BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Cryptocurrency Trading Site Pushes Crypto Stealing Malware

Malware distributors have setup a site that impersonates the legitimate Cryptohopper cryptocurrency trading platform in order to distribute malware payloads such as information-stealing Trojans, miners, and clipboard hijackers.

- Advertisement -

Cryptohopper is a trading platform where users can build models that will be used for automated trading of cryptocurrency on various markets.

In a new campaign discovered by malware researcher Fumik0_, attackers have created a replica of the Cryptohopper trading platform site that when visited will automatically download a Setup.exe executable as shown below.

This Setup.exe executable uses the CryptoHopper logo as its icon to make it seem like a legitimate offering from the trading platform, but is actually the Vidar information-stealing Trojan.

When executed, this Vidar variant will download required libraries and then install two Qulab trojans; one that acts as a miner and the other that acts as a clipper, or clipboard hijacker.

- Advertisement -

The QuLab associated files will be downloaded into the folders:

In order to add persistence, scheduled tasks will be created that launch the clipper and miner executables every minute.

Information-stealing capabilities

After downloading the files and configuring persistence, Vidar will begin to collect data from the machine and compile it under a random named directory in the %ProgramData% folder as shown below.

Configuration files shared with BleepingComputer by Fumik0_ show that Vidar will attempt to steal the following information:

  • browser cookies
  • browser history
  • browser payment information
  • saved login credentials
  • cryptocurrency wallets
  • text files
  • browser form autofill information
  • Authy 2FA authenticator databases
  • a screenshot of your desktop at the time of infection, and more.

This information will then be uploaded to a remote server so that it can be collected by the attackers. After sending the information, the collection of files will be removed from the infected machine, leaving behind a directory full of empty folders.

Due to the nature of the impersonated site, the potential for stolen credentials and 2 factor authentication information is particularly concerning.

As Cryptohopper is a cryptocurrency trading platform, if one of their users mistakenly goes to this fake site and installs the Trojan, their Cryptohopper credentials could be stolen and used to steal cryptocurrency stored on the platform.

Clipper component steals cryptocurrency

Vidar will also download and install the QuLab Trojan, which will perform clipper, or clipboard hijacking, functionality on the infected computer.

As cryptocurrency addresses are long and hard to remember strings, people typically copy the address into the Windows clipboard and then paste them in another application to transfer the cryptocurrency.

When QuLab detects that an address is copied into the clipboard, it will substitute the copied address with one under their control in order to steal the cryptocurrency.

The cryptocurrency addresses that are substituted by this clipper are shown in the table below.

CryptoCurrencyAddressTransactions Amount
Ethereum0xeF44179038f46b139BC4B8f7E73E479642C5B3020.001136742901273047
Bitcoin1FFRitFm5rP5oY5aeTeDikpQiWRz278L4532.87981922
Bitcoin Cashqpuzruuhf04qf9ae4ayvzq7wzyn8drwq05eczxfd960
DOGEDEHfj44qErZuUW2qqw92W2tLVQ4mfyDvXa0
DashXwhQSkYKzyqhjnipro4bhsXHtAtTJD6dbR0.10430658
LitecoinLT1Kqob5UDEML61gCyjnAcfMXgkdP3wGcg4.37138704
Zcasht1JZ7MuMn6D1B8ujUbHEkpC76sK6tG5ic810
Bitcoin GoldGf9m5PCwpwb1EG9XyJgwVosLWYX7URUBcF0
QTUMQihCFPSNPkwLNBTbVZHUAnYc5iRYaWz9em0
RipplerLQMLrMmvrva5skwyM4QzDUoGQJGhaovqy1,094

The transactions in the above cryptocurrency addresses may not be purely from this campaign, but they do show that the actor has made quite a bit of money from their malicious activities.

For example, the Bitcoin address of 1FFRitFm5rP5oY5aeTeDikpQiWRz278L45 has had a total transaction amount of 32.87981922 bitcoins. This is worth $253,238.39 at Bitcoin’s current values.

Sites created to push malware becoming more common

The creation of professionally designed sites to impersonate legitimate services or to promote fake software has become increasingly common.

For example, in May we reported that attackers have created a site to promote a fake VPN software called Pirate Chick that is used to distribute the AZORult password-stealing Trojan.

Another example is a site created to promote a fake Windows system cleaner called G-Cleaner that also installs information stealing Trojans.

To protect themselves, users should make sure the site they are visiting is the legitimate URL for the associated service. Furthermore, if these sites offer any downloads, they should be scanned using VirusTotal before being executed.

Source

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Analyst: Bitcoin’s $100K Push Needs No New Narrative

Analyst Michael van de Poppe suggests Bitcoin’s price can rise to $100,000 without a...

US Crypto CLARITY Act Advances With Stablecoin Rule Text

The CLARITY Act, which aims to provide regulatory clarity for crypto, moves closer to...

Bitcoin Targets $80K As Data Signals Strong Buy Pressure

Bitcoin's price rebounded 2.52% to above $78,800 on Friday, holding support at its 100-day...

Google AppSheet Phishing Wave Hits 30K Facebook Accounts

Vietnamese threat actors used Google AppSheet as a phishing relay to compromise roughly 30,000...

Trump to hike EU auto tariffs to 25% from next week

Former US President Donald Trump announced via social media that tariffs on European Union...

Must Read

5 Best Crypto Jobs Sites To Land Your Next Six Figure Job

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at a blistering pace, the demand for workers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading