Cybersecurity firm Kaspersky has identified a newly discovered malware framework designed to target cryptocurrency investors through social engineering tactics and trojanized applications hosted on GitHub. The malware, which Kaspersky says represents a growing threat to digital asset holders, uses deceptive software downloads to infiltrate victims systems and steal sensitive financial information.
According to Kasperskys threat research team, the attack campaign relies on fake GitHub repositories that appear to offer legitimate cryptocurrency-related tools and applications. Unsuspecting investors who download and run these trojanized applications unknowingly install the malware framework, which then gains access to wallet credentials, private keys, and other critical data.
The malware framework employs multiple techniques to avoid detection, including code obfuscation and anti-analysis measures that make it difficult for traditional security software to identify the threat. Once installed, it can monitor clipboard activity for cryptocurrency addresses, intercept browser sessions related to crypto exchanges, and exfiltrate stored credentials from password managers.
Kaspersky noted that the campaign appears to be actively targeting users across multiple blockchain networks and cryptocurrency platforms. The company advised investors to exercise caution when downloading software from GitHub and other third-party sources, even when the repositories appear to be maintained by legitimate developers.
Security researchers recommend verifying the authenticity of any cryptocurrency tool before installation, using hardware wallets for storing significant amounts of digital assets, and maintaining updated antivirus protection. Users should also enable two-factor authentication on all exchange accounts and avoid running unverified code from unknown sources.
This article was adapted from Cointelegraph. Read the original here.
