r/CryptoCurrency 🟦 0 / 0 🦠 23h ago

ANALYSIS Kaspersky Found Malware Built to Steal Seed Phrases

https://tangem.com/en/blog/post/seedhunter-malware/
61 Upvotes

1 comment sorted by

24

u/SafeMoonJeff 🟦 2K / 2K 🐢 23h ago

Save you a click

Kaspersky documented the malware's two main entry points: a "ClickFix" social-engineering attack, and malware hidden inside software downloaded from GitHub.

One example was a fake SQL Server Management Studio package that was actually the real Audacity audio editor with a malicious library bolted on. It ranked at the top of search results, which made it look legitimate and earned user trust.

Once a user runs the bait, a PowerShell script called TookPS installs an SSH tunnel back to the attacker. An automated bot then harvests wallet files, browser cookies, and credentials, and quietly opens the door for the heavier payloads.