Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

China Revives Heavy Naval Firepower With New 155mm Gun That “Could Support An Attack On Taiwan”

June 17, 2026

Bitcoin Miners Face $50B Funding Gap as AI Pivot Separates Winners From Losers

June 17, 2026

Bitcoin miners' AI pivot faces $50 billion reality check, says VanEck

June 17, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Crypto Wallets Under Attack By DoubleFinger Malware
Crypto Wallets Under Attack By DoubleFinger Malware
Security

Crypto Wallets Under Attack By DoubleFinger Malware

September 30, 2023No Comments2 Mins Read

Cryptocurrency wallets have been targeted by a new malware dubbed “DoubleFinger.”

The findings come from security experts at Kaspersky, who discussed the threat in a blog post published on Monday.

“As the value and popularity of cryptocurrencies continue to rise, so does the interest of cybercriminals,” commented Sergey Lozhkin, a lead security researcher at Kaspersky’s Global Research and Analysis Team (GReAT). 

The malware discovered by Kaspersky employs a multistage attack method that resembles an advanced persistent threat (APT). It starts with a malicious email attachment containing a PIF file, which triggers a chain of events.

“The group behind the DoubleFinger loader and GreetingGhoul malware stands out as a sophisticated actor with high skills in crimeware development,” Lozhkin added.

In the first stage, DoubleFinger downloads encrypted components from the image-sharing platform Imgur.com disguised as a PNG file. These components include a loader for the second stage, a legitimate java.exe file and another PNG file for later stages. 

DoubleFinger then executes its loader, bypassing security software, and launches subsequent stages.

In the fourth stage, DoubleFinger utilizes a technique called Process Doppelgänging to replace a legitimate process with a modified one, housing the fifth-stage payload. 

Finally, the GreetingGhoul crypto stealer is installed and scheduled to run daily, targeting the victim’s crypto wallets. According to Kaspersky’s technical write-up, GreetingGhoul consists of two parts. 

The first detects crypto-wallet applications in the system and steals valuable data such as private keys and seed phrases. The second overlays the interface of cryptocurrency applications, intercepting user input and enabling cyber-criminals to control and withdraw funds.

Some variations of DoubleFinger install the notorious remote access Trojan Remcos, granting cyber-criminals complete control of the infected system.

See also  CoW Protocol Price Falls; $COW Releases Statement on Recent Attack

Read more on this Trojan: Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks

To protect crypto wallets, Kaspersky recommends vigilance against scams, diversifying wallet usage, being aware of cold wallet vulnerabilities and purchasing hardware wallets from official sources, among others.

“Protecting crypto wallets is a shared responsibility between the wallet providers, individuals, and the broader cryptocurrency community,” Lozhkin added.

“By staying vigilant, implementing strong security measures, and staying informed about the latest threats, we can mitigate the risks and ensure the safety of our valuable digital assets.”

Kaspersky’s blog post comes days after two Russian nationals were charged with stealing millions from defunct crypto exchange Mt Gox.

Source link

attack Crypto DoubleFinger Malware wallets

Related Posts

China Revives Heavy Naval Firepower With New 155mm Gun That “Could Support An Attack On Taiwan”

June 17, 2026

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Bitcoin.com Wallet Adds FixedFloat as a Swap Provider for Flexible Crypto Swaps

June 16, 2026
Top Posts

NCA Boss Warns That Teens Are Being “Radicalized” Online

March 20, 2026

Bitdeer Stock Jumps 9% as New LTC/DOGE Miner Debuts

March 16, 2026

‘NFTs as Subscriptions’ Is a Thing Now

November 2, 2023

Type above and press Enter to search. Press Esc to cancel.