search
Underground malware
Trends
- 1Crypto-stealing operation drains $100,000 from victims●$100k in Crypto Drained by the Underground Operation A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader
Researchers report that a malware operation using an Aotera/Tedy loader has stolen roughly $100,000 in cryptocurrency. The loader injects a Vidar-class infostealer into Windows processes, then launches Chrome or Edge to run malicious scripts inside victims' browser sessions, capturing wallets and credentials. Security observers are warning Windows users to be cautious, as the malware builder is being circulated among underground actors.
- 2Info stealer drains $100K in crypto from 350+ victims●💸 $100K in crypto drained. 350+ victims. The withdrawal confirmation email rewritten in their webmail so nothing looks w
A malware strain called Underground is being linked to the theft of roughly $100,000 in cryptocurrency from more than 350 victims. The malware launches a victim's own signed-in Chrome or Edge browser, fakes a Binance two-factor authentication prompt to capture codes, and drains accounts. It also edits the withdrawal confirmation email inside the victim's webmail so nothing looks wrong, and uses a clipboard clipper to swap wallet addresses during transactions.