[ad_1]
Fortinet’s FortiGuard Labs discovered a new scam using the lure of an Amazon gift card generator to steal cryptocurrency from people.
FortiGuard Labs researchers said they found a file called “Amazon Gift Tool.exe” that was marketed on a publicly accessible file repository site as a free Amazon gift card generator.
When people download the file and open it, a malicious winlogin.exe is deleted and executed.
“The purpose of the malware is simple. If the victim tries to add money to their non-bitcoin wallet by copying and pasting the wallet address, the malware overwrites the victim’s wallet address in the press. – papers with his own, which can potentially cost the abuser money, ”the researchers explained.
According to FortiGuard Labs, the malware monitors a user’s clipboard for 54-character text (the length of a cryptocurrency wallet address) and other criteria that indicate the text is crypto-related. -cash.
If the text matches three different criteria, the malware places the attacker’s Bitcoin Cash wallet address instead of the clipboard information.
The malware also searches for addresses related to Ethereum, Binancecoin, Litecoin, Dogecoin, and Ripple.
“We also discovered that the winlogin.exe malware is distributed by a number of attractively-named dropper files, such as Crunchyroll Breaker.exe, Netflix Tools.exe, Multi Gift Tools.exe, etc.,” FortiGuard Labs explained. .
“Free generators like this exist and have been ripping people off for years. But given Amazon’s market power, this new scam is particularly appealing. Consumers are eager to shop as much as they can. Black Friday because a lot of products keep selling. Free Amazon gift cards are very attractive for those who want to spend less for the holiday season. However, be careful what you want and don’t be scammed like this one.
Derek Manky, head of security intelligence and global threat alliances at Fortinet’s FortiGuard Labs, told ZDNet that they made this discovery as part of their threat research process while researching rules / targets specific.
FortiGuard Labs found samples collected through an open repository and then did further correlation work from there as part of the discovery phase, Manky said.
Cryptowallet addresses are quite large, and while cryptowallet users can write their wallet to a physical location, it is likely that they have stored it digitally – either in a cold storage wallet or on their workstation. work, according to Manky.
“These digital encryption wallet addresses are usually accessible during transactions to send / receive money during the transaction itself on the client machine. In this case, the attacker hopes to replace the victim’s wallet with his own. to embezzle funds. Keep in mind that this is usually is MFA with these transactions, but this is done by the client for approval. They may not notice that the wallet address they pasted n ‘was actually not theirs,’ Manky said.
“This attempted attack was specifically designed to hijack cryptowallet addresses / transactions similar to payment hijacking fraud. And in particular Bitcoin Cash.”
FortiGuard Labs has also uncovered another game console scam, trying to attract people interested in purchasing PlayStation 5 and Xbox Series X and S systems.
Researchers found a bunch of malicious PDF files with titles such as “how_much_do_xbox_one_cost_on_black_Friday.pdf” and “Walmart_black_Friday_ps5_pickup.pdf”.
Once the victims click on the link, they are redirected to phishing sites where they are asked to provide confidential information.
|
Sources 2/ https://www.zdnet.com/article/fortinet-warns-of-black-friday-scams-involving-ps5s-xbox-and-fake-amazon-gift-card-generator-stealing-crypto/ The mention sources can contact us to remove/changing this article |
[ad_2]