• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

ElectroRAT Drains Crypto Wallets

You are here: Home / General Cyber Security News / ElectroRAT Drains Crypto Wallets
January 6, 2021

1000’s of cryptocurrency customers have fallen target to a sophisticated danger campaign that makes use of trojanized apps to drain funds from digital wallets.

The lately discovered campaign is a large-ranging procedure that encompasses pretend organizations, a marketing campaign, custom-designed cryptocurrency purposes, and a new Distant Entry Software (RAT) prepared from scratch to stay away from antivirus detection.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Scientists at Intezer who unearthed the procedure in December believe that it was initiated in January 2020.

“The campaign involves area registrations, web-sites, trojanized purposes, phony social media accounts and a new undetected RAT that we have named ElectroRAT,” wrote scientists. 

ElectroRAT is published in the open-source programming language Golang and is compiled to target Windows, Linux, and Mac working programs.

“It is fairly typical to see various data stealers hoping to collect private keys to access victims’ wallets,” wrote researchers. “However, it is unusual to see instruments composed from scratch and made use of to concentrate on a number of running devices for these needs.”

The creator of the destructive marketing campaign entices cryptocurrency customers to download trojanized applications by marketing the applications on social media and in committed on the web forums. 

“We estimate this marketing campaign has presently infected hundreds of victims centered on the selection of distinctive visitors to the pastebin internet pages made use of to identify the command and manage servers,” mentioned scientists.

Three various trojanized apps—Jamm, eTrade, and DaoPoker—have been designed by the attacker, each with a Windows, Linux, and Mac version. The attacker then designed web sites particularly to host the binaries. 

The applications surface to provide easy-to-use resources that will aid people trade and take care of their cryptocurrency. 

“These apps had been promoted in cryptocurrency and blockchain-linked boards this kind of as bitcointalk and SteemCoinPan,” wrote scientists. 

“The advertising posts, printed by faux customers, tempted audience to search the applications’ web internet pages, in which they could download the software devoid of figuring out they were basically setting up malware.”

To make the DaoPoker app show up authentic, the attacker created Twitter and Telegram accounts for it and paid a social media influencer with in excess of 25,000 Twitter followers to advertise the application.

Amongst ElectroRAT’s really intrusive abilities are keylogging, using screenshots, uploading data files from disk, downloading files, and executing commands on the victim’s console.


Some areas of this article are sourced from:
www.infosecurity-journal.com

Previous Post: «Cybercriminals Ramp Up Exploits Against Serious Zyxel Flaw Cybercriminals Ramp Up Exploits Against Serious Zyxel Flaw
Next Post: British Airways Plans £3bn Breach Settlement Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.