Threats Tagged 'crypto wallets'
View all threats tagged with 'crypto wallets'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'crypto wallets'
Click on any threat for detailed analysis and mitigation recommendations
A massive malware campaign dubbed ClawHavoc has been uncovered in the ClawHub marketplace, targeting OpenClaw bots and their users. An AI bot named Alex, working with security researcher Oren Yomtov, discovered 341 malicious skills, including 335 from a single campaign. The malware, identified as Atomic Stealer (AMOS), uses sophisticated techniques to evade detection and steal sensitive data. The attack exploits users' trust in AI assistants, potentially compromising personal and financial information. In response, a new tool called Clawdex has been developed to help bots and users scan for malicious skills before installation. Join the discussion | AlienVault OTX General | 02/04/2026, 12:44:15 UTC Added: 02/04/2026, 14:15:09 UTC |
Arkanix Stealer is a newly discovered information-stealing malware designed for short-term financial gain. Initially developed in Python, it has evolved into a more sophisticated C++ version employing VMProtect obfuscation and a technique called 'Chrome Elevator' to bypass App Bound Encryption. It targets browsers, crypto wallets, VPN accounts, Steam accounts, and system information. Distributed primarily via Discord and online forums disguised as legitimate tools, it offers threat actors a web panel with premium features for managing stolen data. The malware demonstrates advanced capabilities and rapid evolution, highlighting the ease of launching cybercrime operations for quick profits. While no known exploits in the wild have been reported yet, its medium severity reflects the potential impact on confidentiality and financial assets. European organizations using targeted browsers, crypto wallets, or VPN services are at risk, especially those with users active on Discord or similar platforms. Mitigation requires targeted detection of obfuscated binaries, network monitoring for suspicious domains like arkanix.pw, and user education on social engineering risks. Countries with high crypto adoption and active gaming communities are more likely to be affected. Join the discussion | AlienVault OTX General | 12/01/2025, 19:55:01 UTC Added: 12/01/2025, 21:11:39 UTC |
Check Point Research uncovered a malware campaign exploiting expired Discord invite links to redirect users to malicious servers. The attackers use a combination of techniques including ClickFix phishing, multi-stage loaders, and time-based evasions to deliver AsyncRAT and a customized Skuld Stealer targeting crypto wallets. The campaign leverages trusted cloud services for payload delivery and data exfiltration to avoid detection. The operation continues to evolve, with threat actors now able to bypass Chrome's App Bound Encryption using adapted tools like ChromeKatz to steal cookies from new Chromium browser versions. The campaign highlights how subtle features in Discord's invite system can be exploited as attack vectors. Join the discussion | AlienVault OTX General | 06/13/2025, 14:47:04 UTC Added: 06/13/2025, 20:34:24 UTC |
Showing 1 to 3 of 3 results