Cryptocurrency wallets have been targeted by a new malware dubbed “DoubleFinger”.
The findings come from Kaspersky security experts, who discussed the threat in a blog post published Monday.
“As the value and popularity of cryptocurrencies continue to grow, so does the interest of cybercriminals,” commented Sergei Roshkin, chief security researcher at Kaspersky’s Global Research and Analysis Team (GReAT).
The malware discovered by Kaspersky employs a multi-stage attack technique similar to APT (Advanced Persistent Threat). The issue begins with a malicious email attachment containing a PIF file and triggers a chain of events.
“The group behind the DoubleFinger loader and GreetingGhoul malware stands out as a sophisticated threat actor with a high degree of skill in crimeware development,” Roskin added.
In the first stage, DoubleFinger downloads encrypted components from the image sharing platform Imgur.com disguised as PNG files. These components include a loader for the second stage, a legitimate java.exe file, and another of his PNG files for later stages.
DoubleFinger then bypasses the security software and executes the loader to launch subsequent stages.
In the fourth stage, DoubleFinger uses a technique called process doppelgänging to replace the legitimate process with a modified process and store the fifth stage payload.
Finally, the GreetingGhoul crypto stealer was installed and scheduled to run daily targeting the victim’s crypto wallet. According to Kaspersky’s technical documentation, GreetingGhoul consists of his two parts.
The first detects crypto wallet applications in the system and steals valuable data such as private keys and seed phrases. Second, it overlays the interface of cryptocurrency applications, intercepts user input, and allows cybercriminals to manage and withdraw funds.
Some variants of DoubleFinger install the notorious remote access Trojan Remcos, giving cybercriminals complete control over infected systems.
For more information about this Trojan, see Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attack.
To protect cryptocurrency wallets, Kaspersky recommends vigilance against fraud, diversification of wallet usage, awareness of cold wallet vulnerabilities, and purchase of hardware wallets from official sources.
“Securing cryptocurrency wallets is a shared responsibility among wallet providers, individuals and the broader cryptocurrency community,” Roskin added.
“By staying vigilant, implementing strong security measures, and staying informed about the latest threats, you can reduce risk and keep your valuable digital assets safe.”
Kaspersky’s blog post comes days after two Russians were indicted for stealing millions of dollars from defunct cryptocurrency exchange Mt. Gox.