The post New Malware Targets Crypto Wallets to Steal Bitcoin appeared on BitcoinEthereumNews.com. According to a recent report, new malware uses the ClickFix social engineering tactic, a phishing technique where users are tricked into executing a command under the pretext of completing a CAPTCHA or fixing a system issue. Bad actors are primarily hunting for crypto users, but they are also targeting browsers, messaging apps, FTP clients, and email accounts. The campaign is dangerous because it combines social engineering with advanced malware delivery that can evade detection. Evolved from ACR (AcridRain) Stealer, a malware previously sold via a malware-as-a-service (MaaS) model until mid-2024. It is now being sold via a subscription. Users are tricked into running a command in Windows Run under the pretext of completing a CAPTCHA (ClickFix). The campaign is part of a broader phishing ecosystem with fake invoices and VBS attachments. Visitors to fake ClickFix pages (SmartApeSG campaign) to deliver NetSupport RAT. There are also fake Booking.com CAPTCHA and spoofed internal email alerts with fake delivery notifications that prompt victims to click links that steal login credentials. High-value targets Cryptocurrency wallets contain directly transferable assets, which is why crypto wallets are considered to be high-value targets. Malware bypasses antivirus, EDR, and sandboxes. Attackers only deploy RATs on machines with valuable crypto data. Once stolen, it can be transferred globally in minutes without intermediaries. Unlike bank accounts, crypto transactions are irreversible, so once an attacker has the private keys, the victim usually cannot recover the funds. A single compromised wallet can yield hundreds of thousands or even millions of dollars. Malware like Amatera Stealer is specifically designed to detect and extract crypto wallet files, browser wallets, and private keys. Source: https://u.today/new-malware-targets-crypto-wallets-to-steal-bitcoinThe post New Malware Targets Crypto Wallets to Steal Bitcoin appeared on BitcoinEthereumNews.com. According to a recent report, new malware uses the ClickFix social engineering tactic, a phishing technique where users are tricked into executing a command under the pretext of completing a CAPTCHA or fixing a system issue. Bad actors are primarily hunting for crypto users, but they are also targeting browsers, messaging apps, FTP clients, and email accounts. The campaign is dangerous because it combines social engineering with advanced malware delivery that can evade detection. Evolved from ACR (AcridRain) Stealer, a malware previously sold via a malware-as-a-service (MaaS) model until mid-2024. It is now being sold via a subscription. Users are tricked into running a command in Windows Run under the pretext of completing a CAPTCHA (ClickFix). The campaign is part of a broader phishing ecosystem with fake invoices and VBS attachments. Visitors to fake ClickFix pages (SmartApeSG campaign) to deliver NetSupport RAT. There are also fake Booking.com CAPTCHA and spoofed internal email alerts with fake delivery notifications that prompt victims to click links that steal login credentials. High-value targets Cryptocurrency wallets contain directly transferable assets, which is why crypto wallets are considered to be high-value targets. Malware bypasses antivirus, EDR, and sandboxes. Attackers only deploy RATs on machines with valuable crypto data. Once stolen, it can be transferred globally in minutes without intermediaries. Unlike bank accounts, crypto transactions are irreversible, so once an attacker has the private keys, the victim usually cannot recover the funds. A single compromised wallet can yield hundreds of thousands or even millions of dollars. Malware like Amatera Stealer is specifically designed to detect and extract crypto wallet files, browser wallets, and private keys. Source: https://u.today/new-malware-targets-crypto-wallets-to-steal-bitcoin

New Malware Targets Crypto Wallets to Steal Bitcoin

According to a recent report, new malware uses the ClickFix social engineering tactic, a phishing technique where users are tricked into executing a command under the pretext of completing a CAPTCHA or fixing a system issue.

Bad actors are primarily hunting for crypto users, but they are also targeting browsers, messaging apps, FTP clients, and email accounts.

The campaign is dangerous because it combines social engineering with advanced malware delivery that can evade detection.

Evolved from ACR (AcridRain) Stealer, a malware previously sold via a malware-as-a-service (MaaS) model until mid-2024. It is now being sold via a subscription.

Users are tricked into running a command in Windows Run under the pretext of completing a CAPTCHA (ClickFix).

The campaign is part of a broader phishing ecosystem with fake invoices and VBS attachments. Visitors to fake ClickFix pages (SmartApeSG campaign) to deliver NetSupport RAT.

There are also fake Booking.com CAPTCHA and spoofed internal email alerts with fake delivery notifications that prompt victims to click links that steal login credentials.

High-value targets

Cryptocurrency wallets contain directly transferable assets, which is why crypto wallets are considered to be high-value targets. Malware bypasses antivirus, EDR, and sandboxes. Attackers only deploy RATs on machines with valuable crypto data.

Once stolen, it can be transferred globally in minutes without intermediaries.

Unlike bank accounts, crypto transactions are irreversible, so once an attacker has the private keys, the victim usually cannot recover the funds.

A single compromised wallet can yield hundreds of thousands or even millions of dollars.

Malware like Amatera Stealer is specifically designed to detect and extract crypto wallet files, browser wallets, and private keys.

Source: https://u.today/new-malware-targets-crypto-wallets-to-steal-bitcoin

Market Opportunity
Bad Idea AI Logo
Bad Idea AI Price(BAD)
$0.00000000141
$0.00000000141$0.00000000141
-1.39%
USD
Bad Idea AI (BAD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details

Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details

The post Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details appeared on BitcoinEthereumNews.com. Japan-based Bitcoin treasury company Metaplanet announced today that it has successfully completed its public offering process. Metaplanet Grows Bitcoin Treasury with $1.4 Billion IPO The company’s CEO, Simon Gerovich, stated in a post on the X platform that a large number of institutional investors participated in the process. Among the investors, mutual funds, sovereign wealth funds, and hedge funds were notable. According to Gerovich, approximately 100 institutional investors participated in roadshows held prior to the IPO. Ultimately, over 70 investors participated in Metaplanet’s capital raising. Previously disclosed information indicated that the company had raised approximately $1.4 billion through the IPO. This funding will accelerate Metaplanet’s growth plans and, in particular, allow the company to increase its balance sheet Bitcoin holdings. Gerovich emphasized that this step will propel Metaplanet to its next stage of development and strengthen the company’s global Bitcoin strategy. Metaplanet has recently become one of the leading companies in Japan in promoting digital asset adoption. The company has previously stated that it views Bitcoin as a long-term store of value. This large-scale IPO is considered a significant step in not only strengthening Metaplanet’s capital but also consolidating Japan’s role in the global crypto finance market. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/japan-based-bitcoin-treasury-company-metaplanet-completes-1-4-billion-ipo-will-it-buy-bitcoin-here-are-the-details/
Share
BitcoinEthereumNews2025/09/18 08:42
InvestCapitalWorld Updates Platform Features to Support Broader Multi-Asset Market Access

InvestCapitalWorld Updates Platform Features to Support Broader Multi-Asset Market Access

The post InvestCapitalWorld Updates Platform Features to Support Broader Multi-Asset Market Access appeared on BitcoinEthereumNews.com. Paris, France, January 16th
Share
BitcoinEthereumNews2026/01/16 21:27
Why X Banned Information Finance Apps In 2026

Why X Banned Information Finance Apps In 2026

The post Why X Banned Information Finance Apps In 2026 appeared on BitcoinEthereumNews.com. InfoFi Tokens Crash: Why X Banned Information Finance Apps In 2026 Skip
Share
BitcoinEthereumNews2026/01/16 21:32