New virus automatically empties crypto exchange accounts

[ad_1]

Rilide masquerades as a legitimate Google Drive extension and allows cybercriminals to perform various activities including obtaining browsing history data, taking screenshots and withdrawing funds from various crypto exchanges. cash.

Cybersecurity researchers from Trustwave SpiderLabs have discovered a new strain of malware called Rilide that targets Chromium-based browsers like Google Chrome, Microsoft Edge, Brave, and Opera and steals users’ cryptocurrencies.

Rilide virus impacts crypto holders

Rilide differs from other malware strains that SpiderLabs has encountered in that it uses forged dialogs to trick users into handing over their two-factor authentication (2FA) codes. This allows the malware to withdraw cryptocurrencies in the background without users’ knowledge.

While investigating the origins of Rilides, researchers found similar browser extensions advertised for sale and discovered that some of its code had recently been posted to an underground forum due to a dispute over payment.

Researchers discovered two malicious campaigns that led to the installation of the Rilide extension. One such campaign involved a module containing an encoded data block storing the Rilide loader URL.

The payload, which was hosted on Discord CDN, was saved to the %temp% directory and run through the start-process PowerShell cmdlet.

Rilide uses a Rust loader to install the extension if a Chromium-based browser is detected. The loader modifies the shortcut files opening the targeted web browsers, so that they are executed with the load-extension parameter which points to the dropped malicious Rilide extension.

The malware’s background script attaches a listener to certain events and removes the Content Security Policy (CSP) directive for all requests, allowing the extension to perform an attack and load external resources that would be blocked by the CSP without such an approach.

Rilides crypto exchange scripts support a withdrawal feature. While withdrawals are processed in the background, the user is presented with a fake device authentication dialog to get their 2FA code. Email confirmations are replaced on the fly if the user enters their mailbox using the same web browser, prompting the user to provide the authorization code.

During their research, SpiderLabs found several thief extensions for sale with similar capabilities to Rilide, but they were unable to definitively link any of them to the malware. They also uncovered a botnet selling advertisement on an underground forum dated March 2022, which included features such as a reverse proxy and a clicker ad.

The automatic botnet removal feature attacked the same exchanges seen in Rilide samples.

Rilide is a prime example of the growing sophistication of malicious browser extensions and the dangers they pose. Although the forthcoming application of the v3 manifesto may pose more problems for threat actors, it is unlikely to completely solve the problem, as most of the features exploited by Rilide will still be available.

To protect against such threats, it is essential to remain vigilant when receiving unsolicited emails or messages, and to keep up to date with the latest cybersecurity threats and security practices to minimize the risk of fall victim to phishing attacks.

Follow us on Google News

Sources

1/ https://Google.com/

2/ https://crypto.news/new-virus-automatically-empties-crypto-exchange-accounts/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts