BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Tor Browser Steals Cryptocurrency from Darknet Market Users

A trojanized version of the Tor Browser is targeting dark web market shoppers to steal their cryptocurrency and tracks the websites they visit.

- Advertisement -

More than 860 transactions are registered to three of the attackers’ wallets, which received about $40,000 in Bitcoin cryptocurrency.

Careful impersonation

The malicious Tor Browser is actively promoted as the Russian version of the original product through posts on Pastebin that are have been optimized to rank high in queries for drugs, cryptocurrency, censorship bypass, and Russian politicians.

Spam messages also help the actor(s) distribute the trojanized variant, which is delivered from two domains claiming to provide the official Russian version of the software.

Cybercriminals were careful with selecting the two domain names (created in 2014) since to a Russian user they appear to be the real deal:

- Advertisement -
  • tor-browser[.]org
  • torproect[.]org – for Russian-speaking visitors, the missing “j” may be seen as a transliteration from Cyrillic

Furthermore, the design of the pages mimic, to some extent, the official site of the project. Landing on one of these pages shows the visitor a warning that their browser is updated, regardless of the version they run.

Translated into English, the message reads:

“Your anonymity is in danger! WARNING: Your Tor Browser is outdated. Click the button “Update”

In Pastebin messages, the cybercriminals advertise that users would benefit from anti-captcha feature allowing them to get faster to the destination.

This is not true, though. Underneath this Tor Browser impersonator is version 7.5 of the official project, released in January 2018.

Getting the cryptocurrency

The downloaded script can modify the page by stealing content in forms, hiding original content, showing fake messages, or add its own content.

These capabilities allow the script to replace in real-time the destination wallet for cryptocurrency transactions. The JavaScript observed by ESET does exactly this.

The targets are users of the three largest Russian-speaking darknet markets, the researchers say. For the payload they observed (image above), the script also alters the details for the Qiwi payment service provider.

When victims add Bitcoin funds to their account, the script jumps in and changes the wallet address with one belonging to the attackers.

Since cryptocurrency wallets are a large string of random characters, users are likely to miss the swap.

Darknet profile with altered Bitcoin address

At the moment of publishing, the three cryptocurency wallets controlled by the attackers recorded 863 transactions. These are small transfers, supporting the theory that the funds came via the trojanized Tor Browser.

One of them received more than $20,000 from over 370 transactions. The largest balance, though, is currently around $50 in one wallet and less than $2 in the other two.

The three wallets have been used for this purpose since 2017, the researchers found. Although the amount of Bitcoins that passed through these wallets is 4.8, the total proceedings for the attackers is likely higher because Qiwi payment details are also altered.

Source

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Dmail Network Shuts Down After Five-Year Decentralized Run

Decentralized email platform Dmail Network will officially begin ceasing its services on May 15...

Bank of Canada Study: Aave V3 Had Zero Bad Loans in 2024

A Bank of Canada staff analysis found Aave V3 had zero non-performing loans in...

Tech Giants Found AI Payment Protocol Group

The x402 Foundation launched on Thursday by the Linux Foundation to govern an AI...

Elliptic Links $286M Drift Protocol Hack to North Korea

Elliptic attributes the $286 million exploit of Drift Protocol to actors linked to North...

Coinbase Wins Trust Charter, Won’t Become A Bank

Coinbase received conditional approval from the U.S. Office of the Comptroller of the Currency...

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading