{"id":148254,"date":"2023-09-02T04:48:18","date_gmt":"2023-09-01T23:18:18","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=148254"},"modified":"2023-09-02T04:48:18","modified_gmt":"2023-09-01T23:18:18","slug":"new-russian-malware-dubbed-infamous-chisel-identified-targeting-binance-coinbase-and-trust-wallets-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/new-russian-malware-dubbed-infamous-chisel-identified-targeting-binance-coinbase-and-trust-wallets-crypto-news\/","title":{"rendered":"New Russian malware, dubbed \u2018Infamous Chisel,\u2019 identified targeting Binance, Coinbase, and Trust wallets &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<p>Newly discovered malware dubbed \u201cInfamous Chisel\u201d targets crypto wallets and other Android apps, according to a U.K. government report on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.ncsc.gov.uk\/static-assets\/documents\/malware-analysis-reports\/infamous-chisel\/NCSC-MAR-Infamous-Chisel.pdf\">Sept. 1<\/a>.<\/p>\n<p>The U.K.\u2019s National Cyber Security Centre (NCSC) said that the malware works by scanning various directories on infected mobile devices and exfiltrating data.<\/p>\n<p>The malware is known to extract data from at least three cryptocurrency wallets: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/products\/binance\/\">Binance App,<\/a> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/products\/coinbase-wallet\/\">Coinbase Wallet<\/a>, and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/products\/trust-wallet\/\">Trust Wallet<\/a>. Infamous Chisel also extracts data from the Brave and Opera browsers, both of which have cryptocurrency features.<\/p>\n<p>Because the malware is capable of extracting data in general, other apps are also targeted. PayPal, Dropbox, Firefox, Telegram, Skype, WhatsApp, Discord, Viber, and Google Chrome are among the other apps that are vulnerable to attack. A total of 35 application directories, including certain Android system directories, are scanned.<\/p>\n<p>The National Cyber Security Centre\u2019s report did not explicitly state that any data stolen from those apps could allow attackers to steal cryptocurrency, nor did it state whether Infamous Chisel has led to the theft of any cryptocurrency at all. It is possible that any information stolen does not provide attackers with full access to crypto accounts.<\/p>\n<h2>Russia\u2019s Sandworm is behind the threat<\/h2>\n<p>The latest report notes that Infamous Chisel is associated with Sandworm, a state-sponsored hacker group that is part of Russia\u2019s military intelligence service, GRU. The group is also known by other names including Telebots, Voodoo Bear, and Iron Viking. The group notably launched a high-profile <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/glossary\/ransomware\/\">ransomware<\/a> attack against Ukraine in November 2022 and has carried out other earlier attacks as well.<\/p>\n<p>Sandworm is currently using Infamous Chisel to steal information related to the Ukrainian military. The latest report does not describe any profit motives.<\/p>\n<p>Various international cybersecurity groups have recognized the threat, including those in the U.S., the U.K., New Zealand, Canada, and Australia.<\/p>\n<p>The post <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\/new-russian-malware-dubbed-infamous-chisel-identified-targeting-binance-coinbase-and-trust-wallets\/\">New Russian malware, dubbed \u2018Infamous Chisel,\u2019 identified targeting Binance, Coinbase, and Trust wallets<\/a> appeared first on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cryptoslate.com\">CryptoSlate<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Newly discovered malware dubbed \u201cInfamous Chisel\u201d targets crypto wallets and other Android apps, according to a U.K. government report on Sept. 1. The U.K.\u2019s National Cyber Security Centre (NCSC) said that the malware works by scanning various directories on infected mobile devices and exfiltrating data. The malware is known to extract data from at least [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":148255,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[230,225,221,227,226,228,229,60,223,224,222],"class_list":["post-148254","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-brave","tag-coinbase","tag-crypto","tag-decentralised","tag-decentralized","tag-decentralized-exchange","tag-erc-20","tag-featured","tag-meme-coin","tag-robinhood","tag-solana"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/148254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=148254"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/148254\/revisions"}],"predecessor-version":[{"id":148256,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/148254\/revisions\/148256"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/148255"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=148254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=148254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=148254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}