Post
Topic
Board Reputation
Merits 3 from 2 users
Re: What is going on???
by
nutildah
on 23/01/2024, 09:39:43 UTC
⭐ Merited by hugeblack (2) ,yhiaali3 (1)
So the issue seems to be infostealer malware targeting Bitcointalk users.
How do they get infected? If it's targeted attacks, they must know how to get the user to install the malware.

https://socradar.io/what-is-stealer-as-a-service/
Quote
Stealer as a Service Distributing Methods

When deploying a stealer as a service model, a major challenge for threat actors is to lead the victim to download the stealer malware. Threat actors can distribute stealer malware through a variety of attack vectors. To deliver the malware to the victims, threat actors frequently use browser extensions, exploited websites, malicious attachments, and Google ads. Some of the most common methods of infection include:

Infected legitimate app: Threat actors infect legitimate apps with malware. Stealer malware is often embedded in YouTube video reviews of popular games, mining software, or NFT (Non-Fungible Token) files on private forums, cheats for popular video games, social media giveaways, and lottery URLs.

Spam: Threat actors generally send stealers via email, often impersonating trusted organizations. The stealer can be attached to the email directly, or the recipients can be tempted to click on a malicious URL.

Compromised system: Stealer malware is sometimes distributed remotely after threat actors gain access to the target system.

Malicious advertising: Victims are redirected to a fake site to download malware by clicking on the malicious ads. In some cases, simply viewing the malicious ads can be enough to initiate the download of a stealer.

Cracked software: Combining stealer malware with cracked software is a distribution method commonly preferred by threat actors.

There may be something that these users all have in common:

- Peanutswar
- tjtonmoy
- ryzaadit
- yhiaali3

I don't think it has to do with altcoinstalks b/c it happened to Peanutswar before the account teleport option was a thing, and I'm not sure they are all members of that forum...

Could be any number of things. It could even be somebody buying stolen login credentials from the malware service subscribers.