SentinelOne: Вредоносное ПО Webrat крадет данные криптокошельков геймеров

cryptonews.ruPublicado em 2025-03-28Última atualização em 2025-05-28

Эксперты по кибербезопасности компании SentinelOne обнаружили новое вредоносное программное обеспечение под названием Webrat, нацеленное на геймеров и их криптовалютные кошельки.

По информации SentinelOne, Webrat представляет собой троян удаленного доступа (RAT), который распространяется через поддельные сайты, имитирующие популярные игровые платформы, такие как Steam, а также через фишинговые письма и вредоносные ссылки в игровых чатах.

Основная цель такой программы — кража конфиденциальной информации геймеров, которые активно участвуют в блокчейн-играх (Play-to-Earn) или используют криптовалюты для покупки внутриигровых предметов.

Согласно исследованию, Webrat способен перехватывать закрытые ключи и сид-фразы криптокошельков, включая учетные данные игроков, что позволяет злоумышленникам получать доступ к цифровым активам пользователей. Программа также собирает данные о банковских картах, паролях и другой информации.

Эксперты SentinelOne отмечают, что Webrat использует сложные методы сетевой маскировки, включая шифрование данных и динамическое изменение кода, что затрудняет его обнаружение антивирусами.

Аналитики центра киберугроз Solar 4RAYS добавили, что первые версии вредоноса появились в даркнете в начале 2025 года, и сейчас он доступен для покупки через закрытые каналы. При этом злоумышленники маскируют вредонос под другие приложения, а также распространяют его через ссылки в комментариях на YouTube.

Ранее блокчейн-обозреватель Cyvers Alerts сообщил, что неизвестный криптовалютный инвестор стал жертвой двойной фишинговой атаки, потеряв в совокупности около $2,5 млн в стейблкоинах Tether (USDT).

Leituras Relacionadas

Michael Saylor Identifies Bitcoin's 'Most Significant Breakthrough' in History

Michael Saylor, Executive Chairman of Strategy Inc., identifies Bitcoin's most significant breakthrough as its ability to transform economic energy into digital form and securely anchor it to individuals, families, companies, machines, or nations. He positions Bitcoin as a monetary technology enabling digital control of economic value, rather than merely a tradable cryptocurrency. This builds on his previous thesis describing Bitcoin as digital monetary energy, characterized by proof-of-work, fixed supply, digital transferability, and owner-controlled keys. Technically, Bitcoin does not legally tie coins to an identity but enables controlled digital ownership through cryptographic credentials. Ownership depends on securing private keys, which authorize transactions. While blockchain analysis allows for transaction tracking, Saylor's concept emphasizes the control aspect. Strategy Inc. serves as a corporate example, holding a large Bitcoin reserve. As of mid-August, the company reported owning 840,447 BTC. It has executed several sales in recent weeks. Saylor also outlines a four-tier digital money model with Bitcoin at the equity level. Beyond corporate adoption, U.S. banking regulators note increasing interest, with many recent bank charter applicants proposing digital asset-related activities, including stablecoin payments. Institutional analyses, like one from Fidelity Digital Assets, assess Bitcoin's properties such as scarcity and decentralization but caution about its speculative and volatile nature, without endorsing Saylor's energy metaphor.

cryptonews.ruHá 2m

Michael Saylor Identifies Bitcoin's 'Most Significant Breakthrough' in History

cryptonews.ruHá 2m

The Danger of Old Bookmarks: How an Expired Tornado Cash Domain Cost a User 1,000 ETH

A user lost over 1,010 ETH (worth millions) due to a phishing attack via an expired official domain of the Tornado Cash protocol. As reported on August 20, 2026, the domain `tornado.cash` was not renewed by the original developers amid U.S. OFAC sanctions and was subsequently registered by malicious actors. They deployed a fake frontend mimicking the legitimate Tornado Cash interface. Through this site, the attackers gained access to the user's deposit notes—the data required to withdraw funds from the protocol's pools—and drained the ETH within 12 hours. On-chain data shows the stolen funds (e.g., wallet 0xd8B356...) were withdrawn from Tornado Cash pools. However, on-chain analyst Specter cast doubt on the victim's story. He suggested the individual might be involved in illicit activity, noting that a large sum of BTC was received from a coin-mixing service (Whirlpool) and converted to ETH before being sent to the fake Tornado Cash site. The victim's explanation of urgently moving funds due to a compromised hardware wallet was questioned, as the fund trail indicated deliberate obfuscation. Specter speculated this might be a conflict between malicious actors rather than a simple phishing case. The incident highlights the danger of expired domains for major protocols, where old bookmarks can lead to compromised sites. WHOIS records show the domain was registered in March 2025. Broader analysis notes that in 2025, over $1.8 billion was lost to scams and exploits, largely through social engineering like phishing via familiar but hijacked links. This case underscores the persistent risk when a domain's legal status changes but user trust and search engine reputation remain.

cryptonews.ruHá 44m

The Danger of Old Bookmarks: How an Expired Tornado Cash Domain Cost a User 1,000 ETH

cryptonews.ruHá 44m

Trading

Spot
活动图片