[ad_1]
A stealth botnet that has infected computers in nearly 100 different countries is silently stealing cryptocurrency from its victims. From November 2020 to November 2021, he embezzled nearly $ 500,000.
Picture:
getty
The Phorpiex botnet has been operating since 2016 and is made up of hundreds of thousands of compromised devices. In 2019, he was making headlines for an alarmingly successful sextortion email campaign that was making $ 20,000 a month for his criminal controllers.
Phorpiex also has the ability to steal cryptocurrency, which it does through “crypto-clipping”. In these attacks, malware on infected devices waits for cryptocurrency transactions to take place. When a transaction is detected, the malware cuts off the original destination wallet address and replaces it with one controlled by the attacker.
According to Check Point Research, the Phorpiex crypto-clipper supports over 30 different cryptocurrencies. As of April 2016, Phorpiex has hijacked thousands of transactions and stolen around 38 Bitcoin and 133 Ether. At today’s exchange rates, that’s roughly $ 2.2 million worth of stolen cryptocurrency.
From last November to this month of November alone, Phorpiex successfully recorded 969 transactions. These attacks earned its controllers more than $ 650,000.
This summer, however, botnet activity suddenly came to a halt. In August, one of its creators reportedly stepped away from cybercrime and the other decided to sell the Phorpiex code to the highest bidder.
Whether or not a sale had taken place, Phorpiex was back a few weeks later with some new tips. A new variant called Twizt has appeared.
One of the biggest differences with Twizt is that the botnet is now able to communicate on a peer-to-peer basis. This means that it does not depend on specific command and control servers. Infected hosts can send each other instructions.
Twizt also added a double encrypted protocol for communication and new data integrity functions. Check Point researcher Alexey Bukhteyev said that “the emergence of such features suggests that the botnet may become even more stable and therefore more dangerous. “
Security researchers had successfully taken control of the Phorpiex botnet a few times in the past. It could be much, much more difficult now that Twizt has emerged.
|
Sources 2/ https://www.forbes.com/sites/leemathews/2021/12/18/global-botnet-hijacks-500000-in-crypto-transactions-in-just-one-year/ The mention sources can contact us to remove/changing this article |
[ad_2]