Crypto Investors Attacked by New Malware, Cisco Talos Reveals

[ad_1]

Malwarebytes anti-malware software has exposed two new malicious computer programs spread by unknown sources actively targeting crypto investors in a desktop environment.

Since December 2022, the two malicious files in question, MortalKombat ransomware and Laplas Clipper malware, have been actively monitoring the internet and stealing cryptocurrencies from unwary investors, threat research team Cisco Talos has revealed. Campaign victims are primarily located in the United States, with a lower percentage of victims in the United Kingdom, Turkey, and the Philippines, as shown below.

Malicious campaign victimology. Source: Cisco Talos

Malware works in partnership to scan information stored in the user’s clipboard, which is usually a string of letters and numbers copied by the user. The infection then detects the wallet addresses copied to the clipboard and replaces them with a different address.

The attack relies on the users’ inattention to the sender’s wallet address, which would send the cryptocurrencies to the unidentified attacker. With no obvious target, the attack extends to individuals and organizations large and small.

Ransom notes shared by MortalKombat ransomware. Source: Cisco Talos

Once infected, MortalKombat ransomware encrypts users’ files and drops a ransom note with payment instructions as shown above. Revealing the download links (URLs) associated with the attack campaign, the Talos report said:

One of them reaches a server controlled by an attacker via IP address 193[.]169[.]255[.]78, based in Poland, to download MortalKombat ransomware. According to Talos’ analysis, 193[.]169[.]255[.]78 runs an RDP crawler, scanning the internet for exposed RDP port 3389.

As Malwarebytes explains, the tag-team campaign begins with a cryptocurrency-themed email containing a malicious attachment. The attachment executes a BAT file which allows the ransomware to be downloaded and executed when opened.

Through early detection of high-potential malware, investors can proactively prevent this attack from affecting their financial well-being. As always, Cointelegraph advises investors to carry out thorough due diligence before investing, while ensuring the official source of communications. Check out this Cointelegraph magazine article on how to protect crypto assets.

Related: US Department of Justice seizes website of prolific Hive ransomware gang

On the other hand, as ransomware victims continue to deny extortion requests, ransomware revenue for attackers has dropped 40% to $456.8 million in 2022.

Total value extorted by ransomware attackers between 2017 and 2022. Source: Chainalysis

While revealing the information, Chainalysis noted that the numbers do not necessarily mean that the number of attacks is down from the previous year.

Sources

1/ https://Google.com/

2/ https://cointelegraph.com/news/crypto-investors-under-attack-by-two-new-malware-reveals-cisco-talos

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts