Author

Topic: ViperSoftX - A new Trojan that steals cryptocurrencies through a Chrome extensio (Read 115 times)

legendary
Activity: 2450
Merit: 4415
🔐BitcoinMessage.Tools🔑
I thought ViperSoftX has been discovered almost three years ago by a company named FortiGuard Labs; a news article with a description can be found here: https://www.fortinet.com/blog/threat-research/vipersoftx-new-javascript-threat. This malware is a remote access trojan combined with clipboard malware that replaces users' bitcoin and ethereum addresses with hacker's. When a user executes some commands on their computer, malware checks if the information in the clipboard matches certain regex patterns and, if needed, inserts malicious addresses into the machine's clipboard.

Quote
Changing the clipboard data is done based on the OS version. On Windows 10 it uses PowerShell’s scp. Otherwise, it runs cmd as follows:

Cmd.exe /c echo|set /p=[address to set]|clip


Naturally, clipboard malware is not as effective as direct stealing of wallet data and private keys, and much easier to detect, which is why hackers strive to improve their malware to be able to monitor activity on a computer as long as possible.
legendary
Activity: 3374
Merit: 3095
Playbet.io - Crypto Casino and Sportsbook
I have experience installing randomly in my chrome browser and firefox plugin but I don't install it mainly on the PC that I usually use for financial activity, I install it on my Vbox l. Those plugins and extensions that I use are mostly for SEO tools and they sometimes have malware so to protect my PC I use Vbox or use extra hard drives only for unknown extensions or plugins. So I agree with the above it's the user's fault because most of the users are illiterate so we can't blame them either.

And the Avast itself most of the software from Avast is malware I don't use them. The last time that use Avast free gives me a few ads and if you uninstall Avast without using their uninstall tool from their website I'm sure your PC will slow down and you will experience BSOD(Blue screen of death). I experience this many times with Avast so better stay away from using them.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
I believe the problem is not with windows or the browser. The problem here is with the user.
Why install so many extensions? Everyone who cares about security and privacy should avoid installing extensions in their browser.

You are right there, the problem lies in the users and their habits, and above all cracked software that they download from torrents and various suspicious sites. The only extensions that everyone should have are uBlock Origin and Privacy Badger, which can be downloaded from the official browser stores.

As for the news itself, I am always divided on the fact that AV companies use such things to advertise themselves, especially those that have a very problematic past with spying on their users and selling their data to whoever is willing to pay for it.
legendary
Activity: 2352
Merit: 6089
bitcoindata.science
What are we seeing? Again, Windows systems and the Chrome browser Everyone is strongly advised to start studying Linux systems and not to trust this browser and, even more, various extensions that supposedly simplify the work on the Internet.

I believe the problem is not with windows or the browser. The problem here is with the user.
Why install so many extensions? Everyone who cares about security and privacy should avoid installing extensions in their browser.

Everything you install in your computer or smartphone is potentially a spyware or a malware, i.e., it could be collecting your data (most of them do that) or just do bad things to your device.

Before installing anything, think twice if you really need that extension/app
legendary
Activity: 2072
Merit: 4265
✿♥‿♥✿
Avast experts have discovered malware that steals information from users of Windows systems.

Quote
We’ve been closely monitoring an information stealer called ViperSoftX.

They named the USA, India, Italy and Brazil among the most affected countries.

Quote
This multi-stage stealer exhibits interesting hiding capabilities, concealed as small PowerShell scripts on a single line in the middle of otherwise innocent-looking large log files, among others. ViperSoftX focuses on stealing cryptocurrencies, clipboard swapping, fingerprinting the infected machine, as well as downloading and executing arbitrary additional payloads, or executing commands.

Quote
One of the payloads ViperSoftX distributes is a specific information stealer in the form of a browser extension for Chromium-based browsers. Due to its standalone capabilities and uniqueness, we decided to give it its own name, VenomSoftX. The malicious extension provides full access to every page the victim visits, carries out man-in-the-browser attacks to perform cryptocurrency addresses swapping by tampering with API requests’ data on popular cryptocurrency exchanges, steals credentials and clipboard content, tampers with crypto addresses on visited websites, reports events using MQTT to the C&C server, and more.

ViperSoftX is mostly spread via cracked software such as Adobe Illustrator, Corel Video Studio, Microsoft Office, and more, commonly distributed over torrents.
https://decoded.avast.io/janrubin/vipersoftx-hiding-in-system-logs-and-spreading-venomsoftx/

What are we seeing? Again, Windows systems and the Chrome browser Everyone is strongly advised to start studying Linux systems and not to trust this browser and, even more, various extensions that supposedly simplify the work on the Internet.
Jump to: