Bitcoin Forum
May 09, 2024, 10:39:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ViperSoftX - A new Trojan that steals cryptocurrencies through a Chrome extensio  (Read 93 times)
lovesmayfamilis (OP)
Legendary
*
Offline Offline

Activity: 2086
Merit: 4290


✿♥‿♥✿


View Profile
November 22, 2022, 11:11:23 AM
Merited by o_e_l_e_o (4), DdmrDdmr (3), NeuroticFish (1), Lucius (1), witcher_sense (1), bitmover (1), Awaklara (1)
 #1

Avast experts have discovered malware that steals information from users of Windows systems.

Quote
We’ve been closely monitoring an information stealer called ViperSoftX.

They named the USA, India, Italy and Brazil among the most affected countries.

Quote
This multi-stage stealer exhibits interesting hiding capabilities, concealed as small PowerShell scripts on a single line in the middle of otherwise innocent-looking large log files, among others. ViperSoftX focuses on stealing cryptocurrencies, clipboard swapping, fingerprinting the infected machine, as well as downloading and executing arbitrary additional payloads, or executing commands.

Quote
One of the payloads ViperSoftX distributes is a specific information stealer in the form of a browser extension for Chromium-based browsers. Due to its standalone capabilities and uniqueness, we decided to give it its own name, VenomSoftX. The malicious extension provides full access to every page the victim visits, carries out man-in-the-browser attacks to perform cryptocurrency addresses swapping by tampering with API requests’ data on popular cryptocurrency exchanges, steals credentials and clipboard content, tampers with crypto addresses on visited websites, reports events using MQTT to the C&C server, and more.

ViperSoftX is mostly spread via cracked software such as Adobe Illustrator, Corel Video Studio, Microsoft Office, and more, commonly distributed over torrents.
https://decoded.avast.io/janrubin/vipersoftx-hiding-in-system-logs-and-spreading-venomsoftx/

What are we seeing? Again, Windows systems and the Chrome browser Everyone is strongly advised to start studying Linux systems and not to trust this browser and, even more, various extensions that supposedly simplify the work on the Internet.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
1715294355
Hero Member
*
Offline Offline

Posts: 1715294355

View Profile Personal Message (Offline)

Ignore
1715294355
Reply with quote  #2

1715294355
Report to moderator
The forum strives to allow free discussion of any ideas. All policies are built around this principle. This doesn't mean you can post garbage, though: posts should actually contain ideas, and these ideas should be argued reasonably.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715294355
Hero Member
*
Offline Offline

Posts: 1715294355

View Profile Personal Message (Offline)

Ignore
1715294355
Reply with quote  #2

1715294355
Report to moderator
1715294355
Hero Member
*
Offline Offline

Posts: 1715294355

View Profile Personal Message (Offline)

Ignore
1715294355
Reply with quote  #2

1715294355
Report to moderator
bitmover
Legendary
*
Offline Offline

Activity: 2296
Merit: 5935


bitcoindata.science


View Profile WWW
November 22, 2022, 01:23:57 PM
Merited by Lucius (1)
 #2

What are we seeing? Again, Windows systems and the Chrome browser Everyone is strongly advised to start studying Linux systems and not to trust this browser and, even more, various extensions that supposedly simplify the work on the Internet.

I believe the problem is not with windows or the browser. The problem here is with the user.
Why install so many extensions? Everyone who cares about security and privacy should avoid installing extensions in their browser.

Everything you install in your computer or smartphone is potentially a spyware or a malware, i.e., it could be collecting your data (most of them do that) or just do bad things to your device.

Before installing anything, think twice if you really need that extension/app

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5664


Blackjack.fun🎲


View Profile WWW
November 22, 2022, 02:40:49 PM
 #3

I believe the problem is not with windows or the browser. The problem here is with the user.
Why install so many extensions? Everyone who cares about security and privacy should avoid installing extensions in their browser.

You are right there, the problem lies in the users and their habits, and above all cracked software that they download from torrents and various suspicious sites. The only extensions that everyone should have are uBlock Origin and Privacy Badger, which can be downloaded from the official browser stores.

As for the news itself, I am always divided on the fact that AV companies use such things to advertise themselves, especially those that have a very problematic past with spying on their users and selling their data to whoever is willing to pay for it.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
BitMaxz
Legendary
*
Online Online

Activity: 3248
Merit: 2969


Block halving is coming.


View Profile WWW
November 22, 2022, 11:44:26 PM
 #4

I have experience installing randomly in my chrome browser and firefox plugin but I don't install it mainly on the PC that I usually use for financial activity, I install it on my Vbox l. Those plugins and extensions that I use are mostly for SEO tools and they sometimes have malware so to protect my PC I use Vbox or use extra hard drives only for unknown extensions or plugins. So I agree with the above it's the user's fault because most of the users are illiterate so we can't blame them either.

And the Avast itself most of the software from Avast is malware I don't use them. The last time that use Avast free gives me a few ads and if you uninstall Avast without using their uninstall tool from their website I'm sure your PC will slow down and you will experience BSOD(Blue screen of death). I experience this many times with Avast so better stay away from using them.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
witcher_sense
Legendary
*
Offline Offline

Activity: 2338
Merit: 4334

🔐BitcoinMessage.Tools🔑


View Profile WWW
November 23, 2022, 03:27:47 AM
 #5

I thought ViperSoftX has been discovered almost three years ago by a company named FortiGuard Labs; a news article with a description can be found here: https://www.fortinet.com/blog/threat-research/vipersoftx-new-javascript-threat. This malware is a remote access trojan combined with clipboard malware that replaces users' bitcoin and ethereum addresses with hacker's. When a user executes some commands on their computer, malware checks if the information in the clipboard matches certain regex patterns and, if needed, inserts malicious addresses into the machine's clipboard.

Quote
Changing the clipboard data is done based on the OS version. On Windows 10 it uses PowerShell’s scp. Otherwise, it runs cmd as follows:

Cmd.exe /c echo|set /p=[address to set]|clip


Naturally, clipboard malware is not as effective as direct stealing of wallet data and private keys, and much easier to detect, which is why hackers strive to improve their malware to be able to monitor activity on a computer as long as possible.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!