Bitcoin Forum
May 10, 2024, 01:28:55 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: New Malware Trend: Cyber Hackers Target Crypto Investors  (Read 102 times)
Serverandcloud (OP)
Newbie
*
Offline Offline

Activity: 19
Merit: 0


View Profile WWW
April 19, 2023, 02:14:03 PM
 #1

Hi, Bitcointalkers,
We publish this unsolicited material for those who regularly use cryptocurrency for business transactions. As Solar Communications’ main business goal is information security for web hosting services, we are constantly monitoring for new online frauds and reacting sharply to new attempts by scammers to come up with schemes to steal from the Internet.

Two new malware threats have emerged, targeting cryptocurrency investors with phishing emails to steal their funds. Anti-malware software Malwarebytes reports that the MortalKombat ransomware and a GO variant of the Laplas Clipper malware are being deployed in campaigns aimed at stealing cryptocurrency. The phishing emails are predominantly targeting victims in the United States, with a smaller percentage in the United Kingdom, Turkey, and the Philippines. The criminals are scanning the internet for potential targets with an exposed remote desktop protocol (RDP) port 3389.

The campaign begins with a phishing email, which kicks off a multi-stage attack chain where the actor delivers either malware or ransomware and then deletes evidence of malicious files. The phishing email comes with a malicious ZIP file that contains a BAT loader script, which downloads another malicious ZIP file when a victim opens it. The malware inflates the victim’s device and executes the payload, which is either the GO variant of Laplas Clipper malware or MortalKombat ransomware.

The criminals usually impersonate CoinPayments, a legitimate global cryptocurrency payment gateway, in their phishing emails. To make the emails look even more legitimate, they have a spoofed sender, “noreply[at]CoinPayments[.]net”, and the email subject “[CoinPayments[.]net] Payment Timed Out.” A malicious ZIP file is attached with a filename resembling a transaction ID mentioned in the email body, which allures the victim to unzip the malicious attachment to view the contents, which is a malicious BAT loader.

Ransomware and cybersecurity attacks continue to increase. However, victims have been increasingly unwilling to pay attackers their demands, according to a recent report by Chainalysis, which revealed that ransomware revenues for attackers plummeted 40% last year. North Korean hacking groups account for a significant portion of illicit cyber activities. South Korean and United States intelligence agencies recently warned that Pyongyang-based hackers are trying to hit “major international institutions” with ransomware attacks. In December 2022, Kaspersky also revealed that BlueNoroff, a subgroup of the North Korean state-sponsored hacking group Lazarus, is impersonating venture capitalists looking to invest in crypto startups in a new phishing method.

What do you think about it?
1715304535
Hero Member
*
Offline Offline

Posts: 1715304535

View Profile Personal Message (Offline)

Ignore
1715304535
Reply with quote  #2

1715304535
Report to moderator
1715304535
Hero Member
*
Offline Offline

Posts: 1715304535

View Profile Personal Message (Offline)

Ignore
1715304535
Reply with quote  #2

1715304535
Report to moderator
1715304535
Hero Member
*
Offline Offline

Posts: 1715304535

View Profile Personal Message (Offline)

Ignore
1715304535
Reply with quote  #2

1715304535
Report to moderator
"Your bitcoin is secured in a way that is physically impossible for others to access, no matter for what reason, no matter how good the excuse, no matter a majority of miners, no matter what." -- Greg Maxwell
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Orpichukwu
Sr. Member
****
Offline Offline

Activity: 476
Merit: 309



View Profile
April 19, 2023, 02:31:21 PM
 #2

https://bitcointalk.org/index.php?topic=5449451.msg62116539#msg62116539
Will I call this plagiarism or you having two different account and making same post with the difference accounts.


.
Duelbits
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
puloweh555
Sr. Member
****
Offline Offline

Activity: 490
Merit: 302


View Profile
April 19, 2023, 11:21:31 PM
Merited by vapourminer (2)
 #3

Maybe you will be understood by DT because you are still a beginner. But as a beginner you also have to read the forum rules before making a post. You should know that plagiarism is strictly prohibited in this forum and should be avoided completely now and in the future. You should always provide the correct source when you quote or use information from other sources in your posts and respect the intellectual property rights of others. Plagiarism is detrimental to the trust and integrity of this forum.


Original: https://lowendtalk.com/discussion/185808/new-malware-trend-cyber-hackers-target-crypto-investors
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!