Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension
Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension
Security

Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension

October 1, 2023No Comments2 Mins Read

A new malware campaign has been discovered that exploits the Satacom downloader, also known as LegionLoader, to distribute a browser extension designed to steal cryptocurrency.

The Satacom downloader, a notorious malware family that emerged in 2019, is known for using DNS server queries to retrieve the next malware stage from another family associated with Satacom. 

The malware is distributed through third-party websites, sometimes leveraging legitimate advertising plugins exploited by attackers to inject malicious advertisements into web pages.

According to a new advisory by Kaspersky, the main objective of the malware dropped by the Satacom downloader is to steal Bitcoin (BTC) from victims’ accounts. It achieves this by installing a Chromium-based web browser extension that communicates with a command-and-control (C2) server. 

Read more on crypto-stealing malware: “Kekw” Malware in Python Packages Could Steal Data and Hijack Crypto

The extension employs various JavaScript scripts to manipulate users’ browsers while browsing targeted cryptocurrency websites. It can also customize the appearance of email services like Gmail, Hotmail and Yahoo to hide its activity involving the victim’s cryptocurrencies.

The initial infection occurs when a user downloads a ZIP archive file from a fake software portal containing legitimate DLLs and a malicious Setup.exe file. 

The malware spreads through different types of websites, some of which have hardcoded download links, while others inject a deceptive “Download” button using legitimate ad plugins. Kaspersky highlighted that the QUADS ad plugin had been abused to deliver the Satacom malware.

Once the malware is executed, it employs process injection techniques to evade detection by antivirus programs. The security experts said that the dynamic nature of this malware campaign poses challenges for mitigation and detection. 

See also  Critical Warning for XRP Ledger Users Issued by Top Contributor

Based on Kaspersky’s telemetry data, this campaign focuses on individual users globally. During Q1 2023, Brazil, Algeria, Turkey, Vietnam, Indonesia, India, Egypt and Mexico were the countries with the highest infection frequency.

Users are advised to exercise caution when downloading software from untrusted sources and to keep their antivirus software up to date to protect against such threats.

The Kaspersky advisory comes a few months after a US man was charged with fraudulently acquiring $110m worth of cryptocurrency from Mango Markets – a crypto exchange – and its customers.

Source link

browser Campaign Crypto Extension Malware Satacom Steals Stealthy

Related Posts

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Bitcoin.com Wallet Adds FixedFloat as a Swap Provider for Flexible Crypto Swaps

June 16, 2026

India Should Mine Bitcoin Domestically to Curb Dollar Outflow, Says Crypto Educator

June 16, 2026
Top Posts

Stani Kulechov: Aave’s token-centric model enhances value capture, V4 introduces a hub and spoke architecture, and DAOs boost governance resilience

February 19, 2026

PEPE Gained 20% in One Day, What Could Be Behind the Rally?

September 27, 2023

Judge shoots down disgraced FTX founder Sam Bankman-Fried’s new request for pretrial release

September 29, 2023

Type above and press Enter to search. Press Esc to cancel.