SafeGuard warns of new crypto-stealing malware in Telegram
The malware spreads via spamming with images and hides on the victim's device as an operating system file
12.07.2022 - 15:20
952
1 min
0
What’s new? Cybersecurity solutions provider SafeGuard Cyber warned of the emergence of a malware to steal keys to crypto wallets, which is spreading in the Telegram messenger. According to the press release, the company first discovered the fraudulent software back in June. The program masqueraded as an image file posted to a public Telegram channel about trading and digital assets.
What is the danger of the virus? The program spreads through spam with images and is downloaded by clicking on the attachment. On the device, it hides itself as an operating system file and then creates hidden copies of the victim's public and private keys to steal cryptocurrencies from the wallet. The software also has backdoor functionality, which can be upgraded and equipped with additional features.
The company noted that hackers are increasingly using communication platforms to spread malware.
Earlier, analysts at Cyble described the PennyWise virus, which can steal data from 30 different cryptocurrency wallets, including cold ones. The virus is spread under the guise of free mining software, links to which are posted under tutorial videos on YouTube. PennyWise is built using an unknown crypter, making it difficult to remove.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter