Trojan-infected TOR browser installers spreading crypto-stealing Clipper malware

[ad_1]

29 March 2023Ravie LakshmananCryptocurrency / Malware

Trojanized installers for the TOR anonymity browser have been used to target users in Russia and Eastern Europe with clipper malware designed to siphon cryptocurrencies since September 2022.

“Clipboard Injectors […] can remain silent for years, showing no network activity or any other signs of presence until the disastrous day when they replace a crypto wallet address,” said Vitaly Kamluk, Director of the Global Research and Analytics Team (GReAT) for APAC at Kaspersky.

Another notable aspect of clipper malware is that its nefarious functions are not triggered unless the clipboard data meets a specific criteria, which makes it more evasive.

It’s not immediately clear how the installers are distributed, but evidence points to the use of torrent downloads or an unknown third-party source since the Tor Project website has been subject to blockages in Russia in recent years. .

Whichever method is used, the installer launches the legitimate executable, while simultaneously launching the clipper payload designed to monitor the contents of the clipboard.

“If the clipboard contains text, it parses the content with a set of built-in regular expressions,” Kamluk noted. “If it finds a match, it’s replaced with a randomly chosen address from a hard-coded list.”

Each sample contains thousands of randomly selected possible replacement addresses. It also offers the possibility to disable the malware by means of a special hotkey combination (Ctrl+Alt+F10), an option probably added during the testing phase.

The Russian cybersecurity company said it recorded around 16,000 detections, the majority of which are registered in Russia and Ukraine, followed by the United States, Germany, Uzbekistan, Belarus, China, United States. Netherlands, UK and France. In total, the threat has been spotted in 52 countries around the world.

THN WEBINAR

Become an incident response pro!

Discover the secrets of rock-solid incident response – Master the 6-phase process with Asaf Perlman, Cynet’s IR Manager!

Don’t miss a thing – Reserve your seat!

The scheme is estimated to have earned operators nearly $400,000 in illicit profits from the theft of Bitcoin, Litecoin, Ether, and Dogecoin. The amount of Monero assets looted is not known due to the privacy features built into the service.

It is suspected that the campaign could have a wider reach due to the possibility of threat actors exploiting other software installers and never-before-seen delivery methods to target unwary users.

To protect against such threats, it is always recommended to download software only from trusted and trusted sources.

Did you find this article interesting ? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sources

1/ https://Google.com/

2/ https://thehackernews.com/2023/03/trojanized-tor-browser-installers.html

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts