Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

TON Price Prediction: $1.50 Target as Technical Indicators Signal Potential 13% Rally

May 2, 2026

The Cheap Foreign Labor Regime Blocking Agricultural Intelligence

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Crypto Wallets Under Attack By DoubleFinger Malware
Crypto Wallets Under Attack By DoubleFinger Malware
Security

Crypto Wallets Under Attack By DoubleFinger Malware

September 30, 2023No Comments2 Mins Read

Cryptocurrency wallets have been targeted by a new malware dubbed “DoubleFinger.”

The findings come from security experts at Kaspersky, who discussed the threat in a blog post published on Monday.

“As the value and popularity of cryptocurrencies continue to rise, so does the interest of cybercriminals,” commented Sergey Lozhkin, a lead security researcher at Kaspersky’s Global Research and Analysis Team (GReAT). 

The malware discovered by Kaspersky employs a multistage attack method that resembles an advanced persistent threat (APT). It starts with a malicious email attachment containing a PIF file, which triggers a chain of events.

“The group behind the DoubleFinger loader and GreetingGhoul malware stands out as a sophisticated actor with high skills in crimeware development,” Lozhkin added.

In the first stage, DoubleFinger downloads encrypted components from the image-sharing platform Imgur.com disguised as a PNG file. These components include a loader for the second stage, a legitimate java.exe file and another PNG file for later stages. 

DoubleFinger then executes its loader, bypassing security software, and launches subsequent stages.

In the fourth stage, DoubleFinger utilizes a technique called Process Doppelgänging to replace a legitimate process with a modified one, housing the fifth-stage payload. 

Finally, the GreetingGhoul crypto stealer is installed and scheduled to run daily, targeting the victim’s crypto wallets. According to Kaspersky’s technical write-up, GreetingGhoul consists of two parts. 

The first detects crypto-wallet applications in the system and steals valuable data such as private keys and seed phrases. The second overlays the interface of cryptocurrency applications, intercepting user input and enabling cyber-criminals to control and withdraw funds.

Some variations of DoubleFinger install the notorious remote access Trojan Remcos, granting cyber-criminals complete control of the infected system.

See also  U.S. freezes crypto network that fed nearly $800 million to North Korea’s weapons programs

Read more on this Trojan: Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks

To protect crypto wallets, Kaspersky recommends vigilance against scams, diversifying wallet usage, being aware of cold wallet vulnerabilities and purchasing hardware wallets from official sources, among others.

“Protecting crypto wallets is a shared responsibility between the wallet providers, individuals, and the broader cryptocurrency community,” Lozhkin added.

“By staying vigilant, implementing strong security measures, and staying informed about the latest threats, we can mitigate the risks and ensure the safety of our valuable digital assets.”

Kaspersky’s blog post comes days after two Russian nationals were charged with stealing millions from defunct crypto exchange Mt Gox.

Source link

attack Crypto DoubleFinger Malware wallets

Related Posts

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Brazil's central bank bans stablecoin and crypto settlement in cross-border payments

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026
Top Posts

Stablecoin Yield Fight Nears Resolution as Tillis, Alsobrooks Finalize Draft Language – Regulation Bitcoin News

April 14, 2026

XRPL Validator Sounds Alarm to XRP Users on Social Engineering Threat

April 8, 2026

Polymarket’s New DC ‘Situation Room’ Bar Lets Patrons Sip Old Fashioneds And Monitor WW3 Headlines

March 18, 2026

Type above and press Enter to search. Press Esc to cancel.