Research: New Malware Employs Tor and Bittorrent To Steal Bitcoin and Ether

Research: New Malware Employs Tor and Bittorrent To Steal Bitcoin and Ether
фото показано с : news.bitcoin.com

2020-9-4 12:30

A new trojan called Krypto Cibule uses infested computers’ power to mine cryptocurrency, steal crypto wallet files, and redirect incoming digital assets to a hacker address. The malware rides on the Tor network and the Bittorrent protocol to perform attacks, according to an extensive report by cybersecurity company, ESET.

“Krypto Cibule is spread through malicious torrents for ZIP files whose contents masquerade as installers for cracked or pirated software and games,” researchers Matthieu Faou and Alexandre Cote Cyr, detailed in their report published September 2.

The malware is mostly active in the Czech Republic and Slovakia where it has been responsible for hundreds of attacks. Most victims downloaded the malware from files hosted on a torrent site popular in the two countries called uloz.to.

The mining operations of the malware, which ESET researchers trace back to 2018, are written into XMRig, an open-source program that mines monero using the CPU, and kawpowminer, another open-source program that mines ethereum (ETH) using the GPU, with both programs set up to connect to a hacker-controlled mining server over the Tor proxy.

Researchers have attributed the little attention previously given to the trojan to the discretion of its operations. To keep the owner of the computer unsuspecting, the malware recalls the GPU miner when the battery is under 30% and stops operations altogether when the battery is under 10%.

The clipboard-hijacking operation masquerades as SystemArchitectureTranslation.exe. It monitors changes to the clipboard in order to replace wallet addresses with addresses of controlled by the malware operator in order to misdirect funds. The researchers noted:

At the time of this writing, the wallets used by the clipboard hijacking component had received a little over $1,800 in bitcoin (BTC) and ethereum.

Exfiltration works by walking through the filesystem of each available drive to look for filenames that contain certain terms. ESET researchers linked the trojan to terms mostly referring to cryptocurrencies, wallets, or miners, as well as more generic ones like crypto, seed, and password. Files that could provide data such as private keys are also targeted.

According to the research team, the use of legitimate open-source tools as well as a wide range of anti-detection methods is likely to have kept the malware under the radar this far. Krypto Cibule is still being actively developed, with new features having been added in its two-year-old life.

As news.Bitcoin.com reported recently, hackers have already been plundering bitcoin through the large-scale use of malicious relays on the Tor network. Tor is a privacy-oriented network popular with bitcoin investors throughout the world.

What do you think about the new malware exploiting Tor and Bit Torrent? Let us know in the comments section below.

The post Research: New Malware Employs Tor and Bittorrent To Steal Bitcoin and Ether appeared first on Bitcoin News.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

BitTorrent (BTT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.0004175 (-100%)

bittorrent new steal tor malware network protocol

bittorrent new → Результатов: 126


Фото:

Пользователи µTorrent будут получать вознаграждение в криптовалюте на базе TRON

Базирующаяся в Сингапуре BitTorrent Foundation выпустит монету BitTorrent Token (BTT) на базе протокола TRON. Основной функций BTT будет плата пользователям за раздачу файлов. Today we unveil our new token BitTorrent $BTT which features native TRC-10 compatibility and will be exclusively available to non-U.

2019-1-6 15:24


Токенсейл BitTorrent запустят на платформе от биткоин-биржи Binance

Крупнейшая по объему торгов биткоин-биржа Binance перезапустит платформу для проведения токенсейлов Launchpad. #Binance Launchpad Will Feature New Projects in 2019https://t. co/vso8jm6iOf pic. twitter.

2019-1-4 00:39


Tron’s Project Atlas Goes Live For BitTorrent Users

With TRON’s acquisition of BitTorrent in July 2018, the company has concluded moves to combine blockchain and file sharing together with their latest venture, Project Atlas. According to an announcement made by the Decentralized Internet startup, Tron, the firm gave new details of its bid to integrate both functions with its torrent client BitTorrent, which […] The post Tron’s Project Atlas Goes Live For BitTorrent Users appeared first on ZyCrypto.

2018-10-3 16:42


[TRON Newsflash]: Exclusive Inside Look at TRX’s Project Atlas Coming on September 28

Tron Ready to Present an Update on Project Atlas on September 28 One of the most exciting blockchain networks in the market will be releasing information about its Project Atlas on September 28. This project will allow Tron to create a new way of content distribution connecting the BitTorrent peer-to-peer network with TRON and its […]

2018-9-27 22:15


Фото:

BitTorrent: Tron Foundation Officially Completes Acquisition

File sharing software provider BitTorrent announced Tuesday that its acquisition by the Tron Foundation is now officially complete. BitTorrent said it will now operate from Tron’s new San Francisco offices and support the blockchain project’s global development, while continuing to serve the claimed 100 million BitTorrent users around the globe. According to the announcement: “We believe

2018-7-25 19:47


Фото:

Justin Sun now owns BitTorrent, the first of his Infinity stones

The acquisition of BitTorrent by Justin Sun has been finalized, effectively bringing 100 million new users to TRON’s (TRX) decentralized ecosystem. News first broke of the deal back in May, when rumors surfaced that Justin Sun – the founder of blockchain operating system TRX – was interested in purchasing the peer-to-peer (p2p) file-sharing platform and its architecture.

2018-7-24 15:48


Cloud provider Xunlei launches new blockchain file system!

Chinese technology company Xunlei Limited, known to some as the BitTorrent of China, announced Friday that it has launched a new distributed file system aimed at supporting blockchain platforms. The ThunderChain File System (TCFS), as well as three ThunderChain Request for Comments (TRC) standards, will help support blockchain development, the company said in statements. The

2018-7-7 00:40