Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Crypto Wallets Hacked Through Windows Vulnerability
Facebook   X   LinkedIn   Email

Crypto Wallets Hacked Through Windows Vulnerability

May 3, 2024

The security of crypto wallets has been a question mark for some time. And now, there's a Windows vulnerability leaving users infected with a previously unknown infostealer that's draining crypto wallets. It's called Phemedrone Stealer and malicious campaigns are exploiting this Windows vulnerability to steal crypto wallet contents and other sensitive information from victims.

What Phemedrone Stealer Steals

Although Microsoft released a patch (CVE-2023-36025) late last year, malware campaigns using Phemedrone Stealer accounted for the vulnerability in their attacks. The attackers use malicious .url files to download and exploit the vulnerability that bypasses checks and warnings from Microsoft Defender.

Just some of what Phemedrone Stealer actually steals includes: Data from crypto wallets like Bytecoin, Armory, Electrum, and Guarda; Passwords, autofill, and other data from chromium-based browsers like Microsoft Authenticator, Google Authenticator, LastPass, and Duo Mobile; Operating system information; and screenshots of whatever they want to.

No one is quite sure how much Phemedrone Stealer has stolen from crypto wallets. But according to De.Fi, $2 billion was hijacked from these wallets last year. It's safe to say Phemedrone Stealer played a part in that massive total and will continue to pilfer crypto from unpatched devices. The cyber-smart answer to avoid this sneaky infostealer is immediately applying the security patch available and be sure to keep all of your devices up-to-date at all times.


Realst Malware Preying on Mac Users Through Fake Blockchain Games

Your Security

Realst Malware Preying on Mac Users Through Fake Blockchain Games

A new cybersecurity threat has surfaced, ominously dubbed "Realst." Primarily targeting Mac users, this threat lurks in seemingly inconspicuous blockchain games. However, instead of a fun gaming experience, this malware is programmed to steal your personal data. Realst takes a smart, but deceitful approach to get to you, even looking to the future. If you play this game, they may be able to install Realst on your Mac and allow the hackers to choose their targets. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...