BTC $76,130.23 +0.41%
ETH $2,419.81 +0.87%
BNB $723.02 +1.63%
XRP $1.30 +0.40%
SOL $99.05 +1.84%
TRX $0.3358 +0.90%
DOGE $0.0806 +0.83%
ADA $0.1949 +0.45%
BCH $219.76 +0.73%
LINK $11.08 +1.93%
HYPE $78.70 +1.68%
AAVE $120.57 -0.16%
SUI $0.7161 +4.38%
XLM $0.1831 +4.17%
ZEC $1,372.81 +22.67%
AAPL $333.77 +0.61%
AMZN $248.23 -0.24%
GOOGL $345.34 +0.26%
MSFT $493.14 -1.03%
META $678.78 +1.46%
NVDA $215.68 +1.49%
TSLA $360.36 +1.06%
SNDK $1,533.41 +0.33%
INTC $102.34 +5.23%
SPCX $152.29 +6.00%
MU $933.40 +0.52%
AMD $517.16 +2.38%
BTC $76,130.23 +0.41%
ETH $2,419.81 +0.87%
BNB $723.02 +1.63%
XRP $1.30 +0.40%
SOL $99.05 +1.84%
TRX $0.3358 +0.90%
DOGE $0.0806 +0.83%
ADA $0.1949 +0.45%
BCH $219.76 +0.73%
LINK $11.08 +1.93%
HYPE $78.70 +1.68%
AAVE $120.57 -0.16%
SUI $0.7161 +4.38%
XLM $0.1831 +4.17%
ZEC $1,372.81 +22.67%
AAPL $333.77 +0.61%
AMZN $248.23 -0.24%
GOOGL $345.34 +0.26%
MSFT $493.14 -1.03%
META $678.78 +1.46%
NVDA $215.68 +1.49%
TSLA $360.36 +1.06%
SNDK $1,533.41 +0.33%
INTC $102.34 +5.23%
SPCX $152.29 +6.00%
MU $933.40 +0.52%
AMD $517.16 +2.38%

malware

All
Article
Flash

first_img HBO Max account was hijacked, and 108 malicious ads were placed to steal cryptocurrency assets

Cybersecurity company Hudson Rock disclosed that the Reddit verified account of the streaming service HBO Max was hijacked earlier this month and deployed 108 malicious ads within approximately 48 hours. These ads used a non-existent HBO Max native macOS application as bait, luring users to open Terminal or PowerShell and paste malicious commands, a technique known as ClickFix.Researchers named this operation PasteSwitch, and its delivery system adapts based on the visitor's device and the advertised software. Observed Mac payloads include MacSync and Atomic macOS (AMOS) information-stealing trojans, targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware also utilized Binance Smart Chain contracts as variable C2 address delivery points and was associated with a cryptocurrency clipboard hijacker that replaces clipboard wallet addresses.According to Malwarebytes, Reddit administrators have suspended the related ads and initiated a security investigation following reports. The report did not specify how the account was compromised or the number of victims, nor was there evidence found that the HBO Max streaming service itself was breached. The ClickFix technique has previously been used multiple times in attacks targeting cryptocurrency users, including approximately 2,000 compromised WordPress sites and malicious activities disguised as CAPTCHA.

A man in the United States implanted malware through Steam games to steal cryptocurrency assets, infecting about 8,000 devices

The U.S. federal prosecutors have charged a 21-year-old Florida man, Zyaire Wilkins, accusing him of implanting malware to steal cryptocurrency assets in at least 8 games with accomplices between May 2024 and February 2026, spreading it through gaming platforms, resulting in approximately 8,000 devices being infected and about 80 cryptocurrency wallets being stolen, with the amount involved exceeding $220,000.The indictment documents show that the games involved include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova. Some of these games had previously been removed from Steam due to security risks. Investigators stated that the suspect promoted these games through platforms such as Discord, Telegram, X, and LinkedIn, luring users to download and install them, after which the malware stole sensitive information from victims and siphoned off cryptocurrency wallet assets.The FBI indicated that law enforcement identified the suspect through on-chain fund flow analysis and digital payment records. The investigation found that his associated cryptocurrency wallet had purchased over 150 gift cards on the cryptocurrency gift card platform Bitrefill, including Uber Eats gift cards, ultimately helping investigators confirm his phone number and address. The case has now been filed in the U.S. District Court for the Western District of Washington.

macOS malware can bypass Telegram's two-factor authentication to steal cryptocurrency wallets and account permissions

According to FinanceFeeds, security researchers have discovered an information-stealing malware targeting macOS devices that is attacking cryptocurrency users. This malware can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Currently affected wallets and applications include software wallets like Exodus, Atomic, Electrum, Wasabi, and Monero.The malware is capable of extracting sensitive information from macOS Keychain, Safari Cookies, Apple Notes, Telegram Desktop, and multiple cryptocurrency wallet-related databases, including login credentials, authenticated session files, wallet data, and browser extension information. Security analysis points out that the danger of this attack chain lies in its reliance not on a single wallet vulnerability, but on collecting various types of data from the device, linking device intrusion, account takeover, wallet cracking, and mnemonic phrase theft together. Among these, Telegram Desktop sessions have become a key target.Attackers can copy authenticated Telegram local session data and restore the login on another Mac device without needing to enter a phone number, verification code, or Telegram two-factor authentication password. This means that Telegram 2FA cannot provide complete protection in this attack scenario, as the attacker is not performing a new login but is exploiting an already trusted local session. For cryptocurrency users, the risks are further amplified. Since Telegram is widely used for exchange customer service, project communities, OTC trading, and wallet communication, once attackers gain access to user session permissions, they could impersonate the victim, read private chats, locate asset information, and even spread malicious links to contacts.
app_icon
ChainCatcher Building the Web3 world with innovations.