The post New Malware Targets Crypto Wallets to Steal Bitcoin appeared on BitcoinEthereumNews.com. According to a recent report, new malware uses the ClickFix social engineering tactic, a phishing technique where users are tricked into executing a command under the pretext of completing a CAPTCHA or fixing a system issue. Bad actors are primarily hunting for crypto users, but they are also targeting browsers, messaging apps, FTP clients, and email accounts. The campaign is dangerous because it combines social engineering with advanced malware delivery that can evade detection. Evolved from ACR (AcridRain) Stealer, a malware previously sold via a malware-as-a-service (MaaS) model until mid-2024. It is now being sold via a subscription. Users are tricked into running a command in Windows Run under the pretext of completing a CAPTCHA (ClickFix). The campaign is part of a broader phishing ecosystem with fake invoices and VBS attachments. Visitors to fake ClickFix pages (SmartApeSG campaign) to deliver NetSupport RAT. There are also fake Booking.com CAPTCHA and spoofed internal email alerts with fake delivery notifications that prompt victims to click links that steal login credentials. High-value targets Cryptocurrency wallets contain directly transferable assets, which is why crypto wallets are considered to be high-value targets. Malware bypasses antivirus, EDR, and sandboxes. Attackers only deploy RATs on machines with valuable crypto data. Once stolen, it can be transferred globally in minutes without intermediaries. Unlike bank accounts, crypto transactions are irreversible, so once an attacker has the private keys, the victim usually cannot recover the funds. A single compromised wallet can yield hundreds of thousands or even millions of dollars. Malware like Amatera Stealer is specifically designed to detect and extract crypto wallet files, browser wallets, and private keys. Source: https://u.today/new-malware-targets-crypto-wallets-to-steal-bitcoinThe post New Malware Targets Crypto Wallets to Steal Bitcoin appeared on BitcoinEthereumNews.com. According to a recent report, new malware uses the ClickFix social engineering tactic, a phishing technique where users are tricked into executing a command under the pretext of completing a CAPTCHA or fixing a system issue. Bad actors are primarily hunting for crypto users, but they are also targeting browsers, messaging apps, FTP clients, and email accounts. The campaign is dangerous because it combines social engineering with advanced malware delivery that can evade detection. Evolved from ACR (AcridRain) Stealer, a malware previously sold via a malware-as-a-service (MaaS) model until mid-2024. It is now being sold via a subscription. Users are tricked into running a command in Windows Run under the pretext of completing a CAPTCHA (ClickFix). The campaign is part of a broader phishing ecosystem with fake invoices and VBS attachments. Visitors to fake ClickFix pages (SmartApeSG campaign) to deliver NetSupport RAT. There are also fake Booking.com CAPTCHA and spoofed internal email alerts with fake delivery notifications that prompt victims to click links that steal login credentials. High-value targets Cryptocurrency wallets contain directly transferable assets, which is why crypto wallets are considered to be high-value targets. Malware bypasses antivirus, EDR, and sandboxes. Attackers only deploy RATs on machines with valuable crypto data. Once stolen, it can be transferred globally in minutes without intermediaries. Unlike bank accounts, crypto transactions are irreversible, so once an attacker has the private keys, the victim usually cannot recover the funds. A single compromised wallet can yield hundreds of thousands or even millions of dollars. Malware like Amatera Stealer is specifically designed to detect and extract crypto wallet files, browser wallets, and private keys. Source: https://u.today/new-malware-targets-crypto-wallets-to-steal-bitcoin

New Malware Targets Crypto Wallets to Steal Bitcoin

According to a recent report, new malware uses the ClickFix social engineering tactic, a phishing technique where users are tricked into executing a command under the pretext of completing a CAPTCHA or fixing a system issue.

Bad actors are primarily hunting for crypto users, but they are also targeting browsers, messaging apps, FTP clients, and email accounts.

The campaign is dangerous because it combines social engineering with advanced malware delivery that can evade detection.

Evolved from ACR (AcridRain) Stealer, a malware previously sold via a malware-as-a-service (MaaS) model until mid-2024. It is now being sold via a subscription.

Users are tricked into running a command in Windows Run under the pretext of completing a CAPTCHA (ClickFix).

The campaign is part of a broader phishing ecosystem with fake invoices and VBS attachments. Visitors to fake ClickFix pages (SmartApeSG campaign) to deliver NetSupport RAT.

There are also fake Booking.com CAPTCHA and spoofed internal email alerts with fake delivery notifications that prompt victims to click links that steal login credentials.

High-value targets

Cryptocurrency wallets contain directly transferable assets, which is why crypto wallets are considered to be high-value targets. Malware bypasses antivirus, EDR, and sandboxes. Attackers only deploy RATs on machines with valuable crypto data.

Once stolen, it can be transferred globally in minutes without intermediaries.

Unlike bank accounts, crypto transactions are irreversible, so once an attacker has the private keys, the victim usually cannot recover the funds.

A single compromised wallet can yield hundreds of thousands or even millions of dollars.

Malware like Amatera Stealer is specifically designed to detect and extract crypto wallet files, browser wallets, and private keys.

Source: https://u.today/new-malware-targets-crypto-wallets-to-steal-bitcoin

Market Opportunity
Bad Idea AI Logo
Bad Idea AI Price(BAD)
$0.00000000145
$0.00000000145$0.00000000145
+1.39%
USD
Bad Idea AI (BAD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

WOW Summit Partners with Hong Kong Sevens: Five Memorable Days of Web3, Sports, and Excitement!

WOW Summit Partners with Hong Kong Sevens: Five Memorable Days of Web3, Sports, and Excitement!

WOW Summit Hong Kong 2023 is a premium Web3-focused event and a part of the WOW global series.
Share
PANews2023/03/17 12:05
First Multi-Asset Crypto ETP Opens Door to Institutional Adoption

First Multi-Asset Crypto ETP Opens Door to Institutional Adoption

The post First Multi-Asset Crypto ETP Opens Door to Institutional Adoption appeared on BitcoinEthereumNews.com. The US Securities and Exchange Commission (SEC) has officially approved the Grayscale Digital Large Cap Fund (GDLC) for trading on the stock exchange. The decision comes as the SEC also relaxes ETF listing standards. This approval provides easier access for traditional investors and signals a major regulatory shift, paving the way for institutional capital to flow into the crypto market. Grayscale Races to Launch the First Multi-Asset Crypto ETP According to Grayscale CEO Peter Mintzberg, the Grayscale Digital Large Cap Fund ($GDLC) and the Generic Listing Standards have just been approved for trading. Sponsored Sponsored Grayscale Digital Large Cap Fund $GDLC was just approved for trading along with the Generic Listing Standards. The Grayscale team is working expeditiously to bring the FIRST multi #crypto asset ETP to market with Bitcoin, Ethereum, XRP, Solana, and Cardano#BTC #ETH $XRP $SOL… — Peter Mintzberg (@PeterMintzberg) September 17, 2025 The Grayscale Digital Large Cap Fund (GDLC) is the first multi-asset crypto Exchange-Traded Product (ETP). It includes Bitcoin (BTC), Ethereum (ETH), XRP, Solana (SOL), and Cardano (ADA). As of September, the portfolio allocation was 72.23%, 12.17%, 5.62%, 4.03%, and 1% respectively. Grayscale Digital Large Cap Fund (GDLC) Portfolio Allocation. Source: Grayscale Grayscale Investments launched GDLC in 2018. The fund’s primary goal is to expose investors to the most significant digital assets in the market without requiring them to buy, store, or secure the coins directly. In July, the SEC delayed its decision to convert GDLC from an OTC fund into an exchange-listed ETP on NYSE Arca, citing further review. However, the latest developments raise investors’ hopes that a multi-asset crypto ETP from Grayscale will soon become a reality. Approval under the Generic Listing Standards will help “streamline the process,” opening the door for more crypto ETPs. Ethereum, Solana, XRP, and ADA investors are the most…
Share
BitcoinEthereumNews2025/09/18 13:31
Two Prime selected to manage $250 million in bitcoin for Digital Wealth Partners

Two Prime selected to manage $250 million in bitcoin for Digital Wealth Partners

The institutional bitcoin manager expands its mandate as demand for professional risk-managed digital asset strategies grows.
Share
Coinstats2026/01/16 18:00