1714654067

View Profile Personal Message (Offline)

Ignore
1714654067
Reply with quote  #2

1714654067
Report to moderator
Every time a block is mined, a certain amount of BTC (called the subsidy) is created out of thin air and given to the miner. The subsidy halves every four years and will reach 0 in about 130 years.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714654067
Hero Member
*
Offline Offline

Posts: 1714654067

View Profile Personal Message (Offline)

Ignore
1714654067
Reply with quote  #2

1714654067
Report to moderator
Aura
Sr. Member
****
Offline Offline

Activity: 518
Merit: 268


View Profile
February 07, 2018, 07:42:52 PM
 #2

Are you referring to the virus that adjust your clipboard to when it detects that you copied a Bitcoin address? Or is this a new sort of malware that targets specific wallet clients?
13abyknight
Sr. Member
****
Offline Offline

Activity: 602
Merit: 252


View Profile
February 07, 2018, 08:00:37 PM
 #3

This is just for those that haven't heard of this issue. It appears that the virus is from Russian hackers and it changes the send BTC address to their own.

The easiest way to prevent it is what most people do already which is to check the first 3 digits/letters and the last 3 and make sure they match.

Again, even though I had prior knowledge about this, thanks for the heads up. Everyone should definitely resort to double checking addresses before sending/receiving funds.

Are you referring to the virus that adjust your clipboard to when it detects that you copied a Bitcoin address? Or is this a new sort of malware that targets specific wallet clients?

Pretty sure it just copies the address provided by the malware host (creator) to clipboard instead of copying the actual address you highlighted and yes, it works based on some sort of detection algorithm i.e only when Bitcoin addresses are trying to be copied. It targets everything from web browsers to wallet clients using a formgrabber.
Crytptohack (OP)
Member
**
Offline Offline

Activity: 126
Merit: 15

HodL!


View Profile WWW
February 07, 2018, 08:14:05 PM
 #4

13abyknight pretty much answered the question.  When you highlight and copy the BTC recipients address, the copy goes to the clipboard on windows based computers. (Mac's are safe for now)  The hack is when you 'paste' what you think you copied, but it is the address to the hacker. (Pretty slick) 

One article that I read mentioned that this virus was for sale on criminal russian websites.
darkangel11
Legendary
*
Offline Offline

Activity: 2338
Merit: 1345


Defend Bitcoin and its PoW: bitcoincleanup.com


View Profile
February 07, 2018, 08:21:24 PM
 #5

This is just for those that haven't heard of this issue. It appears that the virus is from Russian hackers and it changes the send BTC address to their own.

The easiest way to prevent it is what most people do already which is to check the first 3 digits/letters and the last 3 and make sure they match.



The best way to prevent it is to keep your machine clear. The trojan doesn't jump into your device out of nowhere. It is downloaded along with other software, inside a packed archive, a torrent executable, in a mail attachment. Get decent antivirus software, use official downloads for software, buy software instead of getting cracked versions from god knows where and avoid porn sites because they're full of trojans. I know it's hard, especially the last one, no pun intended, but at least use a different device from the one that's holding your money.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
rosecuppy123
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
June 11, 2018, 07:30:29 AM
 #6

is there anybody who has got affected by this trojan ? Huh
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!