Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»MassJacker malware uses 778,000 wallets to steal cryptocurrency
    Cryptocurrency

    MassJacker malware uses 778,000 wallets to steal cryptocurrency

    March 11, 20253 Mins Read


    Hackers stealing crypto

    A newly discovered clipboard hijacking operation dubbed ‘MassJacker’ uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.

    According to CyberArk, who discovered the MassJacker campaign, roughly 423 wallets linked to the operation contained $95,300 at the time of the analysis, but historical data suggests more significant transactions.

    Also, there’s a single Solana wallet that the threat actors appear to use as a central money-receiving hub, which has amassed over $300,000 in transactions so far.

    CyberArk suspects that the entire MassJacker operation is associated with a specific threat group, as file names downloaded from command and control servers and encryption keys used to decrypt the files were the same throughout the entire campaign.

    However, the operation could still be following a malware-as-a-service model, where a central administrator sells access to various cybercriminals.

    Transactions on the Solana wallet
    Transactions on the Solana wallet
    Source: CyberArk

    CyberArk calls MassJacker a cryptojacking operation, though this term is more often associated with unauthorized cryptocurrency mining leveraging the victim’s processing/hardware resources.

    In reality, MassJacker relies on clipboard hijacking malware (clippers), which is a type of malware that monitors Windows clipboard for copied cryptocurrency wallet addresses and replaces them with one under the attacker’s control.

    By doing so, victims unknowingly send money to the attackers, though they meant to send it to someone else.

    Clippers are simple but very effective tools that are particularly hard to detect due to their limited functionality and operational scope.

    Technical details

    MassJacker is distributed via pesktop[.]com, a site that hosts pirated software and malware.

    Software installers downloaded from this site execute a cmd script that triggers a PowerShell script, which fetches an Amadey bot and two loader files (PackerE and PackerD1).

    Amadey launches PackerE, which, in turn, decrypts and loads PackerD1 into memory.

    PackerD1 features five embedded resources that enhance its evasion and anti-analysis performance, including Just-In-Time (JIT) hooking, metadata token mapping to obfuscate function calls, and a custom virtual machine for command interpretation instead of running regular .NET code.

    PackerD1 decrypts and injects PackerD2, which eventually decompresses and extracts the final payload, MassJacker, and injects it into the legitimate Windows process ‘InstalUtil.exe.’

    MassJacker infection chain
    MassJacker infection chain
    Source: CyberArk

    MassJacker monitors the clipboard for cryptocurrency wallet addresses using regex patterns, and if a match is found, it replaces it with an attacker-controlled wallet address from an encrypted list.

    CyberArk calls the cybersecurity research community to look closer into large cryptojacking operations like MassJacker, as despite the perceived low financial damages, they could reveal valuable identification information on many threat actors.


    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Court acquits defendants in cryptocurrency mining case

    Cryptocurrency

    Top 5 Cloud Mining Platforms for Cryptocurrency in 2026 – Why HashBitcoin Stands Out

    Cryptocurrency

    Better Cryptocurrency to Buy Now and Hold for 10 Years: XRP vs. Bitcoin

    Cryptocurrency

    Coinbase Faces Prospect for a Challenging 2026 as Cryptocurrency Prices Fall

    Cryptocurrency

    Poland to push ahead with cryptocurrency regulation despite presidential veto: minister

    Cryptocurrency

    Understanding Merkle Roots in Cryptocurrency: Basics and Function

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Cryptocurrency

    North Korea stole $2.8 billion in cryptocurrency in 2024 and 2025, report says

    Investments

    Saga of the migrant who moved into a retirement block with his much younger wife and toddler twins – and a human rights farce that’ll make you despair

    Cryptocurrency

    China’s Central Bank to Launch New Digital Yuan Management Framework from January 1

    Editors Picks

    City Farm SLO expands agricultural and educational capabilities with new acreage

    September 29, 2025

    DefiTax.us Launches to Simplify Crypto Tax Reporting Amid U.S. Government’s Strategic Cryptocurrency Adoption

    March 24, 2025

    How to Navigate the Fintech Landscape

    October 16, 2024

    Massive Luno Pay milestone reached

    June 24, 2025
    What's Hot

    City of Lincoln proposes ordinance to protect older adults from cryptocurrency fraud

    October 9, 2025

    BNPL Fintech Affirm Shares Insights On Challenges Associated With Credit Card Rewards

    September 8, 2025

    Budget 2026: Major security, justice, and equality investments

    October 27, 2025
    Our Picks

    London house prices decline as broader UK market rises 3%

    October 22, 2025

    FinovateFall, The World’s premier fintech event Coming to NYC in September 2025

    August 15, 2025

    Check Out These Adorable Metal Gear Solid Rubber Duckies

    September 22, 2025
    Weekly Top

    Silver Price Analysis – Silver Lacks Volume on Monday as Americans Away

    February 16, 2026

    Top 5 Cloud Mining Platforms for Cryptocurrency in 2026 – Why HashBitcoin Stands Out

    February 16, 2026

    Fintech company slice names founder Rajan Bajaj as CEO after RBI nod

    February 16, 2026
    Editor's Pick

    Muller Property opens consultation on Audlem housing plans

    March 26, 2025

    Silver Range Resources Ltd. définit une cible de forage d’exploration à East Goldfield

    April 9, 2025

    BPA plus que triplé au 3e trimestre

    June 25, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.