Bitcoin Forum
May 08, 2024, 08:17:50 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: CHAES: Novel Malware Targeting Latin American E-Commerce and Crypto Mining  (Read 56 times)
Golftech (OP)
Hero Member
*****
Offline Offline

Activity: 2128
Merit: 520


View Profile
November 19, 2020, 09:34:03 AM
Merited by cryptomaniac_xxx (1)
 #1

Another info stealer and crypto miner malware was spotted in Latin America again. It was dub as dubbed Chaes by the team that discovered it, Cybereason Nocturnus researchers.

Initially it focuses on it's attack on MercadoLivre - the largest e-commerce in Brazil.



What makes this infostealer relevant to crypto users is that one component of this malware is that it has a crypto mining module, a coinminer.



Quote
What is CoinMiner malware?

Coinminers (also called cryptocurrency miners) are programs that generate Bitcoin, Monero, Ethereum, or other cryptocurrencies that are surging in popularity. When intentionally run for one's own benefit, they may prove a valuable source of income.

However, malware authors have created threats and viruses which use commonly-available mining software to take advantage of someone else's computing resources (CPU, GPU, RAM, network bandwidth, and power), without their knowledge or consent (i.e. cryptojacking).

And just like the rest of authored malware, they find the weakest link - which is to spread them your email and supposedly software updates.



- https://www.zdnet.com/article/chaes-malware-strikes-customers-of-latin-americas-largest-e-commerce-platform/
- https://www.cybereason.com/blog/novel-chaes-malware-underscores-heightened-e-commerce-risk-this-holiday-season
- https://support.norton.com/sp/en/us/home/current/solutions/v125881893
- https://www.cybereason.com/hubfs/dam/collateral/reports/11-2020-Chaes-e-commerce-malware-research.pdf
1715199470
Hero Member
*
Offline Offline

Posts: 1715199470

View Profile Personal Message (Offline)

Ignore
1715199470
Reply with quote  #2

1715199470
Report to moderator
1715199470
Hero Member
*
Offline Offline

Posts: 1715199470

View Profile Personal Message (Offline)

Ignore
1715199470
Reply with quote  #2

1715199470
Report to moderator
1715199470
Hero Member
*
Offline Offline

Posts: 1715199470

View Profile Personal Message (Offline)

Ignore
1715199470
Reply with quote  #2

1715199470
Report to moderator
Each block is stacked on top of the previous one. Adding another block to the top makes all lower blocks more difficult to remove: there is more "weight" above each block. A transaction in a block 6 blocks deep (6 confirmations) will be very difficult to remove.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
cryptomaniac_xxx
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 566



View Profile
November 22, 2020, 06:50:29 AM
 #2

What's up with LATAM lately?, Ghimob: New banking trojan that also targets crypto exchange apps

There seems to be an uptick of malware activities in that region, moving from the traditional banking trojan, info stealer to crypto related malware? And it could have home grown or group of cyber threat actors targeting LATAM for their criminal activities.

.
 airbet 
██
██
██
██
██
██
██
██
██
██
██
██
██
 .

▄████▄▄▄██████▄
███████████████
███████████████
███████▀▀▀▀████
██████████████
▀███▀███████▄██
██████████▄███
██████████████
███████████████
███████████████
██████████████
█████▐████████
██████▀███████▀
▄███████████████▄
████████████████
█░██████████████
████████████████
████████████████
█████████████████
█████████████████
███████░█░███████
████████████████
█████████████████
██████████████░█
████████████████
▀███████████████▀
.
.
.
.
██▄▄▄
████████▄▄
██████▀▀████▄
██████▄░░████▄
██████████████
████████░░▀███▌
░████████▄▄████
██████████████▌
███░░░█████████
█████████░░░██▀
░░░███████████▀
██████░░░██▀
░░▀▀███▀

   
|.
....
██
██
██
██
██
██
██
██
██
██
██
██
██
.
 PLAY NOW 
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!