Tag: cryptocurrency wallets

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
News

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

A new set of malicious npm packages that are intended to steal sensitive data and cryptocurrency wallets has been discovered by cybersecurity researchers. ReversingLabs is monitoring the behavior as part of the Ghost campaign. Below is a list of the packages that have been identified, all of which were released by the user mikilanjillo: react-performance-suite react-state-optimizer-core react-fast-utilsa ai-fast-auto-trader pkgnewfefame1 coinbase-desktop-sdk According to a report shared with The Hacker News by Lucija Valentić, a software threat researcher at ReversingLabs, the packages themselves are phishing for the sudo password that is used to execute the final stage. They are attempting to conceal their true functionality and evade detection by displaying pho...
Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Stealing User Assets
News

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Stealing User Assets

Researchers studying cybersecurity have discovered more than 40 malicious Mozilla Firefox browser extensions that are intended to steal bitcoin wallet secrets and jeopardize users' digital assets. The wallet tools from popular platforms including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox are impersonated by these extensions. Yuval Ronen, a Koi Security researcher, stated. According to reports, the extensive effort has been going on since at least April 2025, and as recently as last week, fresh extensions were added to the Firefox Add-ons market. By adding hundreds of 5-star ratings that far exceed the total number of active installations, the discovered extensions have been proven to artificially boost their...
GrassCall malware campaign drains crypto wallets via fake job interviews
News

GrassCall malware campaign drains crypto wallets via fake job interviews

Using a fraudulent "GrassCall" meeting software that installs information-stealing malware to steal cryptocurrency wallets, a recent social engineering attack used fictitious job interviews to target job searchers in the Web3 domain. The hoax has affected hundreds of victims, some of whom claim that the attacks have depleted their wallets. For the purpose of discussing the attack and assisting people affected in removing the malware infestations from Mac and Windows systems, a Telegram group has been established. Crazy Evil was a Russian-speaking "traffer team" that ran the campaign. In an effort to fool consumers into downloading dangerous software onto their Mac read more about GrassCall malware campaign drains crypto wallets via fake job interviews. Get up to date on the la...
CoinLurker Next-Gen Tool Used by Threat Actors in Modern Cyberattacks
News

CoinLurker Next-Gen Tool Used by Threat Actors in Modern Cyberattacks

CoinLurker is an advanced malware that steals data and has transformed fraudulent update operations. CoinLurker, which is written in the Go programming language, uses sophisticated obfuscation and anti-analysis techniques to avoid discovery and carry out covert cyberattacks. Morphisec's study claims that threat actors now choose to utilize his next-generation technology to target banking apps, sensitive user data, and cryptocurrency wallets. The dishonest tactics of previous malware attacks like SocGholish, ClearFake, and FakeCAPTCHA are expanded upon by CoinLurker. Phishing emails, malicious CAPTCHA prompts, and phony software update notifications are all used in these efforts to trick users into downloading malware read more about CoinLurker Next-Gen Tool Used by Threat Actors in ...
Rustbased Realst Infostealer Targeting Apple macOS Users’ Cryptocurrency Wallets
News

Rustbased Realst Infostealer Targeting Apple macOS Users’ Cryptocurrency Wallets

A new malware family known as Realst has become the latest to attack Apple macOS devices, with one-third of the variants already built to infect macOS 14 Sonoma, the operating system's impending major version. The malware, written in the Rust programming language, is spread as phoney blockchain games and is capable of "emptying crypto wallets and stealing stored password and browser data" from both Windows and macOS PCs. Security researcher iamdeadlyz spotted Realst in the wild for the first time. "Realst Infostealer is distributed via malicious websites advertising fake blockchain games with names such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend," SentinelOne security researcher Phil Stokes wrote in a report read more Rustbas...
New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer
News

New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer

A cutting-edge attack targeting users in Europe, the United States, and Latin America has been seen to deploy a cryptocurrency stealer known as GreetingGhoul using a revolutionary multi-stage loader called DoubleFinger. According to a paper published on Monday by Kaspersky researcher Sergey Lozhkin, "DoubleFinger is deployed on the target machine, when the victim opens a malicious PIF attachment in an email message, ultimately executing the first of DoubleFinger's loader stages." A customized version of espexe.exe, or the Microsoft Windows Economical Service Provider application, which is designed to run shellcode in order to retrieve a PNG image file from the image hosting service Imgur, serves as the launchpad for the attacks read more New DoubleFinger Loader Targets Cryptocurrenc...
Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets
News

Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets

Security researchers are paying attention to a new stealthy information thief virus called Bandit Stealer since it can target a variety of web browsers and cryptocurrency wallets. In research released on Friday, Trend Micro stated that Bandit Stealer "has the potential to expand to other platforms as it was developed using the Go programming language, possibly allowing cross-platform compatibility." By utilizing the official command-line tool runas.exe, which enables users to run programs as another user with differing rights, the malware is currently concentrated on attacking Windows systems read more about New Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and...
Telegram WhatsApp Trojanized to Target Cryptocurrency Wallets
News

Telegram WhatsApp Trojanized to Target Cryptocurrency Wallets

It has been discovered that dozens of websites have been put up to distribute Trojanized versions of the WhatsApp and Telegram apps to Android and Windows users. Security experts at ESET have found that the majority of these apps rely on malware called clipper that is intended to steal or alter the contents of the Android clipboard. They are all pursuing the bitcoin funds of their victims, with several of them focusing on cryptocurrency wallets. This was the first time we had observed Android clippers concentrating solely on instant messaging read more Telegram WhatsApp Trojanized to Target Cryptocurrency Wallets. Stay up-to-date with the latest cybersecurity news and increase your cybersecurity awareness through ReconBee.com's in-depth coverage of the newest threats, breaches, a...