• +31 320 760020
  • support@yokdata.com

WARNING : New Anubis malware targets digital currency wallets on Windows

Posted on Sep 6, 2020
WARNING : New Anubis malware targets digital currency wallets on Windows

Microsoft has warned against a new form of malware that’s targeting Windows users. Known as Anubis, the malware steals digital currency wallet credentials, credit card details and other valuable data.

The malware shares a name with yet another potent banking Trojan that has been targeting Android smartphones for months now. However, the new malware form is targeting Windows users, Microsoft Security Intelligence (MSI) revealed recently.

MSI first discovered the malware in June when it was being sold in the cybercriminal underground, it revealed on Twitter. Anubis relies on code forked from Loki, an info-stealing malware that targets Android systems. MSI revealed that Anubis has been stealing digital currency wallet credentials and credit card details, among others.

The malware is not as widespread, MSI revealed, claiming that it has only been deployed in “what appears to be limited, initial campaigns that have so far only used a handful of known download URLs and C2 servers.

Anubis, which is named after the Egyptian god of death, is downloaded from certain websites, Tanmay Ganacharya told CoinDesk. Ganacharya, who is a partner director of security research at Microsoft, revealed that the malware steals information and then sends it to command and control servers via a HTTP POST command.

When successfully executed it attempts to steal information and sends stolen information to a C2 server via HTTP POST command. The post command sends back sensitive information that may include username and passwords, such as credentials saved in browsers, credit card information and cryptocurrency wallet IDs.

Full article on https://nationalcybersecuritynews.today/microsoft-microsoftsecurity-new-anubis-malware-targets-digital-currency-wallets-on-windows/

#windows #anubis #malware #microsoft #wallet #yokdata #mindyourdata