Showing posts with label Cryptocurrency. Show all posts
Showing posts with label Cryptocurrency. Show all posts

Wednesday, 14 March 2018

Download.com Distributed Malware That Steals Bitcoins



The popular download site Download.com has been distributing malware for years that bitcoins from internet users have been stolen, anti-virus company ESET says today. The malware was hidden in bombarded applications called Disk Imager, Code :: Blocks and MinGW-w64.

The infected version of Disk Imager has been available on Download.com since May 2016 and was downloaded over 4500 times during that time. Code :: Blocks has been on Download.com since June 2016 and was removed from the website last year by Cnet, owner of Download.com. However, the program had already been downloaded 104,000 times. The number of downloads of MinGW-64, which was also on the website since 2016, amounted to just under 500.


The malware in the three programs was developed to steal bitcoins. Bitcoin users who want to make a payment or transfer money to another wallet often copy the wallet address of the beneficiary and then paste it into a field on the transaction page. At that moment the wallet address is in the clipboard of the computer.

The malware monitors the clipboard on infected computers and when it sees that a user is copying a wallet address, it changes this address. If the user then wants to paste the wallet address onto the transaction page, he will paste the custom wallet address and transfer money to the wrong party. The bitcoin address that the malware uses would have received a total of 8.8 bitcoin, which is currently 62,000 euros. After being informed, Cnet has removed the infected programs. It is not the first time that Download.com is in the news due to malware being offered.

Dofoil Malware (Smoke Loader): Infected MediaGet Update After Recent Cryptominer Outbreak



An infected update for the torrent client MediaGet is responsible for the large cryptominer outbreak that Microsoft warned last week. The software giant quickly discovered 400,000 cases of Dofoil malware on computers, which eventually downloaded the cryptominer.

Following screenshot is Dofoil Malware Timeline:


The cryptominer uses the computational power of the infected computers to mine cryptocurrencies. In particular computers in Russia, Turkey and Ukraine were affected by the malware. Dofoil, also known as Smoke Loader, normally spreads via infected e-mail attachments and exploit kits. Striking in the outbreak last week was that most infected files came from a process called mediaget.exe. MediaGet is a program to download torrents. In this case, the malware was not downloaded via infected torrents, but from the program itself.


Further research showed that it was a carefully planned attack, according to Microsoft . The attackers distributed an infected user update from February 12 to February 19 this year via the MediaGet update servers. This update installed a backed up version of the torrent client. From March 1 to March 6, this backdoor was then used to install malware among users. Microsoft says it has shared information with the MediaGet developers, but they have not yet reported the incident on their website.