1. Home
  2. Malware

Malware

Crimeware-as-a-service: A new threat to crypto users

Crimeware-as-a-service fuels cybercrime in crypto. Explore its impact, tactics used and key steps to safeguard your wallets and transactions.

Crimeware-as-a-service (CaaS) involves experienced criminals selling their tools and services to less experienced offenders for a price. This model resembles software-as-a-service (SaaS), where the provider gives access to the software to the subscriber. In the case of crimeware-as-a-service, the SaaS model has reshaped itself in the context of cybercrime.

In the early days of cybercrime, cybercriminals mostly worked alone or in small groups, playing with technology and trying to sneak into people’s bank accounts or emails for personal gains and fun. Criminals generally used email to send viruses and commit scams. 

Read more

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

Job Seekers Beware: Fraudulent Offers Conceal Dangerous Crypto Malware

Job Seekers Beware: Fraudulent Offers Conceal Dangerous Crypto MalwareJob seekers are being targeted by a sinister scheme, with fake listings installing hidden cryptocurrency mining malware that silently hijacks systems and drains resources. Crypto Malware Disguised as Job Listings Is Preying on Job Seekers Cybersecurity firm Crowdstrike has revealed details of a phishing scheme in a blog post published Tuesday, outlining how attackers manipulate […]

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

Crypto hackers take new spin on fake job scam, dropping ‘nasty’ malware

Rather than tricking victims into opening malware-infested PDFs or running malicious video calling software, this attack method prompts victims to fix a microphone and camrea access issue.

Crypto hackers have reportedly found a slick new way of tricking their victims into downloading “nasty” malware that can grant hackers access to a victim’s computer and drain their wallets or do other significant damage. 

According to blockchain sleuth Taylor Monahan, known as Tay on X, the hackers would first pose as a recruiter from a reputable crypto firm offering their target a  $200,000 to $350,000 salary.

Source: Taylor Monahan

Read more

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

Crypto Enthusiasts Targeted in Multi-Vector Malware Attack Disguised As Python-Based Trading Tool: Report

Crypto Enthusiasts Targeted in Multi-Vector Malware Attack Disguised As Python-Based Trading Tool: Report

Malware disguised as a Python-based trading bot has reportedly targeted crypto traders in a multi-vector supply chain attack. According to a new blog post by cloud-based cybersecurity firm Checkmarx, crypto enthusiasts have been targeted by advanced malware cloaked as a suite of artificial intelligence (AI)-based crypto trading tools that aim to steal sensitive data and […]

The post Crypto Enthusiasts Targeted in Multi-Vector Malware Attack Disguised As Python-Based Trading Tool: Report appeared first on The Daily Hodl.

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

International Sting Unravels Malware Stealing Crypto and Financial Data

International Sting Unravels Malware Stealing Crypto and Financial DataThe U.S. Department of Justice (DOJ) has joined an international crackdown on infostealer malware, seizing servers, domains, and crypto accounts linked to the theft of millions of credentials. International Operation Disrupts Redline and META Infostealers The U.S. Department of Justice (DOJ) announced Tuesday a coordinated international operation to disrupt Redline and META infostealers, malware that […]

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

Crypto-stealing malware discovered in Python Package Index — Checkmarx

According to cybersecurity firm Hacken, financial losses from crypto hacks topped $440 million in the third quarter of 2024.

Researchers at the Checkmarx cybersecurity firm sounded the alarm on a dangerous form of malware uploaded to the Python Package Index (PyPI) — a platform for Python developers to download and share code — that steals private keys, mnemonic phrases, and other sensitive user data.

According to the firm, the malware was automatically uploaded by a suspicious user in several different software packages meant to mimic decoding applications for popular wallets like MetaMask, Atomic, TronLink, Ronin, and other industry staples.

The malware was cleverly embedded within parts of the software packages. This allowed the malicious software to go largely undetected due to what appeared to be harmless code.

Read more

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

German Authorities Shut Down 47 Crypto Exchange Services in Cybercrime Crackdown

German Authorities Shut Down 47 Crypto Exchange Services in Cybercrime CrackdownGerman authorities have dismantled 47 exchange services involved in facilitating anonymous crypto transactions for criminal activities. These platforms bypassed anti-money laundering protocols, enabling cybercriminals to exchange digital currencies without identity verification. The takedown follows a series of other operations targeting major cybercrime networks. With seized user and transaction data, authorities are set to pursue further […]

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

New Android Malware Posing As Legitimate App Emerging, Stealing Seed Phrases of Crypto Users: Cybersecurity Firm

New Android Malware Posing As Legitimate App Emerging, Stealing Seed Phrases of Crypto Users: Cybersecurity Firm

Crypto wallet owners in Korea should be wary of a new type of mobile malware designed to steal seed phrases, warns the cybersecurity firm McAfee. A seed phrase is a collection of 12 to 24 random words used to restore access to a crypto wallet. McAfee researchers note the new malware threat, called SpyAgent, has […]

The post New Android Malware Posing As Legitimate App Emerging, Stealing Seed Phrases of Crypto Users: Cybersecurity Firm appeared first on The Daily Hodl.

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

New Android malware steals private keys from screenshots and images

According to a recent FBI warning, North Korean hackers are "aggressively targeting" the crypto industry with “well-disguised” attacks.

A new Android malware called SpyAgent, discovered by software security firm McAfee, can steal private keys stored in screenshots and images on a smartphone’s internal storage.

More specifically, the malware uses a mechanism known as optical character recognition (OCR) to scan images stored on a smartphone and extract words from them. OCR is present in many technologies, including desktop computers, which can recognize, copy, and paste text from images.

McAfee Labs explained that the malware is distributed through malicious links sent through text messages. The cybersecurity company broke down the process, beginning with an unsuspecting user clicking on a link they received.

Read more

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice

FBI Warns of Sophisticated North Korean Cyber Attacks Targeting Crypto, Defi, ETFs

FBI Warns of Sophisticated North Korean Cyber Attacks Targeting Crypto, Defi, ETFsThe FBI has issued a new warning about North Korea’s cyber campaigns targeting the cryptocurrency sector. The agency highlighted the use of sophisticated, hard-to-detect social engineering tactics to deploy malware and steal digital assets. North Korean hackers are reportedly focusing on decentralized finance (defi) platforms and cryptocurrency exchange-traded funds (ETFs). FBI Warns of North Korean […]

JPMorgan Chase Employee Allegedly Steals $857,000, Abusing Insider Status To Manipulate Hundreds of US Treasury Checks: Department of Justice