Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»MassJacker malware uses 778,000 wallets to steal cryptocurrency
    Cryptocurrency

    MassJacker malware uses 778,000 wallets to steal cryptocurrency

    March 11, 20253 Mins Read


    Hackers stealing crypto

    A newly discovered clipboard hijacking operation dubbed ‘MassJacker’ uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.

    According to CyberArk, who discovered the MassJacker campaign, roughly 423 wallets linked to the operation contained $95,300 at the time of the analysis, but historical data suggests more significant transactions.

    Also, there’s a single Solana wallet that the threat actors appear to use as a central money-receiving hub, which has amassed over $300,000 in transactions so far.

    CyberArk suspects that the entire MassJacker operation is associated with a specific threat group, as file names downloaded from command and control servers and encryption keys used to decrypt the files were the same throughout the entire campaign.

    However, the operation could still be following a malware-as-a-service model, where a central administrator sells access to various cybercriminals.

    Transactions on the Solana wallet
    Transactions on the Solana wallet
    Source: CyberArk

    CyberArk calls MassJacker a cryptojacking operation, though this term is more often associated with unauthorized cryptocurrency mining leveraging the victim’s processing/hardware resources.

    In reality, MassJacker relies on clipboard hijacking malware (clippers), which is a type of malware that monitors Windows clipboard for copied cryptocurrency wallet addresses and replaces them with one under the attacker’s control.

    By doing so, victims unknowingly send money to the attackers, though they meant to send it to someone else.

    Clippers are simple but very effective tools that are particularly hard to detect due to their limited functionality and operational scope.

    Technical details

    MassJacker is distributed via pesktop[.]com, a site that hosts pirated software and malware.

    Software installers downloaded from this site execute a cmd script that triggers a PowerShell script, which fetches an Amadey bot and two loader files (PackerE and PackerD1).

    Amadey launches PackerE, which, in turn, decrypts and loads PackerD1 into memory.

    PackerD1 features five embedded resources that enhance its evasion and anti-analysis performance, including Just-In-Time (JIT) hooking, metadata token mapping to obfuscate function calls, and a custom virtual machine for command interpretation instead of running regular .NET code.

    PackerD1 decrypts and injects PackerD2, which eventually decompresses and extracts the final payload, MassJacker, and injects it into the legitimate Windows process ‘InstalUtil.exe.’

    MassJacker infection chain
    MassJacker infection chain
    Source: CyberArk

    MassJacker monitors the clipboard for cryptocurrency wallet addresses using regex patterns, and if a match is found, it replaces it with an attacker-controlled wallet address from an encrypted list.

    CyberArk calls the cybersecurity research community to look closer into large cryptojacking operations like MassJacker, as despite the perceived low financial damages, they could reveal valuable identification information on many threat actors.


    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Russia’s Major Exchanges Gear Up For Regulated Cryptocurrency Trading

    Cryptocurrency

    Russia bans use of cryptocurrency as means of payment – intelligence

    Cryptocurrency

    Minnesota Attorney General’s Office seeks public input on cryptocurrency ATMs – Twin Cities

    Cryptocurrency

    LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

    Cryptocurrency

    A British Criminal Network Moved Money to Russia Using Cryptocurrencies — Here’s How

    Cryptocurrency

    AG Ellison releases cryptocurrency ATM survey – ABC 6 News

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Investments

    Foreign investors snap up Japanese government bonds as yields surge

    Precious Metal

    Revolver Resources fires off plans for Mt Isa-style copper targets

    Commodities

    Crude oil futures rebound after Wednesday’s fall

    Editors Picks

    La fintech Revolut mise gros sur la France avec un investissement d’un milliard d’euros

    May 19, 2025

    International Co For Agricultural Corps : bénéfice consolidé de 84,8 millions d’EGP au troisième trimestre

    May 28, 2025

    Energy drinks to be banned for under-16s – see which popular drinks will be hit

    September 2, 2025

    Fluctuation in Gold Prices: Antam and Galeri24 Increase, UBS Stays Stable

    May 10, 2025
    What's Hot

    Trie-sur-Baïse. Métal et Mobilier, un savoir-faire

    March 25, 2025

    B2B fintech Yaspa on using its ‘homegrown rebrand’ to break America

    October 15, 2025

    Making Real Estate Investment Accessible

    March 6, 2025
    Our Picks

    Rachel Reeves is coming for YOUR pensions, property and savings: How she could bring in a wealth tax by the back door

    October 21, 2025

    Tractor Junction to channel $22.6 million Series A funding into fintech, commerce expansion and AI platform development

    November 19, 2025

    Morgan: Metal Detective is a cosy Steam Next Fest game that I hope can match my favourite BBC dramedy

    October 14, 2024
    Weekly Top

    Silver Soars Past $75: Amateur Investors Fuel Frenzied Rally

    December 26, 2025

    LG Energy Solution To Sell Ohio Battery  Facility To Honda For $2.85 Billion

    December 26, 2025

    Copper Hits Record in China, Jumps in New York on Supply Concern – Bloomberg.com

    December 26, 2025
    Editor's Pick

    China shares dip as latest property stimulus measures disappoint

    October 17, 2024

    India Deepens Energy Ties with Africa to Diversify Supply and Boost Investments

    April 23, 2025

    If you missed XRP at $1, don’t miss this one, best Cryptocurrency coin to buy in Q4 2025?

    August 22, 2025
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.