initial commit

This commit is contained in:
i2p
2026-08-27 11:22:37 -06:00
commit 2f6dd314cb
46 changed files with 27949 additions and 0 deletions
@@ -0,0 +1,318 @@
# Cryptocurrency Malware Distribution: Threat Intelligence Report (2025-2026)
**Report Date:** March 18, 2026
**Classification:** Defensive Threat Intelligence
**Period Covered:** January 2025 -- March 2026
---
## Executive Summary
Cryptocurrency-targeting malware has reached unprecedented scale and sophistication in 2025-2026. Total illicit crypto volume reached $158 billion in 2025 (TRM Labs), with scam activity alone accounting for approximately $30 billion. DPRK-linked actors stole $2.02 billion in cryptocurrency in 2025 -- a 51% year-over-year increase representing nearly 60% of all global crypto theft. Personal wallet compromises surged to 158,000 incidents affecting 80,000 unique victims, nearly triple the 54,000 incidents recorded in 2022. AI has become a force multiplier: roughly 60% of all funds flowing into crypto scam wallets in 2025 were tied to scammers using AI tools.
---
## 1. Distribution Platforms and Vectors
### 1.1 Telegram
Telegram has become the dominant platform for crypto malware distribution. Blockchain security firm Scam Sniffer reported a **2,000% increase** in Telegram-based malware crypto scams between November 2024 and January 2025.
**Key tactics:**
- **Fake verification bots:** A bot called "Safeguard" claims to verify identity before joining exclusive groups. It instructs users to run code on their devices for "manual identity confirmation," which installs malware that steals Telegram account details and crypto credentials.
- **Bot-based phishing:** Attackers use Telegram bots instead of websites, since bots are cheaper to create and users mistakenly trust the Telegram environment.
- **Malware-laced group infiltration:** Hackers distribute malware in popular trading and airdrop groups, or trick users into downloading fake Telegram apps or "antivirus" software.
- **Money laundering infrastructure:** Chinese-language money laundering networks funneled an estimated $16.1 billion in illicit funds through crypto transactions in 2025, advertising services on Telegram.
### 1.2 Discord
Discord remains a primary attack surface for crypto community targeting.
**Key campaigns:**
- **Expired invite link hijacking:** Check Point Research uncovered attackers hijacking expired Discord invite links through vanity link registration, silently redirecting users from trusted sources to malicious servers. This delivers AsyncRAT and a customized Skuld Stealer targeting crypto wallets using the ClickFix phishing technique with multi-stage loaders and time-based evasions.
- **Clipboard hijacking trojans:** CloudSEK uncovered threat actor "RedLineCyber" distributing "Pro.exe," a Python-based clipboard hijacking trojan designed for silent cryptocurrency theft, through Discord channels.
- **C2 abuse:** ChaosBot, a Rust-based malware discovered in October 2025, uses Discord channels for command-and-control operations.
- **RedTiger weaponization:** An open-source red teaming tool was converted into an infostealer capable of stealing Discord accounts, browser passwords, crypto wallets, and webcam images.
- **Payload hosting via trusted services:** Delivery and exfiltration occur via GitHub, Bitbucket, Pastebin, and Discord CDN, blending into normal traffic.
### 1.3 Twitter/X
- **Fake exchange promotions:** Scammers use DMs on X (formerly WhatsApp-based) to "accidentally" send login details to supposedly well-funded financial accounts.
- **Spoofed advertising:** Nearly 90 fraudulent token presale sites traced to a single threat actor group used X/Twitter ad loopholes with spoofed display URLs.
- **NFT creator targeting:** Threat actors use multiple identities to approach NFT creators on Twitter with fake business deals, tricking them into downloading malware-laced files.
### 1.4 YouTube
- **AI-generated crypto experts:** The National Cyber Security Centre reported AI-assisted scam channels that added over 100,000 followers in a single day. Videos instructed viewers to run code claiming to activate "TradingView developer mode," which installed malware stealing passwords, email access, and crypto wallet contents.
- **Fake MEV bot tutorials:** Over $1 million siphoned through AI-generated YouTube videos promoting malicious smart contracts disguised as MEV trading bots.
- **Fake Binance NFT bots:** RedLine malware distributed through YouTube videos promoting fake Binance NFT mystery box bots, hosted on GitHub repositories.
### 1.5 Facebook/Meta
- A persistent malvertising campaign exploits Facebook's ad network using branding from Binance and TradingView with celebrity images (Elon Musk, Zendaya). At least 75 malicious ads since July 2025 reached tens of thousands of users in the EU alone. The fake desktop client drops a malicious DLL, executing encoded PowerShell scripts that download additional malware.
### 1.6 Supply Chain (npm, GitHub, Browser Extensions)
- **npm poisoning:** Compromised JavaScript packages collectively downloaded more than 2.6 billion times in a single week contained crypto-stealing malware.
- **Trust Wallet supply chain attack:** Compromised npm packages drained 2,596 Trust Wallet wallets of $7 million in December 2025.
- **Browser extension compromise:** In January 2025, AdsPower's distribution system was compromised, replacing a legitimate browser plugin with a malicious version that stole mnemonic phrases and private keys.
---
## 2. North Korean Operations (Lazarus/TraderTraitor)
### 2.1 Scale
DPRK-linked actors stole **$2.02 billion** in cryptocurrency in 2025, a 51% increase year-over-year, representing **nearly 60% of all global crypto theft**. All-time North Korean crypto theft has reached an estimated **$6.75 billion**.
### 2.2 The Bybit Heist ($1.5 Billion)
The largest cryptocurrency heist in history, confirmed by the FBI on February 26, 2025:
**Attack chain:**
1. **Social engineering of Safe{Wallet} developer:** A developer was compromised through a targeted social engineering attack.
2. **Workstation compromise:** Attackers gained access to the developer's workstation and stole AWS session tokens, bypassing MFA controls.
3. **JavaScript injection:** On February 19, 2025, a benign JavaScript file on `app.safe.global` was replaced with malicious code specifically targeting Bybit's Ethereum multisig cold wallet.
4. **Delayed activation:** The malicious code was designed to activate during the next Bybit transaction, which occurred on February 21, 2025.
5. **UI manipulation:** When Bybit employees approved a routine transfer, the UI displayed a legitimate-looking transaction, but funds were redirected to attacker-controlled addresses.
6. **Laundering:** Rapid conversion through intermediary wallets, DEXs, and cross-chain bridges (THORChain, LI.FI), converting ETH to BTC to stablecoins.
### 2.3 TraderTraitor TTPs
- **Fake trading applications:** Electron and Node.js-based wrappers over open-source crypto tools, delivering MANUSCRYPT and RN Stealer RATs.
- **Fake job offers:** The DMM Bitcoin/Ginco breach ($308 million, 4,500 BTC) began with luring a developer through a fake job offer, deploying Python-based RATs, and harvesting cloud credentials.
- **Supply chain poisoning:** Cloud platform disruption and dependency compromises.
- **Target selection:** Financial services, cryptocurrency payments, brokerage, staking, and wallet infrastructure.
### 2.4 Related North Korean Actors
**UNC1069:** Active in 2025 targeting crypto sector with new tooling and AI-enabled social engineering.
---
## 3. Crypto Drainer Ecosystem
### 3.1 Scale and Economics
- Wallet drainer losses declined from $494 million (2024) to $83.85 million (2025), though attack volume increased.
- Dark web threads discussing drainers increased **135%** (55 in 2022 to 129 in 2024, continuing to grow).
- Signature phishing attacks surged **207%** in January 2026, draining $6.27 million from 4,700 wallets.
### 3.2 Drainer-as-a-Service (DaaS)
Drainer kits are sold for **$500 to $10,000** through Telegram groups and darknet forums. Packages include:
- Source code and admin panels
- Exploit libraries
- Phishing kit templates (fake websites, malicious scripts)
- Victim tracking dashboards
- Customer support
- Revenue-sharing agreements (typically 20-30% to the DaaS operator)
### 3.3 Major Drainer Families
**Inferno Drainer:**
- Estimated $80+ million stolen total, making it the largest contributor to drainer losses.
- Over 16,000 unique domains identified, impersonating at least 100 crypto brands.
- Despite announcing shutdown in late 2023, compromised 30,000+ wallets for $9+ million in the following months.
- March 2025 variant offloads C2 communication to customer-installed proxy servers, making infrastructure nearly untraceable.
- Maintains ~40-45% market share among drainer services.
**Angel Drainer:**
- Market share declining as of late 2025.
### 3.4 Drainer Distribution Methods
- Fake airdrop claim pages
- Impersonation of legitimate DeFi protocols
- Token approval phishing (tricking users into signing unlimited approvals)
- Off-chain signature phishing (eth_sign, permit2)
- Google/Twitter ad campaigns pointing to drainer-equipped sites
- Group-IB identified drainers masquerading as European tax authorities
---
## 4. Fake Applications and Platforms
### 4.1 Fake Meeting Apps (Meeten/Meetio)
Active since September 2024, this campaign targets Web3 professionals:
- **Fabricated companies** with AI-generated websites, blog posts, and social media accounts on X and Medium.
- **Social engineering via LinkedIn/Twitter:** Attackers set up video calls and prompt targets to download a "meeting app."
- **Cross-platform malware:** Both Windows and macOS versions target crypto wallets, banking info, browser data, and Keychain credentials.
- **Website-based theft:** Even without downloading the app, Meeten websites contain JavaScript that steals browser-stored cryptocurrency.
- **Constant rebranding:** Previously named "Clusee," "Cuesee," "Meetone," and "Meetio."
- **Theme expansion:** Now covers AI, gaming, Web3, and social media lures.
### 4.2 Fake Wallets
- **GlassWorm (January 2026):** Targets macOS developers through fake Visual Studio Code extensions designed to steal crypto, credentials, and system data.
- **Fake MetaMask extensions:** Malware campaign distributing fake MetaMask wallet with remote access backdoor.
- **StilachiRAT:** Sophisticated RAT discovered by Microsoft that scans for and targets MetaMask and other crypto wallet data.
- Personal wallet compromises surged to **158,000 incidents** affecting **80,000 unique victims** in 2025.
### 4.3 Fake Exchanges
- Fraudulent platforms (Morocoin, Berge, Cirkor) falsely claiming government licenses, totaling at least $14 million in theft.
- Facebook malvertising using Binance and TradingView branding.
- AI-generated "crypto experts" on YouTube driving downloads of trojanized trading tools.
### 4.4 Fake DeFi Platforms
- **Scam-as-a-service:** Operations auto-generate professional dApp layouts and liquidity-pool dashboards on multiple chains, cloning real logos and testimonials.
- **TetherBot.io (March 2025):** Fake "AI-powered trading platform" promising 1.25% daily returns, operating a 4-level referral Ponzi.
- A fake DeFi platform promising 30% weekly returns vanished with $12 million.
- Wallet-related fraud accounted for approximately **$1.7 billion** in losses during 2025.
### 4.5 Fake Trading Bots
- **Weaponized MEV bots:** Over $1 million drained through malicious smart contracts posing as MEV trading bots, promoted via AI-generated YouTube content.
- **$900K Ethereum smart contract scam:** Fake trading bots on Ethereum using obfuscated Solidity code.
- **Fake AI chatbots:** "Google Coin" presale site featuring a chatbot impersonating Google's Gemini AI to guide victims through crypto payments.
---
## 5. Social Engineering Techniques
### 5.1 Airdrop-Based Attacks
- FBI issued a specific announcement (June 2025) about NFT airdrop scams targeting Hedera Hashgraph wallet users.
- Malicious NFTs with hidden smart contracts are airdropped to thousands of wallets; interaction triggers wallet draining.
- Fake airdrop apps capture keystrokes, export seed phrases, or install RATs.
- In 2026, airdrop scams are "professionally engineered traps powered by AI, fake audits, cloned wallets, and social engineering."
### 5.2 Token Presale Scams
- **$GROK Presale scam:** Sophisticated phishing and wallet-draining operation that lured thousands of users.
- **$X Token presale:** Fake presale using token-x.live to collect wallet connections, private keys, and drain funds.
- Common pattern: connect wallet, sign "verification" transaction, or submit seed phrase through a "manual verification" form.
- **~37% of new token launches** in 2025 were rug pulls, per blockchain security firms.
### 5.3 MetaMask-Specific Phishing
- Phishing emails with party-hat fox logo claiming "mandatory 2026 system upgrade."
- "Suspicious login activity" warnings with fake PDF leading to counterfeit MetaMask login on AWS S3.
- ZachXBT tracked $107,000 drained from hundreds of wallets through fake MetaMask emails.
### 5.4 EtherHiding
A novel technique using blockchain infrastructure for malware distribution:
- Malicious content stored on BNB Smart Chain and Ethereum, making takedown nearly impossible.
- Payloads decrypted in-browser using AES GCM and executed after decompression.
- Transaction history used as a Dead Drop Resolver, embedding payloads in calldata.
- Updating malicious instructions requires only broadcasting a new transaction, turning the blockchain into a persistent, censorship-resistant command queue.
---
## 6. AI as a Force Multiplier
AI has fundamentally changed the crypto scam landscape in 2025-2026:
- **~60% of funds** flowing into crypto scam wallets tied to AI-assisted operations (Chainalysis).
- **AI-generated content:** Entire fake company websites, blog posts, social media profiles, and video presenters.
- **Scam-as-a-service platforms** auto-generate professional dApp frontends on multiple chains.
- **Deepfake influencers:** YouTube channels with AI-generated "crypto experts" gaining 100K+ followers in a day.
- **AI chatbot social engineering:** Fake Gemini chatbot guiding victims through crypto purchases.
- **Lowered barrier to entry:** Even low-skill criminals can now execute sophisticated campaigns.
---
## 7. Financial Impact Summary
| Metric | Value | Source |
|--------|-------|--------|
| Total illicit crypto volume (2025) | $158 billion | TRM Labs |
| Crypto scam activity (2025) | $14-17 billion (projected) | Chainalysis |
| DPRK crypto theft (2025) | $2.02 billion | Chainalysis |
| Bybit heist (single event) | $1.5 billion | FBI |
| Wallet-related fraud (2025) | $1.7 billion | Industry reports |
| Crypto hacks H1 2025 | $3.01 billion | CCN |
| Personal wallet compromises (2025) | 158,000 incidents / 80,000 victims | Chainalysis |
| Drainer losses (2025) | $83.85 million (declining) | Scam Sniffer |
| DPRK all-time crypto theft | $6.75 billion | BlockEden |
---
## 8. Defensive Gaps and Recommendations
### 8.1 Where Defenses Are Failing
1. **Supply chain trust:** Legitimate packages and browser extensions can be silently compromised, and users have no practical way to verify integrity at install time.
2. **Social engineering at scale:** AI-generated content makes fake companies, apps, and personalities indistinguishable from real ones.
3. **Blockchain as C2:** EtherHiding and on-chain payload storage cannot be taken down by traditional law enforcement.
4. **Off-chain signature phishing:** Users don't understand that signing seemingly benign messages can authorize unlimited transfers.
5. **Cross-chain laundering:** Rapid conversion through bridges and DEXs makes fund recovery nearly impossible.
6. **Telegram ecosystem:** Minimal moderation, bot infrastructure, and encrypted communications create an ideal environment for both distribution and operations.
### 8.2 Recommended Defensive Measures
1. **Transaction simulation and human-readable signing:** Wallets should show the actual effect of every transaction and signature before approval.
2. **Hardware wallet isolation:** Cold storage for high-value assets; never sign transactions from hot wallets on potentially compromised machines.
3. **Supply chain monitoring:** Pin dependency versions, audit updates, use lockfiles, and monitor for typosquatted packages.
4. **Phishing-resistant authentication:** Hardware security keys for exchange accounts; never trust email-based verification flows.
5. **Token approval hygiene:** Regularly audit and revoke unnecessary token approvals (revoke.cash, Etherscan token approval checker).
6. **Community education:** Focus on off-chain signature risks, airdrop interaction dangers, and fake meeting app campaigns.
7. **Behavioral monitoring:** Detect unusual wallet interaction patterns, especially sudden approval requests after social media engagement.
8. **Browser extension auditing:** Limit extensions, verify publisher identity, and monitor for unexpected updates.
---
## Sources
- [Cyble - 10 New Ransomware Groups of 2025](https://cyble.com/knowledge-hub/10-new-ransomware-groups-of-2025-threat-trend-2026/)
- [Kroll - H1 2025 Threat Landscape Report](https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/threat-landscape-report-lens-on-crypto)
- [Chainalysis - Crypto Ransomware 2026 Report](https://www.chainalysis.com/blog/crypto-ransomware-2026/)
- [Google Cloud - UNC1069 Targets Cryptocurrency Sector](https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering)
- [Google Cloud - UNC5142 EtherHiding](https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware)
- [Darktrace - Meeten Malware](https://www.darktrace.com/blog/meeten-malware-a-cross-platform-threat-to-crypto-wallets-on-macos-and-windows)
- [Bitget - Crypto Wallet Scams 2026](https://web3.bitget.com/en/academy/crypto-wallet-scams-2026-how-to-spot-fake-wallets-before-they-steal-your-money)
- [Malwarebytes - Best Wallet Scam](https://www.malwarebytes.com/blog/news/2025/10/dont-connect-your-wallet-best-wallet-cryptocurrency-scam-is-making-the-rounds)
- [TechWorm - GlassWorm Malware](https://www.techworm.net/2026/01/new-glassworm-malware-targets-macs-fake-crypto-wallet-tools.html)
- [Check Point Research - Discord Invite Hijacking](https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/)
- [CloudSEK - Discord Cryptojacking Campaign](https://www.cloudsek.com/blog/humint-operations-uncover-cryptojacking-campaign-discord-based-distribution-of-clipboard-hijacking-malware-targeting-cryptocurrency-communities)
- [The Hacker News - Discord AsyncRAT and Skuld Stealer](https://thehackernews.com/2025/06/discord-invite-link-hijacking-delivers.html)
- [Kaspersky - Discord Invite Link Hijacking](https://www.kaspersky.com/blog/hijacked-discord-invite-links-for-multi-stage-malware-delivery/53955/)
- [The Hacker News - ChaosBot](https://thehackernews.com/2025/10/new-rust-based-malware-chaosbot-hijacks.html)
- [Three Sigma - AI Trading Scams and DeFi Fraud](https://threesigma.xyz/blog/web3-security/ai-trading-scams-defi-fraud-forensics-part-4)
- [Halborn - Top 100 DeFi Hacks 2025](https://www.halborn.com/reports/top-100-defi-hacks-2025)
- [IC3/FBI - Hedera NFT Airdrop Scam Alert](https://www.ic3.gov/PSA/2025/PSA250603)
- [Kaspersky - Telegram Scams 2025](https://www.kaspersky.com/blog/phishing-and-scam-in-telegram-2025/54090/)
- [The Block - Telegram Malware Over Traditional Phishing](https://www.theblock.co/post/334954/telegram-malware-crypto-scams-rampant-over-traditional-phishing-scam-sniffer)
- [OKX - Telegram Crypto Scams Surge](https://www.okx.com/en-eu/learn/telegram-crypto-scams-malware-attacks)
- [CNBC - Chinese Crime Networks $16B Crypto](https://www.cnbc.com/2026/02/02/chinese-money-laundering-networks-crypto-telegram-2025-chainalysis-scam-southeast-asia-cambodia.html)
- [TRM Labs - Bybit Hack](https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit)
- [Picus Security - FBI Confirms Lazarus Bybit Heist](https://www.picussecurity.com/resource/blog/fbi-north-korean-lazarus-group-bybit-crypto-heist)
- [The Hacker News - Bybit Safe{Wallet} Supply Chain](https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html)
- [BlockEden - Lazarus $6.75B Playbook](https://blockeden.xyz/blog/2026/02/03/lazarus-group-playbook-north-korea-crypto-theft-6-75-billion/)
- [Brandefense - TraderTraitor APT 2025](https://brandefense.io/blog/tradertraitor-apt-2025/)
- [Wiz - TraderTraitor Deep Dive](https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist)
- [The Hacker News - DPRK $2.02B in 2025](https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html)
- [CoinDesk - Weaponized Trading Bots](https://www.coindesk.com/tech/2025/08/07/weaponized-trading-bots-drain-usd1m-from-crypto-users-via-ai-generated-youtube-scam)
- [SentinelOne - Ethereum Drainers as Trading Bots](https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/)
- [Picus Security - EtherHiding](https://www.picussecurity.com/resource/blog/etherhiding-how-web3-infrastructure-enables-stealthy-malware-distribution)
- [CertiK - Hack3d Web3 Security Report 2025](https://www.certik.com/resources/blog/hack3d-the-web3-security-report-2025)
- [Hypernative - State of Web3 Security 2026](https://www.hypernative.io/blog/the-state-of-web3-security-for-2026-winning-the-red-queen-race-in-cryptos-breakout-year)
- [Hackread - Fake Crypto Exchange Ads on Facebook](https://hackread.com/fake-crypto-exchange-ads-facebook-spread-malware/)
- [Malwarebytes - Fake Gemini AI Chatbot](https://www.malwarebytes.com/blog/ai/2026/02/scammers-use-fake-gemini-ai-chatbot-to-sell-fake-google-coin)
- [MetaMask - Security Report December 2025](https://metamask.io/news/metamask-security-report)
- [MetaMask - Security Report February 2026](https://metamask.io/en-GB/news/crypto-security-report-2026)
- [GBHackers - Fake MetaMask Wallet Malware](https://gbhackers.com/fake-metamask-wallet/)
- [Check Point Research - Inferno Drainer Reloaded](https://research.checkpoint.com/2025/inferno-drainer-reloaded-deep-dive-into-the-return-of-the-most-sophisticated-crypto-drainer/)
- [Group-IB - Inferno Drainer](https://www.group-ib.com/blog/inferno-drainer/)
- [Group-IB - Crypto Wallet Drainers](https://www.group-ib.com/resources/knowledge-hub/crypto-wallet-drainers/)
- [Security Alliance - State of Drainers Vol. 1](https://www.securityalliance.org/news/2025-10-drainers-vol-1)
- [Deep Code - Crypto Drainers 2025](https://decodecybercrime.com/crypto-drainers-of-2025-the-rising-web-of-wallet-theft/)
- [DeFi Planet - Drainers-as-a-Service](https://defi-planet.com/2025/08/crypto-drainers-as-a-service-how-these-new-age-scams-are-targeting-your-wallet/)
- [Kaspersky - 135% Surge in Drainer Interest](https://www.kaspersky.com/about/press-releases/kaspersky-reports-135-surge-in-interest-for-crypto-stealing-drainers-on-dark-web)
- [Chainalysis - 2026 Crypto Crime Report: Scams](https://www.chainalysis.com/blog/crypto-scams-2026/)
- [Chainalysis - 2026 Crypto Crime Report Introduction](https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/)
- [MalwareTips - $GROK Presale Scam](https://malwaretips.com/blogs/grok-presale-scam/)
- [Silent Push - X/Twitter Ad Scam](https://www.silentpush.com/blog/x-twitter-ad-scam/)
- [Bitdefender - Meta Malvertising Android](https://www.bitdefender.com/en-us/blog/labs/malvertising-campaign-on-meta-expands-to-android-pushing-advanced-crypto-stealing-malware-to-users-worldwide)
- [Bleeping Computer - Meeten Targets Web3 Pros](https://www.bleepingcomputer.com/news/security/crypto-stealing-malware-posing-as-a-meeting-app-targets-web3-pros/)
- [The Hacker News - Fake Gaming and AI Firms via Telegram/Discord](https://thehackernews.com/2025/07/fake-gaming-and-ai-firms-push-malware.html)
- [Group-IB - Declaration Trap: Drainers as Tax Authorities](https://www.group-ib.com/blog/declaration-trap/)
- [Ledger - Crypto Wallet Security Checklist 2026](https://www.ledger.com/academy/topics/security/crypto-wallet-security-checklist-protect-crypto-with-ledger)
- [Sumsub - 8 Crypto Scams 2025-2026](https://sumsub.com/blog/crypto-scams-you-should-be-aware-of/)