Threats Tagged 'cryptocurrency theft'
View all threats tagged with 'cryptocurrency theft'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cryptocurrency theft'
Click on any threat for detailed analysis and mitigation recommendations
In 2026, the DPRK-sponsored Lazarus subgroup TraderTraitor continued campaigns targeting cryptocurrency entities, including a high-profile attack on LayerZero resulting in $292 million theft from KelpDAO. Following this disclosure, an additional victim was identified: a smaller IT services provider in India with no cryptocurrency connections. The compromise involved a DevOps engineer targeted through fake job interview lures containing weaponized Terraform coding projects. Malicious GitHub repositories used typosquatted provider domains to deliver macOS backdoors FLATROOF and ROOFDECK when victims executed terraform init. The backdoors enabled reconnaissance, credential theft, and cloud environment escalation. One day after LayerZero's public disclosure, attackers deployed an updated stripped version of ROOFDECK and removed earlier implants. Activity continued until June 2026, suggesting the threat actor ultimately abandoned the intrusion after determining insufficient value from the smaller target. Join the discussion | AlienVault OTX General | 09/19/2026, 08:44:15 UTC Added: 09/21/2026, 08:46:37 UTC |
Six Chrome and Firefox extensions linked through shared code, C2 infrastructure, and publishing history have been identified targeting cryptocurrency traders. Four malicious extensions steal authenticated session tokens and wallet data from Axiom Trade and Padre users, while two earlier extensions reveal a pattern of repackaging crypto trading tools. The extensions J7Tracker, VREO, and Orbit Tracker automatically retrieve user information, wallet bundles, Firebase tokens, and application state, then exfiltrate data to threat actor-controlled Vercel deployments. The campaign targets an active trading community with Axiom processing over $15 billion in volume across 650,000 wallets. The malicious code runs inside authenticated sessions, collecting localStorage, IndexedDB data, and API responses containing authentication tokens and wallet keys. Data is Base64-encoded and transmitted via browser navigation to avoid CORS restrictions, enabling account compromise and cryptocurrency theft. Join the discussion | AlienVault OTX General | 09/10/2026, 02:31:34 UTC Added: 09/10/2026, 09:22:42 UTC |
0 Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms. Join the discussion | Cisco Talos | 09/08/2026, 12:22:29 UTC Added: 09/08/2026, 10:06:36 UTC |
On August 31, 2026, U.S., Bulgarian, Hungarian, and Romanian authorities, collaborating with CrowdStrike and Shadowserver Foundation, successfully disrupted the Sality botnet through a peer-to-peer sinkhole operation. Active since 2003, Sality infects Windows executables and spreads malware for credential theft, spam distribution, and DDoS attacks. The botnet delivered EggJagger clipper malware, stealing at least $150,000 through cryptocurrency wallet substitution. The takedown exploited Sality's P2P architecture weakness by manipulating peer lists, isolating over 15,000 infected machines from threat actor control. This peer list manipulation technique prevented payload distribution by inserting sinkhole entries and removing legitimate peers. Associated domains were seized across U.S. and Europe. While the disruption stops new payloads, existing infections remain active requiring remediation. The operation demonstrates that resilient P2P criminal infrastructure can be dismantled through coordinated law enf... Join the discussion | AlienVault OTX General | 09/02/2026, 09:56:00 UTC Added: 09/02/2026, 11:37:30 UTC |
A campaign identified by the Socket Threat Research team involves 19 malicious browser extensions (18 for Chrome, 1 for Edge) active since February 2024. These extensions deliver a modular malware framework that communicates with command and control servers via WebSocket, strips Content Security Policy headers, and uses cross-site scripting (XSS) injection to execute payloads. The primary goal is to steal cryptocurrency wallet secrets and drain crypto assets, as well as harvest credentials. The threat actor either creates malicious extensions from scratch or compromises legitimate extensions with existing user bases, such as the 'Enable Right Click & Copy' extension with tens of thousands of users. The campaign, named 'Superior,' shows sophisticated and evolving capabilities targeting multiple cryptocurrency platforms and exchanges. Join the discussion | AlienVault OTX General | 08/27/2026, 22:16:26 UTC Added: 08/28/2026, 08:52:30 UTC |
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries. Join the discussion | AlienVault OTX General | 08/20/2026, 11:45:48 UTC Added: 08/20/2026, 23:22:26 UTC |
Following Black Hat and DEF CON conferences, a threat actor targeted attendees through X direct messages, posing as CoinDesk's VP and Head of Marketing to establish trust under the pretext of conference planning. The campaign employed a malicious Google Apps Script embedded in a Google Doc that presented ClickFix-style instructions and manual download options. The attack delivered different payloads based on the victim's operating system: macOS users received AMOS infostealer, while Windows users were infected with NetSupport RAT, a Ledger wallet implant, and a TLS-intercepting proxy. A secondary lure masqueraded as a DocSend installer to deliver additional payloads. The operation demonstrated sophisticated social engineering by leveraging trusted platforms and post-conference networking expectations. Join the discussion | AlienVault OTX General | 08/19/2026, 15:56:58 UTC Added: 08/20/2026, 23:07:12 UTC |
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking. Join the discussion | AlienVault OTX General | 08/19/2026, 11:25:09 UTC Added: 08/19/2026, 15:52:33 UTC |
In February 2026, an active malware delivery campaign named Powercat was observed distributing infostealer malware disguised as utility or cheat software for popular PC games including Roblox, Minecraft, and Grand Theft Auto V. The multi-stage infection chain begins with an initial executable that profiles victims and establishes persistence, followed by a Java-based loader that deploys the final infostealer payload. The malware targets cryptocurrency wallets (Exodus, Atomic, Monero-Gui), browser data from Chromium-based applications, Discord tokens, and gaming accounts with payment information. It includes surveillance capabilities such as keylogging, webcam capture, and screen recording. The campaign particularly targets children who frequent gaming platforms and pay-to-cheat websites, with evidence suggesting collected personal information may be used for blackmail or coercion into illegal activities. Join the discussion | AlienVault OTX General | 08/10/2026, 13:45:53 UTC Added: 08/10/2026, 15:56:14 UTC |
0 Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting. Join the discussion | CVE Database V5 | 08/07/2026, 02:45:38 UTC Added: 05/13/2026, 18:36:36 UTC |
Showing 1 to 10 of 41 results