KryptoCibule: The Cryptostealing Malware

ESET antivirus researchers have announced the discovery of an unknown trojan malware family that spreads through malicious torrents and uses multiple methods to extract as many cryptocurrencies from its victims as possible while remaining undetected.

- Advertisement -

ESET named the threat KryptoCibule and, according to its telemetry, the malware appears to target mainly users in the Czech Republic and Slovakia.

Triple Threat

This malware poses a triple threat to cryptocurrencies. It uses the victim’s resources to mine currencies, attempts to infiltrate transactions by replacing wallet addresses on the clipboard, extracts files related to cryptocurrencies, and develops multiple techniques to remain undetected. KryptoCibule makes extensive use of the Tor network and BitTorrent protocol in its communication infrastructure.

How KryptoCibule malware works
How KryptoCibule works. Source: WeLiveSecurity

ESET has identified many versions of KryptoCibule, allowing them to study its evolution from December 2018 to the present day. The malware remains active, new features were added during its lifetime and is under constant development.

Victims Located in Czech Republic and Slovakia

Most of the victims are located in the Czech Republic and Slovakia, and this reflects the user base of the site where the infected torrents are located. Almost all malicious torrents were available on uloz.to, a popular file-sharing site in both countries.

In addition, KryptoCibule specifically checks for the presence of ESET, Avast and AVG security products.

More technical details about KryptoCibule can be read in the relevant blogpost on WeLiveSecurity.

- Advertisement -

Previous Articles:

Stay in the Loop

Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.

    1 Email per day. Unsubscribe at any time.

    - Advertisement -

    Latest News

    IREN Shares Jump 11% as July Bitcoin Production Tops MARA

    IREN Ltd shares rose 11.4% after reporting $86 million in July revenue and strong...

    S Token Launches on Coinbase, Sonic Unveils Summit and Updates

    The S token is now available for trading on Coinbase and can be used...

    Uber Seeks Billions in Funding to Expand Robotaxi Fleet and Tech

    Uber is seeking funding from banks and private firms to expand its Robotaxi operations. Partners...

    Polkadot Surges as Corporate, Institutional Buyers Drive DOT Rally

    Large buyers showed strong interest in Polkadot's DOT over 24 hours. Corporate treasury activity and...

    VexTrio Viper Pushes Scam Apps on Apple, Google Stores, Millions Hit

    Fake apps linked to VexTrio Viper appeared on official Apple and Google app stores,...

    Must Read

    What Are Anonymous Debit Cards And How Do They Work?

    You've heard about anonymous debit cards, but what are they really? Anonymous Debit Cards are cards that let you make purchases without revealing your...