Backdoored cryptocurrency software found serving AZORult malware

Mohammad.Poorya

Bardzo aktywny
Ekspert
Dołączył
19 Wrzesień 2018
Posty
3452
Reakcje/Polubienia
13973
Miasto
On a Bike!
EXCLUSIVE --Hackers have compromised the GitHub account of the Denarius cryptocurrency project lead and have backdoored the Windows client with the AZORult infostealer malware.

The compromised
Zaloguj lub Zarejestruj się aby zobaczyć!
cryptocurrency client --which node operators run on their servers to support the Denarius blockchain-- was spotted earlier today by a security researcher named
Zaloguj lub Zarejestruj się aby zobaczyć!
, who alerted ZDNet.
ZDNet independently confirmed the researcher's findings with the help of RiskIQ threat researcher
Zaloguj lub Zarejestruj się aby zobaczyć!
.

Carsen Klock, the top dev behind the Denarius cryptocurrency, said the incident occurred because he reused an older password to secure his GitHub account.
This allowed a hacker to silently access his GitHub account and upload a backdoored version of the Denarius Window client --
Zaloguj lub Zarejestruj się aby zobaczyć!
, released on January 22.

According to Misterch0c and Klijnsma, this file (
Zaloguj lub Zarejestruj się aby zobaczyć!
) was a modified Denarius client installer that installed a version of the AZORult malware.
"The .bat file is started, which it will start the other bins in sequence, with smaller one being AZORult," Klijnsma said after analyzing the backdoored Denarius installer.

Once installed on a user's computer,
Zaloguj lub Zarejestruj się aby zobaczyć!
can steal a vast array of user data, such as browser passwords, browser cookies, passwords for FTP clients, chat histories, and most importantly, wallet database files from popular cryptocurrency clients.

Read More & SOURCE...
Zaloguj lub Zarejestruj się aby zobaczyć!
 
Do góry