Blockchain & AI
CHECK THOSE ADDRESSES! CRYPTOHOPPER CLONE SPREADING CRYPTO-STEALING TROJANS
Illustrating just how slick scammers have become, an imitation version of the legitimate and popular Cryptohopper website has been discovered.
Typical of the new breed of professionally designed fake websites, this particular scam, which was uncovered by Twitter user and malware researcher Fumik0_,is hard at work spreading cryptocurrency malware, according to a 5th June report on Bleeping Computer.
Vidar behind a fake CryptoCurrency trading software with a fancy website (4962c0afb925d23013f6c80433f0a453), pushing also two Qulab Variants (Clipper only & Miner variant). An example among other about the aggressive focus on Cryptocurrencies these days. pic.twitter.com/TFrzabHHHa
— Fumik0_ (@fumik0_) June 5, 2019
Apparently, merely visiting the fraudulent site causes a setup.exe installer to be downloaded. The installer, which keeps up the charade by using the Cryptohopper logo, if run, infects the computer with the Vidar information-stealing Trojan.
Vidar then installs two more Qulab trojans for the purposes of mining and clipboard hijacking – both of which are almost continuously deployed to capture data. Vidar will also scrape user data including cookies, browser history, payment information, passwords, and cryptowallet info.
Meanwhile, the Qulab clipboard hijacker will watches for a user pasting wallet address strings, then sneakily substitute a different wallet address – which it is very unlikely the user will notice given the length of addresses – in an attempt to redirect cryptocurrency transactions to the attacker’s address.
According to the report, the clipboard hijacker is able to substitute address for ether (ETH), bitcoin (BTC), bitcoin cash (BCH), dogecoin (DOGE), dash (DASH), litecoin (LTC), zcash (ZEC), bitcoin gold (BTG), xrp, and qtum.
One wallet address (1FFRitFm5rP5oY5aeTeDikpQiWRz278L45), suspected of being associated with the clipboard hijacker, is said to have received 33 BTC, worth over a quarter-of-a-million dollar, at the time of press.
Netherlands-based Cryptohopper provides automated cryptocurrency trading tools and claims to have more than 75,000 customers. At the time of press there were no comments regarding the clone site scam on the official Cryptohopper blog.
Despite all the improvements in web security, and the growing savviness of the public in general, the crypto sphere is still attracting a lot of criminal attention. Just last month, the world’s largest cryptocurrency exchange, Binance, lost €36.4m worth of bitcoin (BTC) in a massive, well-planned hack (read more).
Also, at the end of April, it emerged that over 150,000 Electrum bitcoin wallets had been infected in a major hack (read more). And, lets not forget, New Zealand-based crypto exchange Cryptopia was put out of business this year after losing around $16m worth of assets in an attack (read more).
AYO.NEWS says:
Perhaps the most concerning thing about this is, as Fumik0_ points out, the level of visual sophistication; which includes an obviously professionally designed site with a signed HTTPS certificate – something easily capable of duping even experienced customers.
Don’t get paranoid, but just remember its so easy to put together a professional looking website these days, that you need to remember to thoroughly check your URLs, and as frustrating as it might be, double check your wallet addresses before sending any funds!
AYO.NEWS says features the opinion of the author and does not necessarily reflect the views of Pentagon Digital Limited.