Fun

News Feed - 2023-08-25 01:08:36

Martin Young4 hours agoWinRAR patches zero-day bug that targeted stock and crypto tradersAccording to cybersecurity firm Group-IB, weaponized ZIP file archives were being shared on crypto trading forums, with each one containing a nasty surprise.999 Total views18 Total sharesListen to article 0:00NewsJoin us on social networksThe developers behind file compression software WinRAR have patched a zero-day vulnerability that allowed hackers to install malware onto unsuspecting victims" computers, enabling them to hack into their crypto and stock trading accounts.


On Aug. 23, Singapore-based cybersecurity firm Group-IB reported a zero-day vulnerability in the processing of the ZIP file format by WinRAR.


The zero-day vulnerability tracked as CVE-2023-38831 was exploited for approximately four months, allowing hackers to install malware when a victim clicked on files in an archive. The malware would then allow hackers to breach online crypto and stock trading accounts, according to the report.


Using the exploit, the threat actors were able to create malicious RAR and ZIP archives that displayed seemingly innocent files such as JPG images or PDF text documents. These weaponized ZIP archives were then distributed on trading forums targeting crypto traders, offering strategies such as “best Personal Strategy to trade with Bitcoin.”“Once extracted and executed, the malware allows threat actors to withdraw money from broker accounts. This vulnerability has been exploited since April 2023.”


The report confirmed that the malicious archives found their way onto at least eight public trading forums infecting at least 130 devices, however, the victim"s financial losses were unknown.WinRar exploit infection chain. Source: Group-IB


On execution, the script launches a self-extracting (SFX) archive that infects the target computer with various malware strains, such as the DarkMe, GuLoader and Remcos RAT.


These provide the attacker with remote access privileges on the infected computer. DarkMe malware has previously been used in crypto and financially motivated attacks.


The researchers notified RARLABS which patched the zero-day vulnerability in WinRAR version 6.23, released on Aug. 2.


Related:Crypto investors under attack by new malware, reveals Cisco Talos


In August, smartphone giant BlackBerry identified several malware families that actively aimed to hijack computers to mine or steal cryptocurrencies.


The same month also revealed a newly discovered remote access tool called HVNC (Hidden Virtual Network Computer) that can enable hackers to compromise Apple operating systems was found on sale on the dark web.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:Should crypto projects ever negotiate with hackers? Probably# Business# Malware# Hackers# Cybercrime# CybersecurityAdd reactionAdd reactionRead moreHow to send and receive payments on the Lightning NetworkOpinion: Why did Bitget seize more than $200,000 of my money?The future of BTC mining and the Bitcoin halving

News Feed

Elliptic Analysis Says $477 Million Stolen From FTX, ‘Accounts Drainer’ Becomes 35th Largest ETH Holder
Elliptic Analysis Says $477 Million Stolen From FTX, "Accounts Drainer" Becomes 35th Largest ETH Holder Three days ago, on Nov. 11, 2022, it was reported that FTX’s wallets
Brayden Lindrea8 hours agoBlockchain Association files support in suit to lift Tornado Cash sanctionsThe crypto advocacy group said OFAC must act within its statutory authority by sanctioning bad actors, not open-source
Bitcoin UTXO Signal Approaches 99% Level – Bullish Signal Or Profit-Taking Setup?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Coin Center Says OFAC’s Tornado Cash Ban ‘Exceeds Statutory Authority,’ Plans to ‘Engage’ With US Watchdog
Coin Center Says OFAC"s Tornado Cash Ban "Exceeds Statutory Authority," Plans to "Engage" With US Watchdog On August 15, the non-profit that focuses on policy issues facing crypto
South Korea Reportedly Freezes Do Kwon’s Crypto Worth $40M — Luna Founder Says the Funds Are Not His
South Korea Reportedly Freezes Do Kwon"s Crypto Worth $40M — Luna Founder Says the Funds Are Not His South Korean authorities have reportedly frozen $40 million in crypto assets,
Biggest Movers: LTC Races to 9-Month High, ATOM Extends Recent Gains
Biggest Movers: LTC Races to 9-Month High, ATOM Extends Recent Gains Litecoin raced to a nine-month high on Feb. 1, following a breakout of a key resistance level. The surge in pri
Hundreds of Darknet Listings Are Selling Masks and PPE Products for Bitcoin
Hundreds of Darknet Listings Are Selling Masks and PPE Products for BitcoinAccording to a recent research report written by the blockchain surveillance firm Elliptic, there’s
Tether’s Market Valuation Grows 144% in 2020, USDT Market Cap Worth $10 Billion
Tether"s Market Valuation Grows 144% in 2020, USDT Market Cap Worth $10 BillionThe most popular stablecoin, Tether, has propelled its way into the third-largest position by cryptocu
Bitcoin Holds Strong In ‘Wall Of Worry’, Path To $183,000 Remains Open – Analyst
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Holograph fell 80% in 9 hours after exploiter mints 1B additional HLG
Brayden Lindrea6 hours agoHolograph fell 80% in 9 hours after exploiter mints 1B additional HLGThe 1 billion HLG tokens were worth $14.4 million at the time of the first mint, Etherscan data shows.1451 Total views11 Tota
Cryptowisser: Then, Now and What’s Next for NFTs
Cryptowisser: Then, Now and What"s Next for NFTs sponsored Non-Fungible Tokens (NFTs) have been around for some time now, with what is recognized as the first-ever NFT “ Quan
Web3 adoption’s main issue: Seed phrases won’t work for 95% of mainstream users
Zoltan Vardai8 hours agoWeb3 adoption’s main issue: Seed phrases won’t work for 95% of mainstream usersCrypto wallets with easier sign-in options and recoverable passwords could become the industry standard in the fu