Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

KelpDAO commits 2,000 ETH to DeFi united recovery fund for rsETH restoration

May 3, 2026

Steel Power Unveiled: Is SteelPower Male Enhancement Formula Legit? Read Steel Power Supplement Report!

May 2, 2026

Seoul Court Rescues Bithumb from Record 6-Month Suspension

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Crypto Wallets Under Attack By DoubleFinger Malware
Crypto Wallets Under Attack By DoubleFinger Malware
Security

Crypto Wallets Under Attack By DoubleFinger Malware

September 30, 2023No Comments2 Mins Read

Cryptocurrency wallets have been targeted by a new malware dubbed “DoubleFinger.”

The findings come from security experts at Kaspersky, who discussed the threat in a blog post published on Monday.

“As the value and popularity of cryptocurrencies continue to rise, so does the interest of cybercriminals,” commented Sergey Lozhkin, a lead security researcher at Kaspersky’s Global Research and Analysis Team (GReAT). 

The malware discovered by Kaspersky employs a multistage attack method that resembles an advanced persistent threat (APT). It starts with a malicious email attachment containing a PIF file, which triggers a chain of events.

“The group behind the DoubleFinger loader and GreetingGhoul malware stands out as a sophisticated actor with high skills in crimeware development,” Lozhkin added.

In the first stage, DoubleFinger downloads encrypted components from the image-sharing platform Imgur.com disguised as a PNG file. These components include a loader for the second stage, a legitimate java.exe file and another PNG file for later stages. 

DoubleFinger then executes its loader, bypassing security software, and launches subsequent stages.

In the fourth stage, DoubleFinger utilizes a technique called Process Doppelgänging to replace a legitimate process with a modified one, housing the fifth-stage payload. 

Finally, the GreetingGhoul crypto stealer is installed and scheduled to run daily, targeting the victim’s crypto wallets. According to Kaspersky’s technical write-up, GreetingGhoul consists of two parts. 

The first detects crypto-wallet applications in the system and steals valuable data such as private keys and seed phrases. The second overlays the interface of cryptocurrency applications, intercepting user input and enabling cyber-criminals to control and withdraw funds.

Some variations of DoubleFinger install the notorious remote access Trojan Remcos, granting cyber-criminals complete control of the infected system.

See also  JPMorgan’s Chase Bank Announces Ban on Crypto Transactions, Citing Increase in Scams Targeting Customers: Report

Read more on this Trojan: Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks

To protect crypto wallets, Kaspersky recommends vigilance against scams, diversifying wallet usage, being aware of cold wallet vulnerabilities and purchasing hardware wallets from official sources, among others.

“Protecting crypto wallets is a shared responsibility between the wallet providers, individuals, and the broader cryptocurrency community,” Lozhkin added.

“By staying vigilant, implementing strong security measures, and staying informed about the latest threats, we can mitigate the risks and ensure the safety of our valuable digital assets.”

Kaspersky’s blog post comes days after two Russian nationals were charged with stealing millions from defunct crypto exchange Mt Gox.

Source link

attack Crypto DoubleFinger Malware wallets

Related Posts

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Crypto industry backs CLARITY Act yield compromise, pushes Senate Banking for markup

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Brazil's central bank bans stablecoin and crypto settlement in cross-border payments

May 2, 2026
Top Posts

HBAR Price Prediction: Targeting $0.16 Recovery by April Amid Mixed Signals

March 13, 2026

TrueUSD was hacked and issued fake tokens

October 24, 2023

SEC makes huge U-turn, declares crypto tokens are ‘digital commodities’ after years of legal battles

March 18, 2026

Type above and press Enter to search. Press Esc to cancel.