The Phorpiex botnet is back with a new Twizt: hijack hundreds of crypto transactions

[ad_1]

Check Point Research (CPR) spots a botnet variant that has stolen nearly half a million dollars in cryptocurrency through a technique called “crypto clipping.” The new variant, named Twizt and descendant of Phorpiex, steals cryptocurrency during transactions by automatically replacing the intended wallet address with the threat actor’s wallet address. The CPR is warning cryptocurrency traders to be wary of whom they send funds to as 969 transactions have been intercepted and counted. Twizt can operate without active C&C servers, which allows it to evade security mechanisms.

In 12 months, 3.64 Bitcoin, 55.87 Ether and $ 55,000 in ERC20 tokens were taken 26 ETH embezzled in one case Majority of victims reside in Ethiopia, Nigeria and India

Check Point Research (CPR) has spotted a new variant of Phorpiex, a botnet known for sextortion and crypto-jacking. The new variant, called Twizt, works without active command and control servers, which means that every computer it infects can expand the botnet. The CPR estimates that Twizt took nearly half a million dollars worth of cryptocurrency. The new features of Twizt led the CPR to believe that the botnet could become even more stable and, therefore, more dangerous.

How Twizt works

Twizt relies on a technique called “crypto clipping”, which is the theft of cryptocurrency during transactions through the use of malware that automatically replaces the intended wallet address with the actor’s wallet address of the threat. The result is that the funds fall into the wrong hands.

Victims

Over a one-year period, between November 2020 and November 2021, Phorpiex robots hijacked 969 transactions, stealing 3.64 Bitcoin, 55.87 Ether, and $ 55,000 in ERC20 tokens. The value of the stolen goods at current prices is almost half a million US dollars. On several occasions, Phorpiex has succeeded in diverting large-value transactions. The highest amount for an intercepted Ethereum transaction was 26 ETH.

Figure 1. Victims by country

The new variant of Phorpiex carries three main risks. First, Twizt uses a peer-to-peer model and is able to receive commands and updates from thousands of other infected machines. A peer-to-peer botnet is more difficult to take apart and disrupt its functioning. This makes Twizt more stable than previous versions of Phorpiex bots. Second, as well as older versions of Phorpiex, Twizt is able to steal crypto without any communication with C&C, so it’s easier to evade security mechanisms, such as firewalls in order to do damage. Third, Twizt supports over 30 different cryptocurrency wallets from different blockchains including major ones like Bitcoin, Ethereum, Dash, Monero. This creates a huge attack surface, and basically anyone using crypto could be affected. I strongly urge all cryptocurrency users to verify the wallet addresses they copy and paste as you could very well inadvertently send your crypto into the wrong hands.

Safety tips

Check the wallet address. When users copy and paste a crypto wallet address, always verify that the original and pasted addresses match. Test the operations. Before sending large amounts in crypto, first send a probe “test” transaction with a minimum amount. Stay up to date. Keep the operating system up to date, do not download software from unverified sources. Skip the announcements. If you are looking for crypto wallets or trading and exchange platforms in the crypto space, always look at the first website of your search and not in the ad. These can mislead you as the CPR has found scammers using Google Ads to steal crypto wallets. Look at the URLs. Always check urls!

Sources

1/ https://Google.com/

2/ https://blog.checkpoint.com/2021/12/16/phorpiex-botnet-is-back-with-a-new-twizt-hijacking-hundreds-of-crypto-transactions/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts