HomeNewsDecryptMalware Campaign Targets Crypto Wallets With Fake PDF Conversion Software

Malware Campaign Targets Crypto Wallets With Fake PDF Conversion Software

-



In brief

  • A new malware campaign uses fake PDF to DOCX converters as a vector.
  • Victims are tricked into executing a PowerShell command, installing SectopRAT variant Arechclient2.
  • The malware can lift seed phrases and tap into Web3 APIs to drain assets.

A malware campaign is using fake PDF to DOCX converters as a vector for sneaking malicious PowerShell commands onto machines, enabling the attacker to access crypto wallets, hijack browser credentials and steal information.

Following an FBI alert last month, CloudSEK Security Research team has carried out an investigation revealing details about the attacks.

The goal is to trick users into executing a PowerShell command which installs the Arechclient2 malware, a variant of SectopRAT, an information stealing family known to harvest sensitive data from victims.

The malicious websites impersonate that of legitimate file converter PDFCandy, but instead of loading the real software, the malware is downloaded. The site features loading bars and even CAPTCHA verification in order to lull users into a false sense of security.

Ultimately, after several redirects, the victim’s machine downloads an “adobe.zip” file containing the payload—exposing the device to the Remote Access Trojan, which has been active since 2019.

This leaves users open to data theft, including browser credentials and cryptocurrency wallet information.

The malware “checks extension stores, lifts seed phrases, and even taps into Web3 APIs to ghost-drain assets post-approval,” Stephen Ajayi, Dapp Audit Technical Lead at blockchain security firm Hacken, told Decrypt.

CloudSEK advised people to use antivirus and antimalware software, and to “Verify file types beyond just extensions, as malicious files often masquerade as legitimate document types.”

The cybersecurity firm also advises that users rely on “trusted, reputable file conversion tools from official websites rather than searching for ‘free online file converters’,” and to consider using “offline conversion tools that don’t require uploading files to remote servers.”

Hacken’s Ajayi advised crypto users to remember that, “Trust is a spectrum, it’s earned, not given. In cybersecurity, assume nothing is safe by default.” He added that they should, “Apply a zero trust mindset, and keep your security stack up to date especially EDR and AV tools that can flag behavioral anomalies like rogue msbuild.exe activity.”

“Attackers evolve constantly and so should defenders,” Ajayi noted, adding that, “Regular training, situational awareness, and strong detection coverage are essential. Stay skeptical, prepare for worst-case scenarios, and always have a tested response playbook ready to go.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

News source: Malware Campaign Targets Crypto Wallets With Fake PDF Conversion Software
Read the full article and more directly from the source!

Enjoying our initiative? Support us with a BTC donation:
BTC Wallet: bc1q0faa2d4j9ezn29uuf7c57znsm5ueqwwfqw9gde

LATEST POSTS

Why Are So Many Firms Suing Strategy Over Its Bitcoin Holdings?

In brief Five law firms filed identical class action lawsuits against Strategy alleging securities fraud over misleading Bitcoin investment statements. Two law professors told Decrypt that...

Robinhood’s Crypto Keynote Could Be a Chance to Buy the Dip: Compass Point

In brief Robinhood’s crypto keynote event on Monday could be a “sell the news” event, according to one analyst. The company could make announcements surrounding tokenized...

Why ‘Eve Frontier’ Is Opening Up to Everyone With Free Trial Experience

In brief Ethereum-powered space survival game Eve Frontier is running a free trial period for 10 days. Users can earn "Grace" for their actions, which...

Ripple to Drop Appeal in SEC Case Over XRP Sales, Ending Case ‘Once and for All’

Ripple CEO Brad Garlinghouse said on Friday that the fintech will drop its cross appeal in a long-running case with the U.S. Securities and...

Most Popular

spot_img