CIO Influence
CIO Influence News Security

SafeGuard Cyber Detects New Crypto-Stealing Trojan in Telegram

SafeGuard Cyber Launches Advanced Multi-Channel Security with Microsoft 365 Email Protection

SafeGuard Cyber, the leading provider of security and compliance solutions for todayโ€™s email and communication-based threats, has discovered a new information stealer targeting cryptocurrency investors in Telegram.

SafeGuard Cyberโ€™s multi-channel SaaS-based protection platform, which utilizes natural language understanding (NLU) and machine learning technologies to detect and prevent threats across 30 digital communication platforms, first identified the new malware sample in June. The Trojan, which was hidden inside an image file, was detected immediately after it was posted in a public cryptocurrency Telegram channel used by investors and enthusiasts.

โ€œThis malware was intended to target new or unsuspecting users of the Telegram channel, with the goal of stealing their cryptocurrency wallet keys,โ€ saidย Storm Swendsboe, Director of Threat Intelligence of SafeGuard Cyber. โ€œThe Trojan also has backdoor capabilities, which could potentially be used to update or add new features to it, thereby enhancing or expanding its malicious uses in the future.โ€

ITechnology Cloud News: Jenne Cloud Services Brokerage Joins Invoca Partner Program to Help Businesses Drive Growth

Key highlights of the new crypto-stealing Trojan:

  • The Trojan has backdoor functions as well as data stealing functions.
  • It creates hidden copies of the victimโ€™s private and public key store in order to steal cryptocurrency.
  • It also beacons the attacker to confirm the connection is active, suggesting a Command-and-Control (C2) infrastructure.
  • This malware hides itself as an operating system file on the victimโ€™s machine.
  • When deployed in Telegram, the specific sample SafeGuard Cyber analyzed was concealed in an image file to avoid detection. The lure for this malware appears to be spamming images until a victim inadvertently clicks on the attachment.

ITechnology Cloud News: Vibes Announces the Launch of Its Mobile Experience Platform on Salesforce AppExchange

โ€œThreat actors are increasingly using Telegram and other digital communication platforms to spread malware and compromise victims,โ€ saidย Otavio Freire, President and CTO of SafeGuard Cyber. โ€œThis poses an even larger threat than cryptocurrency theft. Once a Trojan infects an employeeโ€™s device, the attacker can then use it to spread laterally within the company or organization. As companies have shifted to cloud-based platforms and hybrid workplaces, employees are utilizing a growing number of diverse digital channels to communicate, nearly all of which are unmonitored by traditional security solutions. This has created an enormous blind spot for businesses and an ideal opportunity for threat actors.โ€

SafeGuard Cyber detects attacks and identifies risk by understanding how humans interact and communicate. The companyโ€™s NLU-based SaaS platform offers the industryโ€™s most advanced visibility and detection of phishing, account takeover, impersonation, BEC, insider threats and malware attacks that span theย full range of modern business communications channels, including social media, collaboration, mobile messaging, conferencing, CRM and theย Microsoft 365 ecosystem.

ITechnology Cloud News: Recorded Future Acquires Hatching to Extend Intelligence Cloud Coverage with Malware Analysis

[To share your insights with us, please write toย sghosh@martechseries.com]

Related posts

Bipsync and Lionpoint Group Announce Strategic Partnership

GlobeNewswire

High-End Electric Vehicle Brand VOYAH Officially Landed in Norway

Accenture and Microsoft Expand Collaboration on Gen-AI Powered Cyber Solutions

Business Wire

Leave a Comment