Bitcoin Forum
May 03, 2024, 07:52:32 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Read]:New ZingoStealer infostealer targets crypto and crypto related wallets  (Read 90 times)
btc_angela (OP)
Hero Member
*****
Offline Offline

Activity: 2604
Merit: 542



View Profile
April 15, 2022, 10:44:14 AM
Last edit: April 15, 2022, 12:56:34 PM by btc_angela
Merited by DdmrDdmr (2), Lafu (1), ABCbits (1), dkbit98 (1)
 #1

Another new info stealer is on the wild, known as ZingoStealer. And this is being released as free to members of the Haskers Gang community.

But the mode of distribution is the same: (1) code generators and cracks (2) game cheat. They even had a Youtube as disguise for a game "Counter-Strike: Global Offensive" (CSGO).



Target browsers:

Quote
Google Chrome
Mozilla Firefox
Opera
Opera GX

And what makes this dangerous is that the malware searches for extensions of crypto wallets such as:

Quote
TronLink
Nifty Wallet
MetaMask
MathWallet
Coinbase Wallet
Binance Wallet
Brave Wallet
Guarda
EQUAL Wallet
BitApp Wallet
iWallet
Wombat - Gaming Wallet

And it also searches %APPDATA%\Local and %APPDATA%\Roaming for cryptocurrency wallet data associated with the following cryptocurrencies.

Quote
Zcash
Armory
Bytecoin
Jaxx Liberty
Exodus
Ethereum
Electrum
Atomic
Guarda
Coinomi

It also queries the registry (HKCU\SOFTWARE\<VALUE>) to identify settings associated with additional cryptocurrency wallets, including:

Quote
Bitcoin
Dash
Litecoin

So overall, this malware targets cryptocurrency wallets so it's a very dangerous information stealer that is going in the wild right now.

Again as I have said before, it's better to have a different machine for your crypto related activities so that the chances of you getting this kind of malware might be lessen.

For a detailed technical explanation you can read it here: https://blog.talosintelligence.com/2022/04/haskers-gang-zingostealer.html

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
1714765952
Hero Member
*
Offline Offline

Posts: 1714765952

View Profile Personal Message (Offline)

Ignore
1714765952
Reply with quote  #2

1714765952
Report to moderator
Activity + Trust + Earned Merit == The Most Recognized Users on Bitcointalk
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714765952
Hero Member
*
Offline Offline

Posts: 1714765952

View Profile Personal Message (Offline)

Ignore
1714765952
Reply with quote  #2

1714765952
Report to moderator
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7117



View Profile WWW
April 15, 2022, 11:59:38 AM
Merited by btc_angela (1)
 #2

This malware again targets only wiNd0ws users because it is in format of loader.exe file, so anyone running Linux or Max should be just fine and protected from this.
However, Zingo is mostly affecting gamers and users who are using Adobe applications, and most of them are sadly using wiNd0ws operating system.

I would suggest anyone who is dealing with Biitcoin to buy good old cheap laptop (Thinkpad would be a good choice) and install Linux operating system.
Use this computer only for crypto and other important stuff, that will be separate from gaming and regular everyday browsing.
This way you are drastically reducing the risk of infecting your system with this and any other malware.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Lafu
Legendary
*
Online Online

Activity: 2968
Merit: 3043



View Profile
April 15, 2022, 12:09:50 PM
Merited by btc_angela (1)
 #3

Thats why you should be not trust any kind of crack or keygen program that you can download , cracks and stuff should be not used at all .
Its a knowen thing that the most cracks , keygen or third party cheat programs can and have that kind or any of malware in it.
Found another article here about it : https://www.bleepingcomputer.com/news/security/new-zingostealer-infostealer-drops-more-malware-cryptominers/

coupable
Hero Member
*****
Offline Offline

Activity: 2338
Merit: 757


View Profile
April 15, 2022, 08:16:55 PM
 #4

I would suggest anyone who is dealing with Biitcoin to buy good old cheap laptop (Thinkpad would be a good choice) and install Linux operating system.
Use this computer only for crypto and other important stuff, that will be separate from gaming and regular everyday browsing.
This way you are drastically reducing the risk of infecting your system with this and any other malware.
You know that not many people can deal with Linux. As far as this system carries features for protection and privacy, it is not available to everyone after they are accustomed using Windows.
Perhaps it should work if there exist a Linux version with personalized features without the need to use programming commands .
BitMaxz
Legendary
*
Online Online

Activity: 3248
Merit: 2955


Block halving is coming.


View Profile WWW
April 15, 2022, 10:55:46 PM
 #5

It seems my kid's PC has this software called loader.exe but not for CSGO mostly my kids are looking for generators and cheats or hacks for Roblox so I think my kid's PC is already infected with that malware. Their PC has full of malware and ads which are very annoying when using their PC.


That is why not recommended to download any game hacks or generators or mostly patcher or loader to bypass playing paid games.
I have experienced wrapping software before that includes silent install and put a readme notes under the rar file and tell them to disable antivirus before you install the software or game. Someone taught me how to do it and monetize them to earn from CPA. So I know how this works and how they can infect target victims without any good antivirus and Malwarebytes protection you can be easily targeted by this. If they are going to target my PC it's impossible for them that they can hack or get any information from my PC because all of them are fake information.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Kemarit
Legendary
*
Offline Offline

Activity: 3080
Merit: 1352



View Profile
April 16, 2022, 11:01:47 AM
 #6

This malware again targets only wiNd0ws users because it is in format of loader.exe file, so anyone running Linux or Max should be just fine and protected from this.
However, Zingo is mostly affecting gamers and users who are using Adobe applications, and most of them are sadly using wiNd0ws operating system.

I would suggest anyone who is dealing with Biitcoin to buy good old cheap laptop (Thinkpad would be a good choice) and install Linux operating system.
Use this computer only for crypto and other important stuff, that will be separate from gaming and regular everyday browsing.
This way you are drastically reducing the risk of infecting your system with this and any other malware.

I have one laptop that I used exactly as this, with Linux OS for my crypto related stuff. Good choice although still has flaws but at least I'm not going to be prone from this kind of attacks because you will never know that you might silently install some malware in your PC specially Windows type based OS.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
aysg76
Legendary
*
Offline Offline

Activity: 1960
Merit: 2124



View Profile
April 16, 2022, 04:51:35 PM
 #7

This malware again targets only wiNd0ws users because it is in format of loader.exe file, so anyone running Linux or Max should be just fine and protected from this.
However, Zingo is mostly affecting gamers and users who are using Adobe applications, and most of them are sadly using wiNd0ws operating system.

I would suggest anyone who is dealing with Biitcoin to buy good old cheap laptop (Thinkpad would be a good choice) and install Linux operating system.
Use this computer only for crypto and other important stuff, that will be separate from gaming and regular everyday browsing.
This way you are drastically reducing the risk of infecting your system with this and any other malware.
Linux is far more safer in comparison with windows in security perspective and most of the scams in crypto are done through windows malware.The reason behind this is most of the users are operating windows in their system and it's easy to target.

Most professional use Linux although the main security lies in your hand but the operating system like Linux can be configured and twicked according to your convenience and provide you more safety.

There was one thread in B&H section for this discussion few days back and members agreed to the fact that linux is comparitavely better.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!