Feb 19, 2023

Malicious Crypto-Themed Campaign Steals from Unwary Investors

Cryptocurrency investors have been warned to remain vigilant against malicious software targeting their investments. In a report by Cisco Talos, two new malicious computer programs have been identified as actively stealing crypto from unsuspecting investors since December 2022.

The two malicious files, MortalKombat ransomware and Laplas Clipper malware, are designed to work in tandem to target user wallets. The malicious software monitors the user’s clipboard, which usually contains a string of letters and numbers copied by the user. If it detects a wallet address, it will replace it with a different address, thus sending the cryptocurrencies to an unknown attacker.

Victimology of the malicious campaign. Source: Cisco Talos

The attack has been targeting individuals and organizations of all sizes, with the majority of victims located in the United States, as well as the United Kingdom, Turkey and the Philippines.

Once infected, the MortalKombat ransomware encrypts the user’s files and drops a ransom note with payment instructions. The malicious software is spread via a cryptocurrency-themed email containing a malicious attachment. The attachment runs a BAT file that helps download and execute the ransomware when opened.

In light of the attack, investors are urged to be extra cautious when investing in crypto and to always ensure that the source of communications is legitimate. Additionally, as ransomware victims continue to refuse extortion demands, ransomware revenues for attackers have dropped 40% to $456.8 million in 2022.

In conclusion, investors should remain vigilant against malicious software targeting their investments.

