Cybersecurity News

Filters
Tag
Reset

Filtered by tag: cryptocurrency × Clear

Security experts targeted by fake crypto conference in scam to hand over details

Cybersecurity researchers are being targeted by a scam involving a fake cryptocurrency conference. Attackers invite professionals to speak or attend, then direct them to a fraudulent website that delivers information-stealing malware, including AMOS. The scheme exploits the credibility of conference invitations to trick even security-savvy victims into compromising their own systems.

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Matched: cryptocurrency

ToxicPanda malware has been updated with 167 remote commands and expanded global targeting, according to Zimperium zLabs. The Android banking trojan now includes PIN harvesting capabilities targeting over 140 banking and cryptocurrency apps. Researchers also noted connections to the GoldDigger malware family, with both conducting on-device fraud to bypass traditional security measures.

15 Malicious Firefox Extensions Abuse Cloudflare Workers to Exfiltrate Crypto Wallet Secrets

Matched: cryptocurrency

Fifteen malicious Firefox extensions posing as crypto wallets, themes, and browser tools have been stealing recovery phrases, private keys, login credentials, and clipboard data since at least March 2026. The campaign uses Cloudflare Workers to exfiltrate stolen information and spans 77 extensions total, putting users' digital assets and online accounts at serious risk.

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Matched: cryptocurrency

Researchers found 40 malicious Firefox extensions disguised as Web3 products like OKX and Rabby Wallet that steal cryptocurrency wallet credentials. Dubbed "Offside Wallet Theft Factory" by Socket Threat Research, the extensions are part of a broader group of 77 add-ons sharing code and infrastructure. Users are advised to verify extensions carefully before installing.

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT

Matched: cryptocurrency

Attackers posing as Web3 recruiters on LinkedIn lured cryptocurrency professionals into fake job interviews, ultimately tricking Windows users into installing malware via a signed ClickOnce application. The infection deployed NeedleStealer, which harvested private keys and browser data, alongside an hVNC remote access trojan. The campaign used Calendly scheduling and technical assessments to appear legitimate.

Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

Matched: cryptocurrency

Phantom Stealer is a credential-stealing malware that conceals malicious code inside PNG image files to avoid detection. Once executed on Windows systems, it harvests passwords, browser cookies, cryptocurrency wallet data, and other sensitive information. The malware has been used in campaigns targeting users across multiple countries.

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Matched: cryptocurrency

Researchers created a fake crypto startup and hired three suspected North Korean IT workers to study their tactics. Every company device was monitored. The operation revealed red flags hiring teams can watch for: one worker claimed to live in Texas but submitted a California driver's license and a New York bank account, exposing the inconsistencies North Korean operatives typically display during onboarding.

Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram

Matched: cryptocurrency

A malicious VS Code extension called Solidity Pro has been discovered stealing cryptocurrency wallet data, API keys, and SSH keys from developers. Disguised as a legitimate Solidity development tool with polished documentation, the extension exfiltrates stolen data via Telegram. The attack highlights how convincing branding and familiar tooling can lower developers' guard against supply chain threats.

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

Matched: cryptocurrency

A ClickFix-style attack campaign is targeting macOS users with Go-based malware that steals cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the host before delivering a CPU-compatible payload, allowing attackers to drain crypto wallets and harvest sensitive data from compromised machines.

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Matched: cryptocurrency

Attackers modified a JavaScript file from ad tech firm Adform to silently replace cryptocurrency wallet addresses in users' browsers. The malicious script, active on July 27, 2026, targeted Bitcoin and other crypto addresses copied by visitors to affected sites. Adform detected and removed the code the same day, notified clients, and reported the incident to authorities. Users who transacted on July 27 should verify their wallet addresses.

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

Matched: cryptocurrency

North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.