• bitcoinBitcoin (BTC) $ 66,761.00
  • ethereumEthereum (ETH) $ 2,018.43
  • tetherTether (USDT) $ 0.999339
  • bnbBNB (BNB) $ 615.49
  • xrpXRP (XRP) $ 1.35
  • usd-coinUSDC (USDC) $ 0.999794
  • solanaSolana (SOL) $ 83.18
  • tronTRON (TRX) $ 0.317195
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.092436
  • usdsUSDS (USDS) $ 0.999802
  • whitebitWhiteBIT Coin (WBT) $ 51.67
  • bitcoin-cashBitcoin Cash (BCH) $ 482.47
  • hyperliquidHyperliquid (HYPE) $ 39.73
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.249791
  • leo-tokenLEO Token (LEO) $ 9.58
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 332.03
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 8.59
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.998973
  • canton-networkCanton (CC) $ 0.150139
  • stellarStellar (XLM) $ 0.170937
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999628
  • daiDai (DAI) $ 0.999616
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 54.15
  • rainRain (RAIN) $ 0.008333
  • hedera-hashgraphHedera (HBAR) $ 0.090716
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 2.23
  • paypal-usdPayPal USD (PYUSD) $ 0.999912
  • avalanche-2Avalanche (AVAX) $ 8.86
  • wethWETH (WETH) $ 2,268.37
  • zcashZcash (ZEC) $ 218.48
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.883813
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.25
  • crypto-com-chainCronos (CRO) $ 0.072283
  • bittensorBittensor (TAO) $ 318.26
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.099651
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,489.12
  • pax-goldPAX Gold (PAXG) $ 4,500.03
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.681369
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • uniswapUniswap (UNI) $ 3.42
  • polkadotPolkadot (DOT) $ 1.28
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • pi-networkPi Network (PI) $ 0.179124
  • okbOKB (OKB) $ 83.87
  • falcon-financeFalcon USD (USDF) $ 0.997929
  • aster-2Aster (ASTER) $ 0.661051
  • skySky (SKY) $ 0.070167
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.18
  • aaveAave (AAVE) $ 97.84
  • ripple-usdRipple USD (RLUSD) $ 0.999966
  • pepePepe (PEPE) $ 0.000003
  • bitget-tokenBitget Token (BGB) $ 1.95
  • ondo-financeOndo (ONDO) $ 0.274360
  • bfusdBFUSD (BFUSD) $ 0.999200
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ethereum-classicEthereum Classic (ETC) $ 8.18
  • internet-computerInternet Computer (ICP) $ 2.26
  • siren-2Siren (SIREN) $ 1.68
  • gatechain-tokenGate (GT) $ 6.55
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 7.96
  • quant-networkQuant (QNT) $ 71.03
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pump-funPump.fun (PUMP) $ 0.001730
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.092285
  • kaspaKaspa (KAS) $ 0.034938
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • render-tokenRender (RENDER) $ 1.70
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • usdtbUSDtb (USDTB) $ 0.999585
  • nexoNEXO (NEXO) $ 0.873178
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • midnight-3Midnight (NIGHT) $ 0.051484
  • worldcoin-wldWorldcoin (WLD) $ 0.272367
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.68
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • morphoMorpho (MORPHO) $ 1.50
  • ethenaEthena (ENA) $ 0.092676
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • usddUSDD (USDD) $ 0.998611
  • aptosAptos (APT) $ 0.941353
  • wbnbWrapped BNB (WBNB) $ 759.61
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.03
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.082555
  • official-trumpOfficial Trump (TRUMP) $ 3.00
  • flare-networksFlare (FLR) $ 0.007834
  • filecoinFilecoin (FIL) $ 0.822610
  • beldexBeldex (BDX) $ 0.081712
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • ousgOUSG (OUSG) $ 114.73
  • xdce-crowd-saleXDC Network (XDC) $ 0.030911
  • hash-2Provenance Blockchain (HASH) $ 0.010884
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • yldsYLDS (YLDS) $ 0.999957
  • ghoGHO (GHO) $ 0.999078
  • vechainVeChain (VET) $ 0.006766
  • usual-usdUsual USD (USD0) $ 0.998692
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.247234
  • stable-2​​Stable (STABLE) $ 0.026039
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • arbitrumArbitrum (ARB) $ 0.091596
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • justJUST (JST) $ 0.059300
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.146231
  • bonkBonk (BONK) $ 0.000006
  • layerzeroLayerZero (ZRO) $ 2.01
  • clbtcclBTC (CLBTC) $ 76,920.00
  • true-usdTrueUSD (TUSD) $ 0.997799
  • a7a5A7A5 (A7A5) $ 0.012222
  • fasttokenFasttoken (FTN) $ 1.09
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.38
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.670010
  • euro-coinEURC (EURC) $ 1.15
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • blockstackStacks (STX) $ 0.224858
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006524
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 32.31
  • chilizChiliz (CHZ) $ 0.039429
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998980
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • tezosTezos (XTZ) $ 0.351314
  • sei-networkSei (SEI) $ 0.054805
  • ether-fiEther.fi (ETHFI) $ 0.463168
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • decredDecred (DCR) $ 20.99
  • hastra-primePRIME (PRIME) $ 1.03
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • usxUSX (USX) $ 0.999439
  • kinesis-goldKinesis Gold (KAU) $ 147.06
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • dexeDeXe (DEXE) $ 7.13
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017285
  • cocaCOCA (COCA) $ 1.30
  • adi-tokenADI (ADI) $ 4.04
  • apenftAINFT (NFT) $ 0.00000033
  • curve-dao-tokenCurve DAO (CRV) $ 0.215415
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • gnosisGnosis (GNO) $ 119.25
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • usdaiUSDai (USDAI) $ 0.999595
  • kite-2Kite (KITE) $ 0.172399
  • aerodrome-financeAerodrome Finance (AERO) $ 0.327283
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • conflux-tokenConflux (CFX) $ 0.057460
  • injective-protocolInjective (INJ) $ 2.89
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • riverRiver (RIVER) $ 14.39
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • fraxLegacy Frax Dollar (FRAX) $ 0.997288
  • bitcoin-svBitcoin SV (BSV) $ 13.67
  • venice-tokenVenice Token (VVV) $ 6.08
  • flokiFLOKI (FLOKI) $ 0.000028
  • kaiaKaia (KAIA) $ 0.046226
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • celestiaCelestia (TIA) $ 0.299803
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • lido-daoLido DAO (LDO) $ 0.313193
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • jasmycoinJasmyCoin (JASMY) $ 0.005331
  • crvusdcrvUSD (CRVUSD) $ 0.997201
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • official-foOfficial FO (FO) $ 0.262929
  • kinesis-silverKinesis Silver (KAG) $ 68.82
  • the-graphThe Graph (GRT) $ 0.024081
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • spx6900SPX6900 (SPX) $ 0.277483
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • monadMonad (MON) $ 0.022942
  • doublezeroDoubleZero (2Z) $ 0.070441
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • olympusOlympus (OHM) $ 15.54
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • iotaIOTA (IOTA) $ 0.055635
  • syrupMaple Finance (SYRUP) $ 0.207995
  • btse-tokenBTSE Token (BTSE) $ 1.44

Astaroth Banking Trojan Harnessing GitHub to Steal Crypto Credentials

0 0


Hackers are deploying a banking Trojan that makes use of GitHub repositories whenever its servers are taken down, according to research from cybersecurity firm McAfee.

Dubbed Astaroth, the Trojan virus is spread via phishing emails that invite victims to download a Windows (.lnk) file, which installs the malware on a host computer.

Astaroth runs in the background of a victim’s device, using keylogging to steal banking and crypto credentials, and sending such credentials using the Ngrok reverse proxy (an intermediary between servers).

Its unique feature is that Astaroth uses GitHub repositories to update its server configuration whenever its command-and-control server is taken down, which usually happens because of intervention from cybersecurity firms or law enforcement agencies.

“GitHub is not used to host the malware itself, but just to host a configuration that points to the bot server,” said Abhishek Karnik, Director for Threat Research and Response at McAfee.

Speaking to Decrypt, Karnik explained that the malware’s deployers are using GitHub as a resource to direct victims to updated servers, which distinguishes the exploit from previous instances in which GitHub has been harnessed.

This includes an attack vector discovered by McAfee in 2024, in which bad actors inserted the Redline Stealer malware into GitHub repositories, something which has been repeated this year in the GitVenom campaign.

“However, in this case, it’s not malware that is being hosted but a configuration that manages how the malware communicates with its backend infrastructure,” Karnik added.

As with the GitVenom campaign, Astaroth’s ultimate purpose is to exfiltrate credentials that can be used to steal a victim’s crypto or to make transfers out of their bank accounts.

“We don’t have data about how much money or crypto it has stolen, but it appears to be very prevalent, especially in Brazil,” said Karnik.

Targeting South America

It seems that Astaroth has primarily targeted South American territories, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela and Panama.

While it is also capable of targeting Portugal and Italy, the malware is written so that it is not uploaded to systems in the United States or other English-speaking countries (such as England).

The malware shuts down its host system if it detects that analysis software is being operated, while it’s designed to run keylogging functions if it detects that a web browser is visiting certain banking sites.

These include caixa.gov.br, safra.com.br, itau.com.br, bancooriginal.com.br, santandernet.com.br and btgpactual.com.

It has also been written to target the following crypto-related domains: etherscan.io, binance.com, bitcointrade.com.br, metamask.io, foxbit.com.br and localbitcoins.com.

In the face of such threats, McAfee advises that users do not open attachments or links from unknown senders, while also using up-to-date antivirus software and two-factor authentication.



Source link

Leave A Reply

Your email address will not be published.