Tag: crypto
-
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift from purely digital exploitation to coordinated physical coercion campaigns. Recent threat intelligence indicates that attackers are systematically profiling cryptocurrency holders using publicly available data across platforms such as Instagram, TikTok, X,…
-
SparkKitty Monitors Mobile Photo Galleries and Exfiltrates Sensitive Images to C2 Servers
SparkKitty is a cross”‘platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker”‘controlled C2 servers on both Android and iOS. Built as an apparent successor to SparkCat, the malware is tuned to hunt cryptocurrency wallet seed phrases, but its indiscriminate photo theft dramatically…
-
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript…
-
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log archive generated by infostealer malware that silently harvests browser-saved passwords, session cookies, cryptocurrency wallet data,…
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Tags: business, communications, credentials, crypto, cyber, data, email, infection, malware, phishing, powershellA sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake…
-
‘Wrench’ attacks against crypto holders appear to be on the rise
There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say. First seen on therecord.media Jump to article: therecord.media/wrench-attacks-against-cryptocurrency-holders
-
‘Wrench’ attacks against crypto holders appear to be on the rise
There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say. First seen on therecord.media Jump to article: therecord.media/wrench-attacks-against-cryptocurrency-holders
-
‘Wrench’ attacks against crypto holders appear to be on the rise
There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say. First seen on therecord.media Jump to article: therecord.media/wrench-attacks-against-cryptocurrency-holders
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea,…
-
Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack
Thailand’s cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company’s disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds. First seen on thecyberexpress.com Jump to…
-
Cryptohack Roundup: BitMex Shuts Down
Also: BitShine Fraudster Jailed, Upbit Sanctions Begin. This week, BitMex to shutter, BitShine fraudster imprisoned, three sentenced in 4 million-pound scam, Upbit sanctions begin, Allbridge lost $1.65 million, HTX caught rotating wallets, the United States to seize $25 million in crypto and Celsius founders reached a settlement with the U.S. FTC. First seen on govinfosecurity.com…
-
What Is Cryptocurrency and How Does It Actually Work?
Learn how cryptocurrency works, from blockchains and wallets to private keys, custody, and secure transactions, with practical security tips. for confident use. First seen on hackread.com Jump to article: hackread.com/what-is-cryptocurrency-how-it-work/
-
Pixelgenaue Fälschungen täuschen Login-Benachrichtigungen von X vor
Ein neuer X-Phishing-Scam kopiert echte Login-Benachrichtigungen bis ins letzte Pixel, um Konten zu kapern und Passwörter zu stehlen. Gekaperte Konten werden für Krypto-Betrug und Phishing genutzt. Die Phishing-E-Mails warnen die Empfänger vor einem Login ‘von einem neuen Gerät” an einem Ort, an dem sie sich noch nie aufgehalten haben. Die E-Mails enthalten das X-Logo, die…
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
South Korea proposes new rules for seizing self-custody crypto wallets
First seen on scworld.com Jump to article: www.scworld.com/brief/south-korea-proposes-new-rules-for-seizing-self-custody-crypto-wallets
-
The Next Crypto Fraud Frontier May Be Space
As Space Investment Grows, Cybercriminals May Target Trust, Hype and Opacity The next frontier of cyber-enabled fraud may involve tokenized space assets, fabricated aerospace claims and orbital projects that were never built. As commercial space investment grows, distinguishing innovation from manufactured credibility can become more difficult. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/next-crypto-fraud-frontier-may-be-space-p-4156
-
Kenya probes hack of president’s website after bitcoin ransom demand
The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid. First seen on therecord.media Jump to article: therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand
-
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly…
-
Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/
-
Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets
Fileless stealer and PureRAT operators are abusing a WebDAV”‘backed “malware delivery lab” to raid browser passwords, Telegram sessions, and cryptocurrency wallets in a campaign that blends fileless info”‘stealing with a modular .NET RAT. The incident began with an MDR alert tied to a user executing content retrieved from a WebDAV server via rundll32.exe, with telemetry…
-
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/
-
FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
FBI agents arrested a Florida man accused of spreading Steam game malware that stole $220,000 in crypto, including $32,000 from a terminally ill cancer patient. First seen on hackread.com Jump to article: hackread.com/fbi-arrests-florida-man-steam-crypto-theft-case/
-
MacOS malware hijacks Telegram sessions, targets crypto wallets
First seen on scworld.com Jump to article: www.scworld.com/brief/macos-malware-hijacks-telegram-sessions-targets-crypto-wallets
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots AsyncAPI npm organization compromised, 2M weekly downloads affected OkoBot: new sophisticated malware framework targets cryptocurrency users […]…
-
FBI arrests man accused of using Steam games to drain victims’ crypto wallets
Prosecutors accused 21-year-old student Zyaire Wilkins of publishing on Steam several fake video games that contained malware, infecting thousands of victims, and stealing crypto from some of them. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/17/fbi-arrests-man-accused-of-using-steam-games-to-drain-victims-crypto-wallets/
-
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed “Starland RAT,” alongside a stealthy in-memory PowerShell implant known as the “WLDR agent.” The operation targets users across the United States and parts of Europe, with a primary focus on…
-
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.”Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet…
-
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/
-
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps. First seen on hackread.com Jump to article: hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/

