216.73.217.98

Cryptocurrency Enthusiasts Targeted in Multi-Vector Supply Chain Attack

· Published 04/11/2024 11:49 · Modified 04/11/2024 12:02

Export JSON

Essential information

Published
04/11/2024 11:49
Modified
04/11/2024 12:02
Tags
2024-11-04 cryptoaitools cryptocurrency data theft github gui multi-stage pypi social engineering supply-chain
Related entities
2 observables, 21 techniques (mitre), 1 malware, 2 others

Description

A sophisticated malware campaign targeting enthusiasts has been uncovered, utilizing multiple attack vectors including a malicious Python package on and deceptive repositories. The malware, disguised as trading tools, aims to steal sensitive data and drain crypto wallets. It employs a deceptive to distract users while performing malicious activities in the background. The attack flow involves an initial infection through the package, followed by a process using a fake website to deliver secondary payloads. The malware conducts extensive , targeting wallet data, browser information, and sensitive system files. The attacker uses multiple platforms to distribute the malware and engages with potential victims through a Telegram channel.

External references