Cybersecurity News
Filters
Filtered by tag: cryptocurrency × Clear
Security experts targeted by fake crypto conference in scam to hand over details
Cybersecurity researchers are being targeted by a scam involving a fake cryptocurrency conference. Attackers invite professionals to speak or attend, then direct them to a fraudulent website that delivers information-stealing malware, including AMOS. The scheme exploits the credibility of conference invitations to trick even security-savvy victims into compromising their own systems.
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Matched: cryptocurrency
ToxicPanda malware has been updated with 167 remote commands and expanded global targeting, according to Zimperium zLabs. The Android banking trojan now includes PIN harvesting capabilities targeting over 140 banking and cryptocurrency apps. Researchers also noted connections to the GoldDigger malware family, with both conducting on-device fraud to bypass traditional security measures.
15 Malicious Firefox Extensions Abuse Cloudflare Workers to Exfiltrate Crypto Wallet Secrets
Matched: cryptocurrency
Fifteen malicious Firefox extensions posing as crypto wallets, themes, and browser tools have been stealing recovery phrases, private keys, login credentials, and clipboard data since at least March 2026. The campaign uses Cloudflare Workers to exfiltrate stolen information and spans 77 extensions total, putting users' digital assets and online accounts at serious risk.
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Matched: cryptocurrency
Researchers found 40 malicious Firefox extensions disguised as Web3 products like OKX and Rabby Wallet that steal cryptocurrency wallet credentials. Dubbed "Offside Wallet Theft Factory" by Socket Threat Research, the extensions are part of a broader group of 77 add-ons sharing code and infrastructure. Users are advised to verify extensions carefully before installing.
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Matched: cryptocurrency
Attackers posing as Web3 recruiters on LinkedIn lured cryptocurrency professionals into fake job interviews, ultimately tricking Windows users into installing malware via a signed ClickOnce application. The infection deployed NeedleStealer, which harvested private keys and browser data, alongside an hVNC remote access trojan. The campaign used Calendly scheduling and technical assessments to appear legitimate.
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Matched: cryptocurrency
Phantom Stealer is a credential-stealing malware that conceals malicious code inside PNG image files to avoid detection. Once executed on Windows systems, it harvests passwords, browser cookies, cryptocurrency wallet data, and other sensitive information. The malware has been used in campaigns targeting users across multiple countries.
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Matched: cryptocurrency
Researchers created a fake crypto startup and hired three suspected North Korean IT workers to study their tactics. Every company device was monitored. The operation revealed red flags hiring teams can watch for: one worker claimed to live in Texas but submitted a California driver's license and a New York bank account, exposing the inconsistencies North Korean operatives typically display during onboarding.
Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram
Matched: cryptocurrency
A malicious VS Code extension called Solidity Pro has been discovered stealing cryptocurrency wallet data, API keys, and SSH keys from developers. Disguised as a legitimate Solidity development tool with polished documentation, the extension exfiltrates stolen data via Telegram. The attack highlights how convincing branding and familiar tooling can lower developers' guard against supply chain threats.
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Matched: cryptocurrency
A ClickFix-style attack campaign is targeting macOS users with Go-based malware that steals cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the host before delivering a CPU-compatible payload, allowing attackers to drain crypto wallets and harvest sensitive data from compromised machines.
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A Mac user was tricked by a fake CAPTCHA prompt into running a Terminal command that installed Go-based malware. The attack, a variant of the ClickFix scam, gave attackers access to macOS Keychain passwords and cryptocurrency wallets. Security researchers warn the technique is growing more common and targets users across platforms.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Matched: cryptocurrency
Attackers modified a JavaScript file from ad tech firm Adform to silently replace cryptocurrency wallet addresses in users' browsers. The malicious script, active on July 27, 2026, targeted Bitcoin and other crypto addresses copied by visitors to affected sites. Adform detected and removed the code the same day, notified clients, and reported the incident to authorities. Users who transacted on July 27 should verify their wallet addresses.
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
Matched: cryptocurrency
North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.
