SafeGuard warns of new crypto-stealing malware in Telegram
The malware spreads via spamming with images and hides on the victim's device as an operating system file
12.07.2022 - 15:20
656
1 min
0
What’s new? Cybersecurity solutions provider SafeGuard Cyber warned of the emergence of a malware to steal keys to crypto wallets, which is spreading in the Telegram messenger. According to the press release, the company first discovered the fraudulent software back in June. The program masqueraded as an image file posted to a public Telegram channel about trading and digital assets.
What is the danger of the virus? The program spreads through spam with images and is downloaded by clicking on the attachment. On the device, it hides itself as an operating system file and then creates hidden copies of the victim's public and private keys to steal cryptocurrencies from the wallet. The software also has backdoor functionality, which can be upgraded and equipped with additional features.
The company noted that hackers are increasingly using communication platforms to spread malware.
Earlier, analysts at Cyble described the PennyWise virus, which can steal data from 30 different cryptocurrency wallets, including cold ones. The virus is spread under the guise of free mining software, links to which are posted under tutorial videos on YouTube. PennyWise is built using an unknown crypter, making it difficult to remove.
Useful material?
Market
Due to supply shortages, the asset’s pre-market exchange rate was climbing above $1000
Dec 16, 2024
Incidents
Reports about the hacking of the exchange with calls to withdraw assets began to spread on December 13
Dec 13, 2024
Crypto regulations
Stablecoins from issuer Circle will not be affected by the changes
Dec 12, 2024
Crypto regulations
The platform will launch after meeting the preconditions of the local exchange authority
Dec 9, 2024
Market
The $1,1 billion figure was reached after the bitcoin correction
Dec 6, 2024
Crypto regulations
By early January, all open positions and loans of local users will be closed and repaid automatically
Dec 5, 2024