Bitcoin Forum
May 06, 2024, 03:14:14 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: New stealer that steals data from crypto wallets and 2FA plugins  (Read 220 times)
lovesmayfamilis (OP)
Legendary
*
Offline Offline

Activity: 2086
Merit: 4288


✿♥‿♥✿


View Profile
February 02, 2022, 12:38:23 PM
Last edit: February 02, 2022, 12:50:00 PM by lovesmayfamilis
Merited by Symmetrick (5), DdmrDdmr (3), NeuroticFish (2), Lucius (1), dkbit98 (1), Rikafip (1), Charles-Tim (1), AhmadM (1)
 #1

Russian hacker forums and social media have reported a malware called Mars Stealer that can steal your cryptocurrency. As they say in the news, the new stealer is an improved version of another malware called. Oski Stealer.

https://www.bleepingcomputer.com/news/security/powerful-new-oski-variant-mars-stealer-grabbing-2fas-and-crypto/

Quote
Mars Stealer uses a custom grabber that retrieves its configuration from the C2 and then proceeds to target the following applications:

Internet apps: Google Chrome, Internet Explorer, Microsoft Edge (Chromium Version), Kometa, Amigo, Torch, Orbitium, Comodo Dragon, Nichrome, Maxxthon5, Maxxthon6, Sputnik Browser, Epic Privacy Browser, Vivaldi, CocCoc, Uran Browser, QIP Surf, Cent Browser, Elements Browser, TorBro Browser, CryptoTab Browser, Brave, Opera Stable, Opera GX, Opera Neon, Firefox, SlimBrowser, PaleMoon, Waterfox, CyberFox, BlackHawk, IceCat, K-Meleon, Thunderbird.

2FA apps: Authenticator, Authy, EOS Authenticator, GAuth Authenticator, Trezor Password Manager.

Crypto extensions: TronLink, MetaMask, Binance Chain Wallet, Yoroi, Nifty Wallet, Math Wallet, Coinbase Wallet, Guarda, EQUAL Wallet, Jaox Liberty, BitAppWllet, iWallet, Wombat, MEW CX, Guild Wallet, Saturn Wallet, Ronin Wallet, Neoline, Clover Wallet, Liquality Wallet, Terra Station, Keplr, Sollet, Auro Wallet, Polymesh Wallet, ICONex, Nabox Wallet, KHC, Temple, TezBox Cyano Wallet, Byone, OneKey, Leaf Wallet, DAppPlay, BitClip, Steem Keychain, Nash Extension, Hycon Lite Client, ZilPay, Coin98 Wallet.

Crypto wallets: Bitcoin Core and all derivatives (Dogecoin, Zcash, DashCore, LiteCoin, etc), Ethereum, Electrum, Electrum LTC, Exodus, Electron Cash, MultiDoge, JAXX, Atomic, Binance, Coinomi.

Again, the security rules include limiting the use of various kinds of cracks, the use of torrent servers, the opening of unwanted emails containing archives. And of course, regularly updating your existing system and antivirus software.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
1714965254
Hero Member
*
Offline Offline

Posts: 1714965254

View Profile Personal Message (Offline)

Ignore
1714965254
Reply with quote  #2

1714965254
Report to moderator
"This isn't the kind of software where we can leave so many unresolved bugs that we need a tracker for them." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714965254
Hero Member
*
Offline Offline

Posts: 1714965254

View Profile Personal Message (Offline)

Ignore
1714965254
Reply with quote  #2

1714965254
Report to moderator
bitmover
Legendary
*
Offline Offline

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
February 02, 2022, 01:38:46 PM
 #2

I think people overestimate 2FA security.

Funds in exchanges are always at risky, using 2FA is good but it is not 100%.

For wallets such as coinomi, electrum, etc, 2FA is basically useless because the private key is all that you need to access your funds.

Nothing is better than keeping the private keys of your wallet in a piece of paper, in an offline environment.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5637


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
February 02, 2022, 03:26:04 PM
 #3

I think people overestimate 2FA security.
Funds in exchanges are always at risky, using 2FA is good but it is not 100%

There is a risk for anyone who does not have complete control over their private keys, but I agree that 2FA may give some the impression that their funds are more secure when it comes to online wallets. It is a well-known fact that hackers target accounts that hold large amounts, and when they manage to get hold of passwords, all they need to do is make a SIM swap and hack the account.

For wallets such as coinomi, electrum, etc, 2FA is basically useless because the private key is all that you need to access your funds.

I would not agree that it is completely useless because in some cases it can prevent a hacker from hacking a wallet. TrustedCoin is a service available through Electrum and it is impossible to make a transaction without being confirmed by their server - so even though it is a paid option, I believe it has saved many users from being hacked.

Nothing is better than keeping the private keys of your wallet in a piece of paper, in an offline environment.

Of course, for long-term storage, a properly made paper wallet is certainly a very good option, but the problem is all those hot wallets that exist and are vulnerable to various attacks.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Charles-Tim
Legendary
*
Offline Offline

Activity: 1540
Merit: 4845



View Profile
February 02, 2022, 03:59:30 PM
 #4

I think people overestimate 2FA security.
Yes, that is why some people will have 2FA app on the device they use for wallet, exchange ect. The best is to have 2FA app on another device different from the one used to access wallets and exchanges.

For wallets such as coinomi, electrum, etc, 2FA is basically useless because the private key is all that you need to access your funds.
I have noticed custodial wallets and exchanges are the ones having 2FA, most noncustododial wallet do not have it. Although, Electrum supports 2FA.

but I agree that 2FA may give some the impression that their funds are more secure when it comes to online wallets. It is a well-known fact that hackers target accounts that hold large amounts, and when they manage to get hold of passwords, all they need to do is make a SIM swap and hack the account.
Never mind this, 2FA are not the same as sim authentication, I will like correction if I am wrong. 2FA like hardware authenticators and apps like Aegis and andOTP, never mind me I did not mention Authy, Google and Windows authenticator because I can not recommend them. 2FA is misused by many people, people should not also 100% rely on it, it can be a hardware but if app, it should be on another device. Sim authentication is the worst among the means of authentication.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Husires
Legendary
*
Offline Offline

Activity: 1596
Merit: 1285



View Profile WWW
February 02, 2022, 04:02:37 PM
 #5

How can this stolen data affect the protection of users? They are privacy statements rather than security holes.
Moreover, Mars Stealer will capture and send the following basic information to the C2:

Quote
IP and country
Working path to EXE file
Local time and time zone
Language system
Language keyboard layout
Notebook or desktop
Processor model
Computer name
User name
Domain computer name
Machine ID
GUID
Installed software and their versions

quote source https://www.bleepingcomputer.com/news/security/powerful-new-oski-variant-mars-stealer-grabbing-2fas-and-crypto/

It targets the user's personal activity such as politicians, social attacks, people tracking and other data.
Data is important to marketers as well, but promoting it as Russian or automatically shutting down when it finds a Russian ID means nothing.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
jerry0
Full Member
***
Offline Offline

Activity: 1736
Merit: 186


View Profile
February 05, 2022, 06:26:50 PM
 #6

So if you have basic windows defender and malwarebytes on laptop... its completely useless against it?


What about paid antivirus like kaspersky or norton?
WellRozey
Newbie
*
Offline Offline

Activity: 23
Merit: 21


View Profile
February 06, 2022, 03:39:11 PM
 #7

I think people overestimate 2FA security.

Funds in exchanges are always at risky, using 2FA is good but it is not 100%.

For wallets such as coinomi, electrum, etc, 2FA is basically useless because the private key is all that you need to access your funds.

Nothing is better than keeping the private keys of your wallet in a piece of paper, in an offline environment.
Not just coinomi and electrum wallet, every single wallets that have it's 2FA security activated only guide the device that's been activated on, if your private key leaks somehow your funds can be moved out successfully.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5637


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
February 06, 2022, 04:00:53 PM
 #8

So if you have basic windows defender and malwarebytes on laptop... its completely useless against it?

I can't say exactly what would happen if an attempt occurred to infect your computer, but if the security software you have on your computer has antivirus definitions of a specific threat in its database, then your computer should be protected. As described in the OP, the first line of defense is to watch what you do online, which means that you refrain from downloading risky content and clicking on links from e-mail or social networks.

What about paid antivirus like kaspersky or norton?

For me personally, paid security solutions are a better choice - and if you choose Norton you won't regret it - it protects me for years, and for now I can't complain.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Porfirii
Legendary
*
Offline Offline

Activity: 1778
Merit: 2074


The Alliance Of Bitcointalk Translators - ENG>SPA


View Profile
February 06, 2022, 04:30:38 PM
 #9

Nothing is better than keeping the private keys of your wallet in a piece of paper, in an offline environment.

As this is "Beginners & Help" I will repeat this idea from bitmover (repetition is great as rhetoric).

In the Spanish board we are talking about the planned obsolescence of hardware wallets and using them as a safe for a long time, and one idea in the thread is that the piece of paper is the really valuable thing.

So kids, think about using more pen and paper.

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
lovesmayfamilis (OP)
Legendary
*
Offline Offline

Activity: 2086
Merit: 4288


✿♥‿♥✿


View Profile
February 06, 2022, 04:38:47 PM
 #10

So if you have basic windows defender and malwarebytes on laptop... its completely useless against it?


What about paid antivirus like kaspersky or norton?

How to remove Mars stealer-type malware from the operating system?

I found an article on removing this stealer. If you doubt the presence of this virus on your computer, read the tips that are recommended for cleaning your computer.
But since I myself do not use the Windows system, I cannot write a full review about this antivirus. Read all the features of the program, and of course act at your own peril and risk.
Developer Tomas Meskauskas - expert security researcher, professional malware analyst.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7129



View Profile WWW
February 06, 2022, 07:22:06 PM
 #11

I am not sure if this malware is affecting Linux OS, but instead of going with all that mambo jumbo in Windows and be scared of next new malware thing, you could simply switch to Linux.
If you need to use wNd0ws for some games etc than just use it for that purpose only on separate machine, or without internet connection.
Looking at the link posted by lovesmayfamilis it looks like Mars stealer is build.exe file that you have to click and install, so I would be careful opening anything from emails, sms or in telegram.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Welsh
Staff
Legendary
*
Offline Offline

Activity: 3262
Merit: 4110


View Profile
May 16, 2022, 09:05:19 PM
 #12

I am not sure if this malware is affecting Linux OS, but instead of going with all that mambo jumbo in Windows and be scared of next new malware thing, you could simply switch to Linux.
If you need to use wNd0ws for some games etc than just use it for that purpose only on separate machine, or without internet connection.
Looking at the link posted by lovesmayfamilis it looks like Mars stealer is build.exe file that you have to click and install, so I would be careful opening anything from emails, sms or in telegram.
Windows isn't something so inseucre that simply connecting to the internet compromises you. I mean, technically any machine connected to the internet or using Wifi private or not could be compromised, but for a gaming machine, personally the threat level is rather low.

Instead, the better advice is to just move your Bitcoin to a offline machine, and then use a hardware wallet for sending funds. That's probably the best approach to the situation. This particular software requires you to execute it anyway, so unless you're downloading dodgy stuff, you aren't likely to be effected.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!