• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Analysis

Kaspersky Flags Malware on SourceForge That Tricks Victims Into Sending Attackers Their Crypto

admin by admin
April 25, 2025
in Analysis
0
Kaspersky Flags Malware on SourceForge That Tricks Victims Into Sending Attackers Their Crypto
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Cybersecurity firm Kasperky has discovered a malware which tricks victims into sending attackers their crypto by replacing trusted wallet addresses on a users’ clip board.

The malware is being distributed under the guise of Microsoft Office Add-Ins on the SourceForge website.

Related articles

ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

May 28, 2025
Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

May 28, 2025

In reality, alternate links are being used to install this malware and infiltrate crypto wallets. The coding appears to be in Russian with an expected 90% of potential victims in Russia, Kaspersky researchers wrote in a post on their SecureList blog.

However, the link does lead to a website written in English for the download—suggesting this could expand far wider than Russia.

Once installed, the malware places ClipBanker on the device, which is a malware that replaces cryptocurrency addresses in the clipboard with the attacker’s own.

Since most crypto wallet users tend to copy and paste addresses, rather than typing them, the address replacement usually goes undetected until the victim’s money is sent somewhere they did not intend.

Kaspersky warns that this could do even more damage.

“The persistence methods are worthy of note as well. Attackers secure access to an infected system through multiple methods, including unconventional ones,” the researchers wrote. “While the attack primarily targets cryptocurrency by deploying a miner and ClipBanker, the attackers could sell system access to more dangerous actors.”

It’s worth noting that SourceForge is a legitimate website for hosting software downloads and that this exploit relies on users being taken to another download link, which is not safe.

A seemingly legitimate link redirects to a page where users are encouraged to download the infected software.

The download appears to be a legitimate 700MB installer, but it’s mostly filled with junk files. The actual malware is just 7MB.

According to the report, some 4,604 Russian users have encountered this scheme between early January and late March alone.

Kaspersky warns: “We advise users against downloading software from untrusted sources. If you are unable to obtain some software from official sources for any reason, remember that seeking alternative download options always carries higher security risks.”

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



#Kaspersky #Flags #Malware #SourceForge #Tricks #Victims #Sending #Attackers #Crypto

Tags: 919 blackrock s bitcoin anda complete surprise in late marchAttackersattackers their crypto bybtc past 200k in 2025bulls overcome the barrier the linkchico california clearly employingcloudbet is opening no limitcommunity around the organization s corecongress according to digital asset cryptographycreate a community owned ai protocolcryptocrypto by replacingcrypto walletdevelopment refueling in orbit which likelyFlagsid what is the link betweenin other news blockchainjunk filesKasperskymalwaremint megaeth soperations p p last weekp p kraken sp tsx compositepeople deemed un americanSendingsolana meme coin act i theSourceForgethat replaces cryptocurrency addresses in thethe consumer price index cpi alsothe link does lead to aTricksvictimswallet security tips li liwallet userswith over 13 billion cryptowp caption text two
Share76Tweet47

Related Posts

ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

by admin
May 28, 2025
0

In brief ASIC has filed civil charges against former Blockchain Global director Liang Guo over alleged misuse of ACX customer...

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

by admin
May 28, 2025
0

Six days after a $223 million exploit shook the Sui ecosystem, decentralized exchange Cetus has announced a recovery initiative that...

El Salvador Defies IMF Again With Fresh Bitcoin Purchase Following Loan Review

El Salvador Defies IMF Again With Fresh Bitcoin Purchase Following Loan Review

by admin
May 28, 2025
0

In brief El Salvador added eight more Bitcoin to its reserve despite IMF warnings An IMF agreement struck on Tuesday...

AI and Crypto Czar David Sacks Says the US Could Buy More Bitcoin

AI and Crypto Czar David Sacks Says the US Could Buy More Bitcoin

by admin
May 28, 2025
0

In brief AI and Crypto Czar David Sacks appeared at Bitcoin 2025 in Las Vegas on Tuesday. Sacks suggested that...

Ethereum Options Market Signals Cautious Optimism as Open Interest Climbs

Ethereum Options Market Signals Cautious Optimism as Open Interest Climbs

by admin
May 28, 2025
0

In brief Amberdata data shows only a 12% chance of ETH exceeding $5,000 by December 2025. Retail traders are targeting...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

May 28, 2025
Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

May 28, 2025
Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

May 28, 2025
Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

May 28, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com