Monday, August 2, 2021
Only Bitcoin Market News
Bitcoin Tax Solutions
  • Home
  • Crypto Wallet Uk
  • Bitcoin
  • Market
  • Cash
  • Price
  • Beginners
  • Gold
  • Private
  • Cryptos
  • Investors
  • Technical
  • Crash
  • Spam
  • Stock
  • Blockchain
  • Videos
  • New Betting Sites UK
  • Home
  • Bitcoin
  • Market
  • Cash
  • Price
  • Beginners
  • Gold
  • Private
  • Cryptos
  • Investors
  • Technical
  • Crash
  • Spam
  • Stock
  • Blockchain
  • Videos
Only Bitcoin Market News
No Result
View All Result

‘Panda Stealer’ Targets Cryptocurrency Wallets

1 month ago
in Spam
2 min read
‘Panda Stealer’ Targets Cryptocurrency Wallets
Share on FacebookShare on Twitter


Cryptocurrency Fraud
,
Cybercrime
,
Fraud Management & Cybercrime

Malware Spread Through Spam Email Campaign

Prajeet Nair (@prajeetspeaks) •
May 7, 2021    

'Panda Stealer' Targets Cryptocurrency Wallets

Researchers at Trend Micro have uncovered a new cryptocurrency stealer variant that uses a fileless approach in its global spam email distribution campaign to evade detection.

See Also: Live Webinar | The Role of Passwords in the Hybrid Workforce

The gang behind the malware, dubbed “Panda Stealer,” starts with emails that appear to be business quote requests to entice recipients to open malicious Excel files, Trend Micro says.

Researchers found that the malware, a modification of Collector Stealer, has targeted victims in the United States, Australia, Japan and Germany.

Infection Chains

Trend Micro identified two infection chains. One uses an .XLSM attachment that contains macros that download a loader, which then downloads and executes the main stealer.

The second infection chain method involves an attached .XLS file containing an Excel formula that uses a PowerShell command to access paste.ee, a Pastebin alternative, which accesses a second encrypted PowerShell command.

“Decoding these PowerShell scripts revealed that they are used to access paste.ee URLs for easy implementation of fileless payloads. The CallByName export function in Visual Basic is used to call the loading of a .NET assembly within memory from a paste.ee URL. The loaded assembly, obfuscated with an Agile.NET obfuscator, hollows a legitimate MSBuild.exe process and replaces it with its payload: the hex-encoded Panda Stealer binary from another paste.ee URL,” according to the Trend Micro researchers.

Stealing Information

Once it’s installed on a device, Panda Stealer can collect private keys and records of past transactions from victim’s digital currency wallets, including Dash, Bytecoin, Litecoin and Ethereum.

“Not only does it target cryptocurrency wallets, it can steal credentials from other applications, such as NordVPN, Telegram, Discord chat app and Steam,” the researchers note. “It’s also capable of taking screenshots of the infected computer and exfiltrating data from browsers, like cookies, passwords and cards.”

After stealing information, the malware stores stolen files in a %TEMP% folder under random file names. The files are…



Read more:‘Panda Stealer’ Targets Cryptocurrency Wallets

Related articles

How To Spot A Bitcoin Scam

How To Spot A Bitcoin Scam

August 1, 2021
‘Bitcoin’ Scam Ads Continue To Plague Facebook Despite Policy Overhaul

‘Bitcoin’ Scam Ads Continue To Plague Facebook Despite Policy Overhaul

July 31, 2021
Tags: bitcoin news todayCryptocurrencyDiscordPandaPanda StealerStealerTargetsTrend MicroWallets

Related Posts

How To Spot A Bitcoin Scam

How To Spot A Bitcoin Scam

by Bitcoin Market
August 1, 2021
0

Whenever something gets hot, the only guarantee is that scamsters will lock onto it like a heat-seeking missile. The...

‘Bitcoin’ Scam Ads Continue To Plague Facebook Despite Policy Overhaul

‘Bitcoin’ Scam Ads Continue To Plague Facebook Despite Policy Overhaul

by Bitcoin Market
July 31, 2021
0

Bitcoin scam ads, luring Facebook users with promises of riches using binary trading platforms, continue to plague the social...

Scams in Norfolk: DVLA emails, Hermes texts, and investment fraud

Scams in Norfolk: DVLA emails, Hermes texts, and investment fraud

by Bitcoin Market
July 31, 2021
0

Norfolk County Council has warned of scams currently running in the county. Be wary texts claiming to be about a missed Hermes...

“Nasty” sexploitation scam demands bitcoin ransom

“Nasty” sexploitation scam demands bitcoin ransom

by Bitcoin Market
July 30, 2021
0

Using stolen passwords to get a victim's attention, a new sexploitation scam threatens victims with exposing them "doing nasty...

‘Freaked out’ Sydney woman issues ‘Zoom scam’ warning after being BLACKMAILED over

‘Freaked out’ Sydney woman issues ‘Zoom scam’ warning after being BLACKMAILED over

by Bitcoin Market
July 30, 2021
0

A Sydney woman has issued a warning after being targeted in a sextortion scam that left her “freaked out”.Jessica*...

Load More

Trend Now

  • Trending
  • Comments
  • Latest
5 Cryptocurrency Staking Providers – A Review | Hacker Noon

5 Cryptocurrency Staking Providers - A Review | Hacker Noon

January 30, 2021
Crypto-Powered Social Media Platform Voice Planning Launch for July 4 | CryptoGlobe

Crypto-Powered Social Media Platform Voice Planning Launch for July 4 | CryptoGlobe

June 8, 2020
‘It will be ugly’: Bitcoin bear gives 2 reasons why he thinks the ‘bubble’ is going

‘It will be ugly’: Bitcoin bear gives 2 reasons why he thinks the ‘bubble’ is going

April 20, 2021
Argo Blockchain boosts mining margins in July

Argo Blockchain boosts mining margins in July

August 5, 2020
J.K. Rowling Twitter Storm shows the Crypto Ecosystem Needs to Mature – CityAM

J.K. Rowling Twitter Storm shows the Crypto Ecosystem Needs to Mature - CityAM

May 19, 2020
North America’s first bitcoin ETF launches in Canada today

North America’s first bitcoin ETF launches in Canada today

February 18, 2021
U.S. Promoter of Foreign Cryptocurrency Companies Pleads Guilty for Role in

U.S. Promoter of Foreign Cryptocurrency Companies Pleads Guilty for Role in

0
Bitcoin daily chart alert – Bullish chart pattern develops – May 19

Bitcoin daily chart alert - Bullish chart pattern develops - May 19

0
Calvin Ayre Invests in True Reviews: A New Take on Consumer Review Sites Built on the

Calvin Ayre Invests in True Reviews: A New Take on Consumer Review Sites Built on the

0
J.K. Rowling Twitter Storm shows the Crypto Ecosystem Needs to Mature – CityAM

J.K. Rowling Twitter Storm shows the Crypto Ecosystem Needs to Mature - CityAM

0
Crypto.com’s MCO Visa Cards Are Now Shipping In Europe – Fintech Singapore

Crypto.com’s MCO Visa Cards Are Now Shipping In Europe - Fintech Singapore

0
Elon Musk tried to explain Bitcoin to JK Rowling on Twitter and this happened

Elon Musk tried to explain Bitcoin to JK Rowling on Twitter and this happened

0
U.S. Promoter of Foreign Cryptocurrency Companies Pleads Guilty for Role in

U.S. Promoter of Foreign Cryptocurrency Companies Pleads Guilty for Role in

August 2, 2021
China SMBs Complete Transfers Using Blockchain

China SMBs Complete Transfers Using Blockchain

August 2, 2021
Bitcoin is headed toward its worst month since 2011; ‘Rich Dad, Poor Dad’ author

Bitcoin rallies above $40,000, then pulls back again

August 2, 2021
Baby Doge coin crypto continues to rise. But is it the best token right now?

Baby Doge coin crypto continues to rise. But is it the best token right now?

August 2, 2021
Promoter of Crypto Scheme Touted by Steven Seagal Pleads Guilty, Faces 5 Years in

Promoter of Crypto Scheme Touted by Steven Seagal Pleads Guilty, Faces 5 Years in

August 1, 2021
WallStreetBets Founder Talks About GameStop, WSB Future, and How It’s Related to

WallStreetBets Founder Talks About GameStop, WSB Future, and How It’s Related to

August 1, 2021
  • Contact Us
  • Terms of Use
  • Cookie Privacy Policy
  • Privacy Policy
  • DMCA

© 2020 MarketForBitcoin.com

No Result
View All Result
  • Home
  • Bitcoin
  • Market
  • Cash
  • Price
  • Beginners
  • Gold
  • Private
  • Cryptos
  • Investors
  • Technical
  • Crash
  • Spam
  • Stock
  • Blockchain
  • Videos

© 2020 MarketForBitcoin.com

  • Bitcoin(BTC)$56,605.00-1.12%
  • Bitcoin Cash(BCH)$1,422.397.04%
  • Binance Coin(BNB)$657.52-0.15%
  • Bitcoin Gold(BTG)$117.79-3.40%
  • Bitcoin Private(BTCP)$2.04-10.21%
  • Blocktix(TIX)$0.0120.00%