Phorpiex a new malicious botnet has been discovered
The crypto clipper changes the recipient addresses when sending cryptocurrency

17.12.2021 - 12:20
333
1 min
0
What’s new? Check Point Research (CPR), a cyberthreat research company, reports a new variant of Phorpiex, a botnet known for spamming, extortion, and cryptocurrency theft. The new variant, dubbed Twizt, has stolen more than $500 000 worth of cryptocurrency in a year.
How does Twizt work? According to CPR, the botnet uses a technique called “cryptocurrency clipping.” The malware replaces the recipient's wallet address with that of the attacker. Twizt operates without active management and control servers, meaning that each infected computer can expand the botnet. Since the botnet uses a peer-to-peer model, it can receive the commands and updates from other devices hosting the virus.
How much did the attackers manage to steal? Between November 2020 and November 2021, Phorpiex bots hijacked 969 transactions. The hackers stole 3,64 BTC, 55,87 ETH, and $55 000 in ERC20 tokens. The largest intercepted transaction was 26 ETH.
Useful material?
Market
The feature is available for selected clients
Mar 24, 2025
Incidents
He turned out to be a British citizen who had previously been convicted of fraud
Mar 21, 2025
Market
Transactions related to the new platform may also be blocked due to sanctions evasion
Mar 20, 2025
Market
To pass, the document must receive majority support in the House of Representatives and 60 votes in the Senate
Mar 14, 2025
Market
The update will gradually become available to users in March and April
Mar 13, 2025
Mining
Industry participants with such low-powered devices have extremely low chances of single block mining
Mar 12, 2025