A new type of crypto-Trojan has a particular focus on European Internet users. ESET analyzed the previously unknown family of malware.
ESET researchers have analyzed a previously unknown family of malware that is spreading via malicious torrent files and targeting European internet users. If the infection is successful, the Trojan secretly tries to mine cryptocurrencies, manipulate wallets and transactions and steal related data. The experts at the European IT security manufacturer named the malware KryptoCibule. The malware tries to stay under the radar using various techniques. The ESET researchers are now presenting their analysis results on WeLiveSecurity.
Crypto Trojans: Malware is always evolving
“KryptoCibule also uses legitimate software. Some, like Tor and the Transmission torrent client, are linked to the installer, others are downloaded later, ”says Matthieu Faou, ESET researcher who uncovered the new family of malware. “KryptoCibule consists of three components to get access to crypto currencies: cryptomining, manipulation of the clipboard and data theft. According to our analysis results, enough profit could only be achieved by using all three functions to justify the development effort observed. "
ESET has identified several versions of KryptoCibule. The researchers at the European IT security manufacturer can thus trace the development of the malicious program back to December 2018. Since then, the malware has continued to evolve and new features have been added on a regular basis.
European internet users in focus
The malware targets European internet users in particular. The criminals behind KryptoCibule uploaded the infected torrent files to a file sharing platform that is very popular with users from the Czech Republic and Slovakia. The ESET researchers suspect that users from both countries are in particular focus because the malware specifically checks the affected systems for security solutions that are frequently used in both countries.
More on this at WeLiveSecurity at ESET.com
About ESET ESET is a European company with headquarters in Bratislava (Slovakia). ESET has been developing award-winning security software since 1987 that has already helped over 100 million users enjoy secure technology. The broad portfolio of security products covers all common platforms and offers companies and consumers worldwide the perfect balance between performance and proactive protection. The company has a global sales network in over 180 countries and branches in Jena, San Diego, Singapore and Buenos Aires. For more information, visit www.eset.de or follow us on LinkedIn, Facebook and Twitter.