Automatically translated.View original post

Phishing Release Malware OKBot Steal Seed Bag Crypto

Phishing campaign detected, released OKBot malware, stole Seed, Trezor bags and Ledger.

According to a report by the website The Hacker News, it mentioned the detection of a Phishing scam campaign in the OKBot malware release scam (which is not listed by the source, but expected from the name may be a malware type, switching the victim's machine to a network of hackers, or Botnet), whose detection was the work of a GReAT research team from Kaspersky, a popular anti-Virus software developer. The research team found two ways of using the scam together:

The deception runs code on its own machine by claiming to confirm identity or correct errors, a method called ClickFix.

The use of malware embedding software deposited on GitHub's Repo or Repository. The detected case is an advertising method that the deposited software is SQL Server Management Studio software. But when it was downloaded inside, it was a software to customize the sound called Audacity with malware embedded. The research team found that the Repo was created around March 2025 (2025) and was deleted during the last June.

Both ways lead to running a PowerShell script downloader like TookPS. The downloaded script acts to install SSH, contact the control server (C2 or Command and

Control), set up a Forward Port to SSH Daemon Port to receive commands from the C2 server and wait for commands to be sent to the malware. In the meantime, the malware will secretly steal files related to the password (Credential), Crypto Wallet, Web Browser Profile information, and Cookes files to be sent out to hackers through the Tunnel, scan for Anti-Virus software on board, then modify the Registry to turn off Microsoft Defender notifications and open the entrance. The system provides a way for hackers to manage the system.

Open Firewall for incoming Remote Desktop Protocol

Add a hacker's account to the Remote Desktop Users Group.

Overlap the termsrv.dll file with a modified version to allow hackers to use RDP on the current Sessions forever.

Make Task Scheduling (Task Scheduling) under the name Apple Sync, which will serve to create Reverse SSH Tunnel for Local RDP Port every hour.

After that, the malware downloads modules from the control server (C2 or Command and Control), which initially consists of two key tools:

HDUtil is a launcher that is prevented from running in simulated conditions (VM or Virtual Machine). It is used to run modules and tools, as well as has the ability to upgrade system privileges through Windows RPC (Remote Procedure Call), a Windows tool that has the ability to raise general user privileges to the highest attendant level (System). It also bypasses UAC (User Account Control), a Windows account security tool.

Volume2 is a Utility tool that comes with a protobuf.dll file used to decryption and runs a real Payload file, a plugin Dispatcher that will perform Polling on the C2 server every 20 seconds.

The research team also detected 5 plug-ins associated with the above tools as follows:

OkoSpyware is a spying type of malware or Spyware used to monitor the operation of more than 100 software. Important software such as Password Manager 1Password and Crypto wallet such as Exodus, MetaMask, and Tonkeeper are also on this spyware's watchlist. The malware works with plugins to record videos and trap prints to steal data from such software.

FFmpeg is a plug-in that helps OkoSpyware malware to save the screen out as an MP4-style clip.

MC Keylogger is a plug-in that helps OkoSpyware malware to save print (Keystroke). It covers from Input, Clipboard, various USB devices, and also has the ability to save screenshots (Screenshots) every 5 minutes.

Rilide, a type of malware, steals data from the victim's machine (Infostealer) in the web browser extension (Extension) form of the Chromium family of web browsers.

SeedHunter, a tool for stealing Krypto wallet loan codes or Seed Phrases from hardware wallets like Trezor and Ledger

For the last plugin, which is called the most serious because it can steal a wallet of the type that many people think is safe, it checks wallet applications like Trezor Suite, Ledger Wallet, and Ledger Live. If one is found on the machine, it will shoot its own Injection code into those applications to intercept data from Electron inside these pockets, and then ask to the C2 server located at the moonsand [.] store. If the flag server (Flag) is Wait, the plugin will scan the USB drive according to the developer ID (Vendor) and the product itself. And then wait until such a bag is plugged into the USB drive.

After the bag has been successfully inserted, the malware will display a screen for recovering the pre-set bag (Hardcoded) to lure the victim into filling in the Seed Phrase. All the filled-in codes will be sent to the console of the bag recovery page with @: app: print, and then forwarded to the connected mal _ LogConsoleMessage function to trap the code. All the codes will be exported as JSON files with an RC4 copy that will be saved as a temporary file and then smuggled out (Exfiltration) to the C2 server. Hackers have easy access to all the money inside the victim's hardware pocket.

# Trending # lemon 8 diary # Krypto # Malware # freedomhack

6 days agoEdited to

... Read moreจากประสบการณ์ส่วนตัวที่ติดตามข่าวสารด้านความปลอดภัยไซเบอร์เกี่ยวกับคริปโตมาโดยตลอด ผมเข้าใจดีว่าแม้กระเป๋าคริปโตฮาร์ดแวร์อย่าง Trezor และ Ledger จะได้รับการยอมรับว่าปลอดภัย แต่มัลแวร์ OKBot นี้ทำให้เห็นว่าไม่มีอะไรที่ปลอดภัยแบบ 100% อย่างแท้จริง การใช้วิธีการ Phishing หลอกให้เหยื่อรันโค้ดบนเครื่อง หรือดาวน์โหลดซอฟต์แวร์ปลอมบน GitHub เพื่อฝังมัลแวร์ ถือเป็นเทคนิคที่แฮกเกอร์เลือกใช้ด้วยความชาญฉลาด สิ่งที่น่ากังวลคือมัลแวร์ตัวนี้ไม่ได้แค่ขโมยรหัสผ่านทั่วไป แต่รวมถึง Seed Phrase ซึ่งคือรหัสกู้กระเป๋าคริปโตที่เป็นกุญแจสำคัญในการเข้าถึงเงินดิจิทัลของเราเอง อีกทั้งยังมีการใช้สคริปท์ PowerShell และเทคนิคหลายชั้น เช่น การเปิดพอร์ต SSH, ปิดแจ้งเตือนแอนตี้ไวรัส, เปิดไฟร์วอลล์ RDP และเพิ่มบัญชีแฮกเกอร์ ทำให้แฮกเกอร์สามารถเข้าควบคุมเครื่องได้โดยตรงโดยที่เจ้าของไม่รู้ตัว ผมแนะนำให้ผู้ใช้งานคริปโตทุกคนควรระมัดระวังขั้นสูงสุด ต้องหลีกเลี่ยงการคลิกลิงก์ในอีเมลหรือข้อความที่ไม่น่าเชื่อถือ และไม่ควรดาวน์โหลดโปรแกรมจากแหล่งที่ไม่น่าเชื่อถือ แม้จะเป็นบน GitHub ก็ตาม นอกจากนี้ควรอัพเดตซอฟต์แวร์ป้องกันไวรัสและระบบปฏิบัติการของเครื่องให้เป็นเวอร์ชันล่าสุดเสมอ เพื่อป้องกันการถูกโจมตีในระดับลึก สำหรับผู้ใช้กระเป๋าฮาร์ดแวร์ ควรเก็บ Seed Phrase ไว้ในที่ปลอดภัยที่ไม่มีการเชื่อมต่อกับอินเทอร์เน็ต และไม่กรอกข้อมูล Seed Phrase ลงในซอฟต์แวร์หรือเว็บไซต์ใดๆ ที่ไม่น่าไว้วางใจ การรักษาความปลอดภัยแบบรัดกุมนี้เป็นสิ่งจำเป็นเพราะการโจมตีแบบนี้ไม่ได้เกิดขึ้นเพียงครั้งเดียว แต่ยังมีการพัฒนาเทคนิคแฮกเกอร์เรื่อยๆ ในฐานะที่ติดตามข่าวและมีประสบการณ์กับการใช้คริปโต ผมจึงมองว่าการตระหนักรู้ในภัยคุกคามและปรับใช้วิธีการรักษาความปลอดภัยที่เหมาะสมจะช่วยลดความเสี่ยงจากมัลแวร์ OKBot และแฮกเกอร์กลุ่มนี้ได้จริงๆ การมีข้อมูลและวิธีป้องกันที่ถูกต้องจึงเป็นเครื่องมือสำคัญสำหรับทุกคนที่ใช้งานคริปโตในยุคปัจจุบันนี้