Blockchain & AI
FAKE TOR BROWSER STEALING BITCOIN FROM RUSSIANS SINCE 2017
Antivirus software firm ESET has warned about a trojanised Tor browser that has apparently been busty stealing Bitcoin (BTC) on the darknet since 2017.
The Slovakia-based security company says that the fake Tor was being distributed by two websites, and swaps user entered crypto addresses with its own. As we’ve reported before, this is very hard to detect given the fact that crypto addresses are so long, meaning people normally copy-and-paste, without checking carefully.
Apparently, the trojan has been targeting users in Russia since 2017, but the fake websites tor-browser[.]org and torproect[.]org actually date from as far back as 2014. Mimicking the real Tor website, torproject.org, the fake sites apparently prompt users to update their versions of Tor to the ‘latest version’ – however, the download contains the malware.
ESET says the malware seems to be confined to Windows, with no reports of anything on Linux, macOS or mobile. The company has identified three wallets involved in the scam, and says its seems to have got away with 4.8 BTC to-date, with the latest transaction being registered last month.
AYO.NEWS says:
This could explain why Finnish peer-to-peer cryptocurrency exchange LocalBitcoins issued a warning about Tor in mid-September (read more) – perhaps having heard reports from Tor users who lost BTC, but not knowing any further details.
One notable feature of this scam is that it stole Bitcoin over a long period, in what looks like relatively small amounts – a strategy that often makes scams much harder to detect.
AYO.NEWS says features the opinion of the author and does not necessarily reflect the views of Pentagon Digital Limited.