Skip to main content

$100k in Crypto Drained by the Underground Operation

0
Medium
Published: 10/02/2026 (10/02/2026, 07:13:34 UTC)
Source: AlienVault OTX General

Description

A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader injects a Vidar-class stealer into Windows processes, launching Chrome or Edge to inject malicious scripts into victim sessions. The malware builder, dubbed Underground, has been active since October 2023. The operation employs seven gate domains and has drained approximately $100,000 across 80+ destination addresses on 23 blockchain networks from 350-430 victims. The infection begins with lure archives containing trojanized files, deploying a loader that implements anti-analysis checks against 67 monitoring tools. Once injected, the stealer automatically drains cryptocurrency exchange accounts through fake security overlays, converts holdings to Bitcoin, and modifies withdrawal confirmation emails. A clipboard clipper targeting two dozen cryptocurrencies replaces copied wallet addresses with operator-controlled addresses. The operation rotates Cloudflare-fronted domains faster than reputation-based detection can respond.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 08:16:26 UTC

Technical Analysis

This threat involves a malware campaign called Underground that uses an Aotera/Tedy loader to inject a Vidar-class stealer into Windows processes. The stealer targets cryptocurrency exchange accounts by injecting malicious scripts into Chrome and Edge sessions, enabling automatic theft via fake overlays and email manipulation. Additionally, a clipboard hijacker replaces legitimate cryptocurrency wallet addresses with attacker-controlled ones to divert funds. The campaign employs seven gate domains and rotates Cloudflare-fronted domains rapidly to avoid reputation-based detection. Infection starts with lure archives containing trojanized files and includes anti-analysis checks against 67 monitoring tools. The operation has stolen about $100,000 from hundreds of victims since October 2023.

Potential Impact

The malware campaign results in direct financial loss to victims by stealing cryptocurrency from exchange accounts and wallets. It manipulates browser sessions and email communications to facilitate unauthorized withdrawals and converts stolen assets to Bitcoin, complicating recovery. The clipboard hijacking further increases the risk of fund diversion by replacing copied wallet addresses. Approximately 350-430 victims have been affected, with losses totaling around $100,000 across 23 blockchain networks.

Defensive Guidance

No vendor advisory or official patch information is available for this malware campaign. Mitigation should focus on user education to avoid opening lure archives and trojanized files. Security teams should monitor for indicators of compromise such as the domains quick-neo.com and easybooters.com, and IP 95.164.53.76. Employ endpoint detection tools capable of identifying Aotera/Tedy loaders and Vidar stealers. Use multi-factor authentication on cryptocurrency accounts and verify wallet addresses manually rather than relying on clipboard contents. Due to rapid domain rotation, reputation-based detection may be insufficient, so behavioral detection and threat intelligence integration are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation"]
Pulse Id
6abf599ea3419c5518645c45

Indicators of Compromise

Domain

ValueDescriptionCopy
domainquick-neo.com
—
domaineasybooters.com
—

Ip

ValueDescriptionCopy
ip95.164.53.76
—

Url

ValueDescriptionCopy
urlhttp://95.164.53.76/new/log/048466C5/startCrypt
—
urlhttp://95.164.53.76/new/log/29A5FDA7/failed/1769331221
—
urlhttp://95.164.53.76/new/log/29A5FDA7/startLoader/1769331211
—
urlhttp://95.164.53.76/new/log/8320E1A4/success/1767499039
—
urlhttp://95.164.53.76/new/log/8320e1a4/startloader/1767499038
—
urlhttp://95.164.53.76/new/log/D9D278DD/success/1696492954
—
urlhttps://easybooters.com/newlog.php'
—

Threat ID: 6abf6144a43b0b3b898aa69d

Added to database: 10/02/2026, 07:46:12 UTC

Last enriched: 10/02/2026, 08:16:26 UTC

Last updated: 10/02/2026, 19:48:02 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses