Tag: crypto
-
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data collection rather than a single targeted objective. Its collection scope includes macOS Keychain files, Safari…
-
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them.The way these wallets talk to websites and blockchain servers can tie a person’s separate addresses together and let outsiders follow them from…
-
New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/macos-malware-apple-crash-reporter/
-
Häftling droht Strafverlängerung: Krypto-Diebstahl aus der Gefängniszelle
Tags: cryptoEin bereits wegen Geldwäsche verurteilter Mann soll aus der Haft heraus mit mehreren Komplizen beschlagnahmte Krypto-Coins gestohlen und gewaschen haben. First seen on golem.de Jump to article: www.golem.de/news/vom-gefaengnis-aus-haeftling-soll-sich-an-krypto-diebstahl-beteiligt-haben-2607-210839.html
-
Vom Gefängnis aus: Häftling soll sich an Krypto-Diebstahl beteiligt haben
Tags: cryptoEin bereits wegen Geldwäsche verurteilter Mann soll aus der Haft heraus mit mehreren Komplizen beschlagnahmte Krypto-Coins gestohlen und gewaschen haben. First seen on golem.de Jump to article: www.golem.de/news/vom-gefaengnis-aus-haeftling-soll-sich-an-krypto-diebstahl-beteiligt-haben-2607-210839.html
-
SpaceX and Starlink X Accounts Hacked in Crypto Scam
Tags: cryptoReportedly compromised SpaceX and Starlink X accounts were used to promote a fraudulent cryptocurrency scam. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/spacex-and-starlink-x-accounts-hacked-in-crypto-scam/
-
New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple’s crash-reporting tool to steal credentials, keychain data, and crypto wallets. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/
-
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers. First seen on hackread.com Jump to article: hackread.com/siggen-backdoor-windows-developers-visual-studio-projects/
-
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers. First seen on hackread.com Jump to article: hackread.com/siggen-backdoor-windows-developers-visual-studio-projects/
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
Inmate charged with stealing seized cryptocurrency while serving prison sentence
Tags: cryptoFirst seen on scworld.com Jump to article: www.scworld.com/brief/inmate-charged-with-stealing-seized-cryptocurrency-while-serving-prison-sentence
-
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed First seen…
-
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
Cyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-campaign-vidar-stealer-monero/
-
Malicious websites trick AI agents into crypto payments, context poisoning
First seen on scworld.com Jump to article: www.scworld.com/news/malicious-websites-trick-ai-agents-into-crypto-payments-context-poisoning
-
Keyfactor Lands $1B to Expand Crypto Trust Platform
CEO Jordan Rackie Cites AI, Regulation and Quantum Computing as Big Demand Drivers. Summit Partners invested $1 billion in Keyfactor as enterprises accelerate post-quantum cryptography planning, AI-driven identity management and cryptographic modernization, giving the trust infrastructure provider capital to expand R&D, global operations and enterprise security capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/keyfactor-lands-1b-to-expand-crypto-trust-platform-a-32163
-
Attackers vote themselves $20 million in BONK cryptocurrency
BonkDAO said in a social media post that it was the victim of a “malicious governance proposal,” or an attack in which holders of a large amount of BONK used that leverage to vote more coins into their wallets. First seen on therecord.media Jump to article: therecord.media/attackers-vote-themselves-20-million-bonk-crypto
-
Vect and TeamPCP Cybercrime Groups Link for Ransomware Hits
Supply-Chain Victims Also at Risk From Poorly Coded, Data-Shredding Crypto-Locker. Recently announced tie-ups between ransomware group Vect, supply-chain attack specialists TeamPCP and data-leak stalwart Lapsus$ show cybercriminals continuing their quest to monetize their attacks and develop new profit streams. But not all has been smooth sailing. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vect-teampcp-cybercrime-groups-link-for-ransomware-hits-a-32159
-
Indirect Prompt Injection in Web Content Targets AI Agents
Zscaler found sites hiding prompt-injection text to manipulate AI agents into crypto payments First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/indirect-prompt-injection-web/
-
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards.The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and…
-
GTA 6 Early Access: Fake-Webseiten locken Fans in Krypto-Falle
GTA 6 Early Access gibt es offiziell nicht. Fake-Webseiten locken mit VIP-Zugängen, Malware und Krypto-Betrug. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/gaming/gta-6-early-access-krypto-falle-331077.html
-
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments
Hackers are now weaponizing documentation and site metadata to mislead autonomous AI agents into executing cryptocurrency payments. The attack leverages indirect prompt injection (IPI): malicious instructions hidden in web content and structured data that influence an AI agent’s reasoning during automated tasks. By combining SEO poisoning, JSON”‘LD abuse and CSS concealment, attackers create seemingly legitimate…
-
Cryptohack Roundup: Chinese Fraudster Gets 30 Years in Prison
Also: Hollywood Director Jailed for $11M Fraud. This week, a Chinese fraudster got 30 years, Hollywood director jailed for $11M fraud, Florida crypto scam plea, China jailed five in FX case, South Korea fines Bithumb, Thailand hunted mining suspect, Poland arrested SIM swappers, Emurgo planned recovery, South Korea targeted manipulators. First seen on govinfosecurity.com Jump…
-
Quantum Breakthroughs Compress Post-Quantum Computing Timeline
Microsoft, Google and AWS cite major gains in reliability and error correction.. Rapid advances in quantum hardware, AI-assisted error correction and fault-tolerant architectures from Microsoft, Google and Amazon are accelerating expectations for practical quantum computing, increasing pressure on organizations to adopt crypto-agility and prepare for post-quantum encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quantum-breakthroughs-compress-post-quantum-computing-timeline-a-32137
-
Fake “Google Notes” Browser Extension Caught Swapping Crypto Wallet Addresses
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users. First seen on hackread.com Jump to article: hackread.com/fake-google-notes-browser-extension-swap-crypto-wallets/
-
Malicious Google Notes Extension Swaps Crypto Wallet Addresses During Transactions
Technically sophisticated campaign delivering a malicious Chromium extension that silently swaps cryptocurrency wallet addresses during transactions. Delivered via unsigned installers observed in both .NET and Golang variants access, the payload masquerades as a minimalist “Google Notes” browser extension. Once deployed, the extension acts as a clipboard-aware crypto clipper: it monitors copy-and-paste activity, recognizes wallet addresses…
-
Silent Swap Uses Fake Chrome Extension to Steal Crypto
Silent Swap uses a fake Chrome extension to silently replace cryptocurrency wallet addresses and steal digital assets. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/silent-swap-uses-fake-chrome-extension-to-steal-crypto/
-
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Tags: ai, attack, crypto, cve, data-breach, endpoint, exploit, intelligence, rce, remote-code-execution, threat, vulnerabilityThreat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner.The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) First seen on…
-
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction.The cryptocurrency clipper activity has been codenamed Silent Swap by McAfee Labs.”The campaign is delivered through unsigned installers observed in both .NET and Golang variants that First seen on thehackernews.com…

