Connect with us

Hi, what are you looking for?

Crypto
Crypto
#image_title

Cryptocurrency

Malware targeting crypto users hides in fake office add-ins

Cybercriminals have infused malware into the fake Microsoft Office add-ins that target cryptocurrency users.  The malware hides in the clipboard and changes the wallet addresses of regular users. These fake add-ins, like SourceForge, can easily rob you of your money and data without your notice.

Cybercriminals have found a smart way to take your crypto using fake Microsoft Office add-ons that steal your money.  Many users download the tools that are disguised as normal tools, as these fake add-ins are available on SourceForge. But these packages come with a stealthy malware called ClipBanker that siphons off your crypto without you knowing.

ClipBanker does its job in the background, taking over one of the most widely performed actions by crypto users: copying and pasting wallet addresses. After a user copies a wallet address to the clipboard, the malware switches it to that of the attacker’s. Most users use copy-paste instead of typing long wallet addresses, so this substitution goes unnoticed most of the time until they unknowingly send their funds to the wrong address.

One such vendor, “Office Package,” uses a fake Office add-in with download buttons copied from authentic pages. Once people install the extension, it initiates a relentless attack. The malicious program hijacks your clipboard and collects your system information like IP address, geolocation, and username, which it sends to hackers via Telegram. Moreover, it uses anti-detection techniques; if it detects any antivirus, it will erase itself to avoid detection.

Cybersecurity professionals have highlighted more alarming signs, like suspiciously small file sizes that don’t match what Office software usually produces and files that have been stuffed with random crap.

The dangers extend beyond stolen funds. When hackers seize control of the device, they can use it for other criminal activities. Other criminals could profit from this access and carry out even more devastating actions. The hackers want your crypto transaction, but they can exploit you more over time.

The interface of the fake add-in is Russian; this shows at least the Russian-speaking users are targeted.  The data shows that thousands, mostly Russians, have come across this malware already.

To protect yourself from this danger, do not download anything from unverified or unofficial sources. Furthermore, be careful about suspicious extensions, even the harmless ones. Cyber criminals are becoming even more sophisticated and are on the rise as crypto usage increases. Keeping up-to-date and following best practices is essential for safeguarding digital assets from ever-more-sophisticated attacks.

author avatar
CryptoCorn
CryptoCorn is Editor and Author at 4C Media Co. and covers all stories and news related to Crypto & Finance. Excellent blogger and Passionate Crypto Trader. Follow her on twitter at @cryptocorn7.
Advertisement

You May Also Like

Cryptocurrency

This week’s Crypto Chronicle explores Ripple's potential SEC settlement, Canada’s leap ahead with Solana ETFs, growing controversy around MANTRA token, and Meta’s aggressive push...

Cryptocurrency

Mantra’s CEO, Mullin John, will burn 300 million locked team tokens, which is approximately 17% of its total, after the steep price drop of...

AI

OpenAI is said to be developing a new social media platform built around its ChatGPT and image tools, which could rival Elon Musk’s X...

Cryptocurrency

On 16th April, Canada is going to launch the first-ever spot Solana (SOL) ETFs, which will also have a staking facility.  Canada’s launch of...

polkadot
Polkadot (DOT) $ 3.82 1.69%
bitcoin
Bitcoin (BTC) $ 86,891.00 2.82%
ethereum
Ethereum (ETH) $ 1,574.44 0.36%
cardano
Cardano (ADA) $ 0.62046 0.88%
xrp
XRP (XRP) $ 2.07 0.80%
stellar
Stellar (XLM) $ 0.252564 4.47%
litecoin
Litecoin (LTC) $ 77.71 1.22%