New Malware Swaps Out Crypto Wallet Addresses as You Type Them

A newly discovered piece of malware can secretly steal your crypto wallets and passwords.

Sep 27, 2019 at 5:00 p.m. UTC
Updated Sep 13, 2021 at 11:30 a.m. UTC

A new bit of malware called Masad Stealer can replace wallet addresses as you type them thanks to malicious code injected into your browser. According to Juniper Networks, it also steals:

PC and system information

Credit Card Browser Data

Browser passwords

Installed software and processes

Desktop Files

Screenshot of Desktop

Browser cookies

Steam files

AutoFill browser fields

Discord and Telegram data

FileZilla files

The program dumps this information to the malware controller's Telegram account, ensuring relative security for the data it steals. It can also clip and change monero, litecoin, zcash, dash and ethereum addresses automatically and uses special search functions to pinpoint these addresses on your clipboard. Once it swaps the addresses it can intercept crypto as its being sent to legitimate wallets.

The particular version of the malware Juniper studied sent crypto to this wallet which currently contains almost a one full bitcoin.

"Based on our telemetry, Masad Stealer’s main distribution vectors are masquerading as a legitimate tool or bundling themselves into third party tools," wrote the research organization. "Threat actors achieve end user downloads by advertising in forums, on third party download sites or on file sharing sites."

The software masquerades as useful-looking software like Tradebot_binance.exe, Galaxy Software Update.exe, and Fortniteaimbot  2019.exe. Once infected, the computer then begins communicating with the command and control Telegram channel and sends back private data.

The malware allegedly costs $40 on the dark web and is completely configurable and very dangerous, said Juniper.

"Juniper Threat Labs believes that Masad Stealer represents an active and ongoing threat.  Command and Control bots are still alive and responding as of this writing, and the malware appears to still be available for purchase on the black market," wrote the researchers.

Hacker image via Michael Geiger/Unsplash

The Festival for the Decentralized World
Thursday - Sunday, June 9-12, 2022
Austin, Texas
Save a Seat Now

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

Trending

1
Blockchain Gaming Developer N3TWORK Studios Closes $46M Funding Led by Griffin Gaming

The firm will release two crypto-native games focused around Web 3 following the Series A raise.

The firm will release two crypto-native games focused around Web 3 following the Series A raise.

2
Bitcoin, Major Cryptos Slide as Markets Digest Hawkish Powell Remarks

A day after the U.S. Federal Reserve chair pledged to keep tightening monetary conditions until inflation comes down, analysts and traders from crypto to stocks and futures were assessing the economic impact – from higher mortgage rates to lower company earnings.

A day after the U.S. Federal Reserve chair pledged to keep tightening monetary conditions until inflation comes down, analysts and traders from crypto to stocks and futures were assessing the economic impact – from higher mortgage rates to lower company earnings.

3
Swiss ETP Issuer 21Shares Dives Into US Market With 2 Crypto Index Funds

The new funds are its first crypto products for U.S. customers and will only be available to accredited investors.

The new funds are its first crypto products for U.S. customers and will only be available to accredited investors.

4
Will a Proof-of-Stake Ethereum Lead to More Centralization?

Lido’s staking protocol now holds 33% of all staked ether.

Lido’s staking protocol now holds 33% of all staked ether.