$100k in Crypto Drained by the Underground Operation
A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader injects a Vidar-class stealer into Windows processes, launching Chrome or Edge to inject malicious scripts into victim sessions. The malware builder, dubbed Underground, has been active since October 2023. The operation employs seven gate domains and has drained approximately $100,000 across 80+ destination addresses on 23 blockchain networks from 350-430 victims. The infection begins with lure archives containing trojanized files, deploying a loader that implements anti-analysis checks against 67 monitoring tools. Once injected, the stealer automatically drains cryptocurrency exchange accounts through fake security overlays, converts holdings to Bitcoin, and modifies withdrawal confirmation emails. A clipboard clipper targeting two dozen cryptocurrencies replaces copied wallet addresses with operator-controlled addresses. The operation rotates Cloudflare-fronted domains faster than reputation-based detection can respond.
AI Analysis
Technical Summary
This threat involves a malware campaign called Underground that uses an Aotera/Tedy loader to inject a Vidar-class stealer into Windows processes. The stealer targets cryptocurrency exchange accounts by injecting malicious scripts into Chrome and Edge sessions, enabling automatic theft via fake overlays and email manipulation. Additionally, a clipboard hijacker replaces legitimate cryptocurrency wallet addresses with attacker-controlled ones to divert funds. The campaign employs seven gate domains and rotates Cloudflare-fronted domains rapidly to avoid reputation-based detection. Infection starts with lure archives containing trojanized files and includes anti-analysis checks against 67 monitoring tools. The operation has stolen about $100,000 from hundreds of victims since October 2023.
Potential Impact
The malware campaign results in direct financial loss to victims by stealing cryptocurrency from exchange accounts and wallets. It manipulates browser sessions and email communications to facilitate unauthorized withdrawals and converts stolen assets to Bitcoin, complicating recovery. The clipboard hijacking further increases the risk of fund diversion by replacing copied wallet addresses. Approximately 350-430 victims have been affected, with losses totaling around $100,000 across 23 blockchain networks.
Mitigation Recommendations
No vendor advisory or official patch information is available for this malware campaign. Mitigation should focus on user education to avoid opening lure archives and trojanized files. Security teams should monitor for indicators of compromise such as the domains quick-neo.com and easybooters.com, and IP 95.164.53.76. Employ endpoint detection tools capable of identifying Aotera/Tedy loaders and Vidar stealers. Use multi-factor authentication on cryptocurrency accounts and verify wallet addresses manually rather than relying on clipboard contents. Due to rapid domain rotation, reputation-based detection may be insufficient, so behavioral detection and threat intelligence integration are recommended.
Indicators of Compromise
- domain: quick-neo.com
- ip: 95.164.53.76
- url: http://95.164.53.76/new/log/048466C5/startCrypt
- url: http://95.164.53.76/new/log/29A5FDA7/failed/1769331221
- url: http://95.164.53.76/new/log/29A5FDA7/startLoader/1769331211
- url: http://95.164.53.76/new/log/8320E1A4/success/1767499039
- url: http://95.164.53.76/new/log/8320e1a4/startloader/1767499038
- url: http://95.164.53.76/new/log/D9D278DD/success/1696492954
- url: https://easybooters.com/newlog.php'
- domain: easybooters.com
$100k in Crypto Drained by the Underground Operation
Description
A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader injects a Vidar-class stealer into Windows processes, launching Chrome or Edge to inject malicious scripts into victim sessions. The malware builder, dubbed Underground, has been active since October 2023. The operation employs seven gate domains and has drained approximately $100,000 across 80+ destination addresses on 23 blockchain networks from 350-430 victims. The infection begins with lure archives containing trojanized files, deploying a loader that implements anti-analysis checks against 67 monitoring tools. Once injected, the stealer automatically drains cryptocurrency exchange accounts through fake security overlays, converts holdings to Bitcoin, and modifies withdrawal confirmation emails. A clipboard clipper targeting two dozen cryptocurrencies replaces copied wallet addresses with operator-controlled addresses. The operation rotates Cloudflare-fronted domains faster than reputation-based detection can respond.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a malware campaign called Underground that uses an Aotera/Tedy loader to inject a Vidar-class stealer into Windows processes. The stealer targets cryptocurrency exchange accounts by injecting malicious scripts into Chrome and Edge sessions, enabling automatic theft via fake overlays and email manipulation. Additionally, a clipboard hijacker replaces legitimate cryptocurrency wallet addresses with attacker-controlled ones to divert funds. The campaign employs seven gate domains and rotates Cloudflare-fronted domains rapidly to avoid reputation-based detection. Infection starts with lure archives containing trojanized files and includes anti-analysis checks against 67 monitoring tools. The operation has stolen about $100,000 from hundreds of victims since October 2023.
Potential Impact
The malware campaign results in direct financial loss to victims by stealing cryptocurrency from exchange accounts and wallets. It manipulates browser sessions and email communications to facilitate unauthorized withdrawals and converts stolen assets to Bitcoin, complicating recovery. The clipboard hijacking further increases the risk of fund diversion by replacing copied wallet addresses. Approximately 350-430 victims have been affected, with losses totaling around $100,000 across 23 blockchain networks.
Defensive Guidance
No vendor advisory or official patch information is available for this malware campaign. Mitigation should focus on user education to avoid opening lure archives and trojanized files. Security teams should monitor for indicators of compromise such as the domains quick-neo.com and easybooters.com, and IP 95.164.53.76. Employ endpoint detection tools capable of identifying Aotera/Tedy loaders and Vidar stealers. Use multi-factor authentication on cryptocurrency accounts and verify wallet addresses manually rather than relying on clipboard contents. Due to rapid domain rotation, reputation-based detection may be insufficient, so behavioral detection and threat intelligence integration are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation"]
- Pulse Id
- 6abf599ea3419c5518645c45
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainquick-neo.com | — | |
domaineasybooters.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip95.164.53.76 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://95.164.53.76/new/log/048466C5/startCrypt | — | |
urlhttp://95.164.53.76/new/log/29A5FDA7/failed/1769331221 | — | |
urlhttp://95.164.53.76/new/log/29A5FDA7/startLoader/1769331211 | — | |
urlhttp://95.164.53.76/new/log/8320E1A4/success/1767499039 | — | |
urlhttp://95.164.53.76/new/log/8320e1a4/startloader/1767499038 | — | |
urlhttp://95.164.53.76/new/log/D9D278DD/success/1696492954 | — | |
urlhttps://easybooters.com/newlog.php' | — |
Threat ID: 6abf6144a43b0b3b898aa69d
Added to database: 10/02/2026, 07:46:12 UTC
Last enriched: 10/02/2026, 08:16:26 UTC
Last updated: 10/02/2026, 19:48:02 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.