Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»MassJacker malware uses 778,000 wallets to steal cryptocurrency
    Cryptocurrency

    MassJacker malware uses 778,000 wallets to steal cryptocurrency

    March 11, 20253 Mins Read


    Hackers stealing crypto

    A newly discovered clipboard hijacking operation dubbed ‘MassJacker’ uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.

    According to CyberArk, who discovered the MassJacker campaign, roughly 423 wallets linked to the operation contained $95,300 at the time of the analysis, but historical data suggests more significant transactions.

    Also, there’s a single Solana wallet that the threat actors appear to use as a central money-receiving hub, which has amassed over $300,000 in transactions so far.

    CyberArk suspects that the entire MassJacker operation is associated with a specific threat group, as file names downloaded from command and control servers and encryption keys used to decrypt the files were the same throughout the entire campaign.

    However, the operation could still be following a malware-as-a-service model, where a central administrator sells access to various cybercriminals.

    Transactions on the Solana wallet
    Transactions on the Solana wallet
    Source: CyberArk

    CyberArk calls MassJacker a cryptojacking operation, though this term is more often associated with unauthorized cryptocurrency mining leveraging the victim’s processing/hardware resources.

    In reality, MassJacker relies on clipboard hijacking malware (clippers), which is a type of malware that monitors Windows clipboard for copied cryptocurrency wallet addresses and replaces them with one under the attacker’s control.

    By doing so, victims unknowingly send money to the attackers, though they meant to send it to someone else.

    Clippers are simple but very effective tools that are particularly hard to detect due to their limited functionality and operational scope.

    Technical details

    MassJacker is distributed via pesktop[.]com, a site that hosts pirated software and malware.

    Software installers downloaded from this site execute a cmd script that triggers a PowerShell script, which fetches an Amadey bot and two loader files (PackerE and PackerD1).

    Amadey launches PackerE, which, in turn, decrypts and loads PackerD1 into memory.

    PackerD1 features five embedded resources that enhance its evasion and anti-analysis performance, including Just-In-Time (JIT) hooking, metadata token mapping to obfuscate function calls, and a custom virtual machine for command interpretation instead of running regular .NET code.

    PackerD1 decrypts and injects PackerD2, which eventually decompresses and extracts the final payload, MassJacker, and injects it into the legitimate Windows process ‘InstalUtil.exe.’

    MassJacker infection chain
    MassJacker infection chain
    Source: CyberArk

    MassJacker monitors the clipboard for cryptocurrency wallet addresses using regex patterns, and if a match is found, it replaces it with an attacker-controlled wallet address from an encrypted list.

    CyberArk calls the cybersecurity research community to look closer into large cryptojacking operations like MassJacker, as despite the perceived low financial damages, they could reveal valuable identification information on many threat actors.


    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Cryptocurrency Live News & Updates : DexOne Launches Beta for AI Trading Platform

    Cryptocurrency

    UK-Based Cloud Mining Platform Launches Simplified Cloud Mining, Starter Bonuses For First-Time Cryptocurrency Miners

    Cryptocurrency

    Cryptocurrency fraud ring busted in Spain after laundering $540 million, Europol says – Cryptocurrency News

    Cryptocurrency

    Texas declares gold and silver as legal tender, paving the way for currency reform

    Cryptocurrency

    Palestinian Authority Considers Ditching Israeli Shekel Amid Currency Surplus Crisis

    Cryptocurrency

    3 Concerns Investors Have if the Cryptocurrency-Focused Genius Act Becomes Law

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Mirova soutient EDF pour fournir 5 millions d’Africains en énergie propre d’ici 2030

    Cryptocurrency

    Among the Most Profitable Cryptocurrency Stocks To Buy Now

    Fintech

    Fintech Live 2024: Day 1 recap – Innovation in payments, embedded finance, and AI

    Editors Picks

    Invesco S&P 500 Equal Weight Utilities ETF (NYSEARCA:RSPU) Shares Acquired by Jones Financial Companies Lllp

    March 14, 2025

    Atalaya Mining Copper prévoit une production de cuivre de 48 à 52 kt en 2025 -Le 18 mars 2025 à 08:13

    March 17, 2025

    Pay property tax in advance, get up to 15% rebate in 2025-26 | Ahmedabad News

    February 14, 2025

    3 Passive Income ETFs for Your Retirement Strategy

    October 29, 2024
    What's Hot

    To Improve Crypto Tax Gap, IRS Must Enhance Compliance Efforts

    July 23, 2024

    How Digital Currencies Can Become More Inclusive

    April 23, 2025

    Farther Secures $72M Series C to Innovate Wealth Management

    October 11, 2024
    Our Picks

    Bailador Technology Investments investit 12,5 millions de dollars australiens dans Prophero -Le 19 février 2025 à 03:28

    February 18, 2025

    Aya Gold & Silver affiche une forte hausse de sa production au premier trimestre et réaffirme ses prévisions pour 2025

    May 9, 2025

    Unite Group Acquires Empiric Student Property in Major $976 Million Deal, ET RealEstate

    June 5, 2025
    Weekly Top

    UK GDP: Fastest Growth in Q1 2025

    June 30, 2025

    Investments in Russian coal industry will fall below 248 bln rubles ($3.16 bln) this year – Business & Economy

    June 30, 2025

    UK-Based Cloud Mining Platform Launches Simplified Cloud Mining, Starter Bonuses For First-Time Cryptocurrency Miners

    June 30, 2025
    Editor's Pick

    Dividend Fortunes: 2 Canadian Stocks Leading the Way to Retirement

    January 20, 2025

    Auramet Closes $350 Million Syndicated Revolving Credit Facility to Support Metals Franchise

    June 24, 2025

    MAG Silver Corp. Expected to Earn Q2 2024 Earnings of $0.15 Per Share (NYSEAMERICAN:MAG)

    July 22, 2024
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.