YourCryptoNews
  • Live Prices
  • Crypto News
    • Altcoins
    • Bitcoin
  • Defi News
  • NFT News
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
YourCryptoNews
  • Live Prices
  • Crypto News
    • Altcoins
    • Bitcoin
  • Defi News
  • NFT News
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
YourCryptoNews
No Result
View All Result

Solana Phantom security update NFTs push password-stealing malware

October 9, 2022
in NFT News
Reading Time: 3 mins read
A A
Solana Phantom security update NFTs push password-stealing malware
ShareShareShareShareShare

You might also like

Defiance shuts world’s first NFT-focused crypto industry ETF | ETF Strategy

Defiance shuts world’s first NFT-focused crypto industry ETF | ETF Strategy

February 2, 2023
Star power? Growing list of celeb endorsers showing up in crypto/NFT lawsuits

Star power? Growing list of celeb endorsers showing up in crypto/NFT lawsuits

February 1, 2023

Hackers are airdropping NFTs to Solana cryptocurrency owners pretending to be alerts for a new Phantom security update that lead to the installation of password-stealing malware and the theft of cryptocurrency wallets.

This ongoing attack started two weeks ago, with NFTs titled ‘PHANTOMUPDATE.COM’ or ‘UPDATEPHANTOM.COM’ sent that claim to be warnings from the developers of Phantom.

When opening the NFTs, wallet owners are told that a new security update has been released and that they should click the enclosed link or visit the site to download and install it.

“Phantom requires all users to update their wallets. This must be done as soon as possible,” reads the warning in the fake Phantom update NFT.

“Failing to do so, may result in loss of funds due to hackers exploiting the Solana network. Visit www.updatePhantom.com to get the latest security update.”

Fake Phantom security update NFTs
Fake Phantom security update NFTs
Source: BleepingComputer

When visiting these sites from any device (desktop or mobile), the site automatically downloads a Windows batch file named Phantom_Update_2022-10-08.bat [VirusTotal] from DropBox. Previous campaigns were downloading executables named Phantom_Update_2022-10-04.exe.

When the batch file is launched, it will check if it is running with Administrator privileges and, if not, show a Windows UAC prompt asking for permissions.

Windows UAC prompt requesting admin privileges
Windows UAC prompt requesting admin privileges
Source: BleepingComputer

If the UAC prompt is accepted, a PowerShell script will be launched that decrypts further commands to execute in Windows.

Batch file downloaded from fake Phantom Update sites
Batch file downloaded from fake Phantom Update sites
Source: BleepingComputer

Ultimately, this will lead to a windll32.exe executable [VirusTotal] being downloaded from GitHub and executed from the C:Users<username>AppDataLocal folder.

windll32.exe malware installed on Windows
windll32.exe malware installed on Windows
Source: BleepingComputer

According to VirusTotal, the windll32.exe file is a password-stealing malware that attempts to steal browser information, such as history, cookies, and passwords, as well as SSH keys and other information. 

While it is unclear what specific password-stealing trojan is currently being spread, previous campaigns distributed a file name lib64.exe [VirusTotal], which was identified as MarsStealer.

MarsStealer is an information-stealing malware launched in 2020 and steals data from all popular web browsers, two-factor authentication plugins, and multiple cryptocurrency extensions and wallets.

The goal of this campaign is likely to steal cryptocurrency wallets and passwords that would allow the threat actors to steal all crypto funds and compromise other accounts belonging to the victim.

Victims who installed the fake Phantom security update should immediately scan their computer with an antivirus program and then transfer crypto funds and assets from their existing Phantom wallet to a new one.

Next, victims should change their passwords on all sites they use, focusing on cryptocurrency trading platforms, online wallets, bank accounts, email, or other sensitive platforms.

Ultimately, victims should change their password to a unique one for every site they visit to prevent credential leaks at one site from affecting other sites.

Credit: Source link

Related Stories

Defiance shuts world’s first NFT-focused crypto industry ETF | ETF Strategy
NFT News

Defiance shuts world’s first NFT-focused crypto industry ETF | ETF Strategy

February 2, 2023
Star power? Growing list of celeb endorsers showing up in crypto/NFT lawsuits
NFT News

Star power? Growing list of celeb endorsers showing up in crypto/NFT lawsuits

February 1, 2023
Coinbase NFT Pauses Creator Drops, Insists Marketplace Is Not Shutting Down
NFT News

Coinbase NFT Pauses Creator Drops, Insists Marketplace Is Not Shutting Down

February 1, 2023
OpenSea’s Polygon NFT Sales Top Ethereum for Second Straight Month
NFT News

OpenSea’s Polygon NFT Sales Top Ethereum for Second Straight Month

February 1, 2023
Next Post
Cardano NFTs are the best NFTs – Experts

Cardano NFTs are the best NFTs - Experts

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Top White House Officials Ask Congress to Frame Regulatory Framework for Crypto

Top White House Officials Ask Congress to Frame Regulatory Framework for Crypto

January 28, 2023
Web3 Wallets Providing Users with Risk Notifications 

Web3 Wallets Providing Users with Risk Notifications 

February 1, 2023

Popular Story

    • Contact Us
    • Privacy Policy
    • Terms of Use
    • DMCA

    © 2021 - YourCryptoNews.net - All rights reserved!

    No Result
    View All Result
    • Live Prices
    • Crypto News
      • Altcoins
      • Bitcoin
    • Defi News
    • NFT News
    • Blockchain
    • Regulations
    • Trading
    • Scams

    © 2021 - YourCryptoNews.net - All rights reserved!

    • bitcoinBitcoin (BTC) $ 23,892.00 3.42%
    • ethereumEthereum (ETH) $ 1,674.43 6.21%
    • tetherTether (USDT) $ 1.00 0.22%
    • bnbBNB (BNB) $ 331.11 7.43%
    • usd-coinUSD Coin (USDC) $ 1.00 0.19%
    • xrpXRP (XRP) $ 0.414291 3.23%
    • binance-usdBinance USD (BUSD) $ 1.00 0.32%
    • cardanoCardano (ADA) $ 0.403694 5.5%
    • dogecoinDogecoin (DOGE) $ 0.093799 1.4%
    • matic-networkPolygon (MATIC) $ 1.24 12.98%
    • okbOKB (OKB) $ 40.20 7.38%
    • solanaSolana (SOL) $ 24.97 5.98%
    • staked-etherLido Staked Ether (STETH) $ 1,667.38 6.29%
    • polkadotPolkadot (DOT) $ 6.54 5.61%
    • litecoinLitecoin (LTC) $ 100.79 4.39%
    • shiba-inuShiba Inu (SHIB) $ 0.000012 3.59%
    • avalanche-2Avalanche (AVAX) $ 21.95 14.45%
    • tronTRON (TRX) $ 0.063687 2.68%
    • uniswapUniswap (UNI) $ 7.03 7.64%
    • daiDai (DAI) $ 1.00 0.13%
    • cosmosCosmos Hub (ATOM) $ 14.90 9.9%
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 23,837.00 3.42%
    • the-open-networkToncoin (TON) $ 2.48 8.17%
    • chainlinkChainlink (LINK) $ 7.29 6.54%
    • moneroMonero (XMR) $ 179.17 2.88%
    • leo-tokenLEO Token (LEO) $ 3.37 6.79%
    • ethereum-classicEthereum Classic (ETC) $ 22.67 6.16%
    • aptosAptos (APT) $ 18.26 9.99%
    • bitcoin-cashBitcoin Cash (BCH) $ 138.40 4.9%
    • stellarStellar (XLM) $ 0.093410 4.32%
    • apecoinApeCoin (APE) $ 6.22 7.08%
    • quant-networkQuant (QNT) $ 149.76 8.33%
    • filecoinFilecoin (FIL) $ 5.73 11.37%
    • nearNEAR Protocol (NEAR) $ 2.47 10.4%
    • crypto-com-chainCronos (CRO) $ 0.081270 3.34%
    • lido-daoLido DAO (LDO) $ 2.33 7.17%
    • algorandAlgorand (ALGO) $ 0.256568 8.26%
    • vechainVeChain (VET) $ 0.024959 10.03%
    • hedera-hashgraphHedera (HBAR) $ 0.069099 8.69%
    • internet-computerInternet Computer (ICP) $ 6.02 2.69%
    • fantomFantom (FTM) $ 0.575396 9.81%
    • decentralandDecentraland (MANA) $ 0.794149 8.47%
    • axie-infinityAxie Infinity (AXS) $ 11.65 9.48%
    • aaveAave (AAVE) $ 91.87 13.13%
    • the-sandboxThe Sandbox (SAND) $ 0.764028 7.76%
    • flowFlow (FLOW) $ 1.15 10.01%
    • eosEOS (EOS) $ 1.09 3.48%
    • elrond-erd-2MultiversX (EGLD) $ 44.40 5.48%
    • theta-tokenTheta Network (THETA) $ 1.09 8.2%
    • terra-lunaTerra Luna Classic (LUNC) $ 0.000174 2.52%