BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Old Cardinal RAT Malware Resurrects Through Series Of Updates

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Israeli tech companies, beware: This malware family is back after two years in hiding.

A type of malware family not seen since 2017 has resurfaced and is targeting FinTech and cryptocurrency companies in Israel, according to a March 19 blog post from cybersecurity watchdog Unit 42.

The previous version of the malware family, dubbed Cardinal RAT, employed the Carp Downloader, which uses “malicious macros in Microsoft Excel documents to compile embedded C# (C Sharp) Programming Language source code into an executable that in turn is run to deploy the Cardinal RAT malware.”

According to Unit 42, the new version of the Cardinal RAT malware comes with updates and modifications that “evade detection and hinder analysis.” This version of Cardinal RAT uses a variety of obfuscation techniques, including hiding malicious code in in a bitmap file. Once the victim opens the file, the malware is decrypted and begins to infect the victim’s computer.

- Advertisement -

Unit 42 confirmed the updated version of Cardinal RAT infects the victim’s computer by collecting victim information, updating settings, acting as a reverse proxy, executing a command, uninstalling itself, recovering passwords, downloading and executing new files, keylogging, capturing screenshots, and cleaning cookies from browsers.

According to The Next Web, in addition to nine reports from Israel of Cardinal RAT Malware attacks, there have been two in the US and one in both Japan and Austria. To protect one’s personal data from malware attacks, Unit 42 suggests that individuals and companies beef up their spam filters and parental controls to “restrict use of scripting languages by malware” and not open or even allow “inbound e-mails with LNK file as attachments [or] … e-mails from external sources where the documents contain macros.”

Although the Cardinal RAT malware was silent for two years, there have been quite a few malware attacks targeting the personal data of people and companies. Just last month, cybersecurity firm ESET announced it discovered malware created to steal crypto wallet addresses and personal keys infecting the Google Play store.

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest Cardinal RAT, Carp Downloader or other Ethereum ecosystem news.



Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Alphabet Stock: $3,000 DCA Plan Could Reach $144K by 2036

A $3,000 initial investment followed by a $300 monthly DCA in Google's Alphabet stock...

Ledger Adds Hardware Wallet Signing for MoonPay AI Agents

Ledger hardware wallets can now be used to approve transactions initiated by MoonPay's AI...

Venus Protocol Halts THE Pool After $3.7M Exploit

Venus Protocol detected suspicious trading activity in its THE/Cake liquidity pool and paused related...

Florida’s Stablecoin Bill Raises Surveillance Concerns

Florida Governor Ron DeSantis, a vocal CBDC skeptic, may sign legislation allowing the state...

Bitcoin Aims for Key Weekly Close Above $70K Trend Line

Bitcoin inched higher over the weekend, with bulls intently focused on sealing a pivotal...

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...