GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser Crypto Data

A new iteration of the GlassWorm campaign has been identified by cybersecurity researchers. It offers a multi-stage framework that can install a remote access trojan (RAT) that launches an information-stealing Google Chrome extension that poses as an offline version of Google Docs.

According to a paper released last week by Aikido security researcher Ilyas Makari, it records keystrokes, dumps cookies and session tokens, takes images, and receives commands from a C2 server concealed in a Solana blockchain document.

A persistent effort known as “GlassWorm” gains an initial footing through rogue packages released on GitHub, PyPI, npm, and the Open VSX marketplace. Furthermore, it is known that the operators hack project maintainers’ accounts in order to distribute malicious updates.

The assaults employ Solana transactions as a dead drop resolver to retrieve the command-and-control (C2) server read more about GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser Crypto Data.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *