Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

May 2, 2026

ZachXBT Exposes US Law Firm Gerstein Harrow’s $71M Grab of Stolen Lazarus Funds

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension
Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension
Security

Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension

October 1, 2023No Comments2 Mins Read

A new malware campaign has been discovered that exploits the Satacom downloader, also known as LegionLoader, to distribute a browser extension designed to steal cryptocurrency.

The Satacom downloader, a notorious malware family that emerged in 2019, is known for using DNS server queries to retrieve the next malware stage from another family associated with Satacom. 

The malware is distributed through third-party websites, sometimes leveraging legitimate advertising plugins exploited by attackers to inject malicious advertisements into web pages.

According to a new advisory by Kaspersky, the main objective of the malware dropped by the Satacom downloader is to steal Bitcoin (BTC) from victims’ accounts. It achieves this by installing a Chromium-based web browser extension that communicates with a command-and-control (C2) server. 

Read more on crypto-stealing malware: “Kekw” Malware in Python Packages Could Steal Data and Hijack Crypto

The extension employs various JavaScript scripts to manipulate users’ browsers while browsing targeted cryptocurrency websites. It can also customize the appearance of email services like Gmail, Hotmail and Yahoo to hide its activity involving the victim’s cryptocurrencies.

The initial infection occurs when a user downloads a ZIP archive file from a fake software portal containing legitimate DLLs and a malicious Setup.exe file. 

The malware spreads through different types of websites, some of which have hardcoded download links, while others inject a deceptive “Download” button using legitimate ad plugins. Kaspersky highlighted that the QUADS ad plugin had been abused to deliver the Satacom malware.

Once the malware is executed, it employs process injection techniques to evade detection by antivirus programs. The security experts said that the dynamic nature of this malware campaign poses challenges for mitigation and detection. 

See also  OpenAI launches benchmarking system for securing crypto tokens and smart contracts

Based on Kaspersky’s telemetry data, this campaign focuses on individual users globally. During Q1 2023, Brazil, Algeria, Turkey, Vietnam, Indonesia, India, Egypt and Mexico were the countries with the highest infection frequency.

Users are advised to exercise caution when downloading software from untrusted sources and to keep their antivirus software up to date to protect against such threats.

The Kaspersky advisory comes a few months after a US man was charged with fraudulently acquiring $110m worth of cryptocurrency from Mango Markets – a crypto exchange – and its customers.

Source link

browser Campaign Crypto Extension Malware Satacom Steals Stealthy

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

El Salvador Crypto Remittances Reach $17.38M

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

BTC miners grow in Georgia on low electricity rates and favorable regulations

April 7, 2026

Americans Traveling To Europe Now Forced To Take A New Step

October 30, 2023

Bitcoin hits breaking point this week as the Fed’s hidden liquidity trap threatens to drain markets despite a rate hold

February 4, 2026

Type above and press Enter to search. Press Esc to cancel.