<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GreetingGhoul cryptocurrency thief &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/greetingghoul-cryptocurrency-thief/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Mon, 19 Jun 2023 11:37:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>GreetingGhoul cryptocurrency thief &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Multi-phase DoubleFinger malware steals cryptocurrencies in Europe, the United States and Latin America</title>
		<link>https://bitfinance.news/en/multi-phase-doublefinger-malware-steals-cryptocurrencies-in-europe-the-united-states-and-latin-america/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 19 Jun 2023 20:00:48 +0000</pubDate>
				<category><![CDATA[Cryptocurrencies]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[cryptocurrencies]]></category>
		<category><![CDATA[cyberdeliyos]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[GreetingGhoul cryptocurrency thief]]></category>
		<category><![CDATA[Latin America]]></category>
		<category><![CDATA[Remcos trojan]]></category>
		<category><![CDATA[usa]]></category>
		<category><![CDATA[walets]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=95588</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Malware multifase DoubleFinger roba criptomonedas en Europa, Estados Unidos y Latinoamérica" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash.jpg 1200w, https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash-300x169.jpg 300w, https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash-1024x576.jpg 1024w, https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>A group of researchers has discovered a campaign of attacks against cryptocurrency wallets in Europe, the United States and Latin America, which operates through the DoubleFinger multi-stage malware, which deploys the GreetingGhoul cryptocurrency thief and the Remcos Trojan. Currently, cybercriminal interest in cryptocurrency is growing at a rapid pace, and in this case, malicious actors [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/multi-phase-doublefinger-malware-steals-cryptocurrencies-in-europe-the-united-states-and-latin-america/">Multi-phase DoubleFinger malware steals cryptocurrencies in Europe, the United States and Latin America</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Malware multifase DoubleFinger roba criptomonedas en Europa, Estados Unidos y Latinoamérica" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash.jpg 1200w, https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash-300x169.jpg 300w, https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash-1024x576.jpg 1024w, https://bitfinance.news/wp-content/uploads/2023/06/keepcoding-lVF2HLzjopw-unsplash-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p style="text-align: justify;">A group of <strong>researchers</strong> has discovered a campaign of <strong>attacks against cryptocurrency wallets in Europe, the United States and Latin America,</strong> which operates through the <strong>DoubleFinger multi-stage malware</strong>, which deploys the <strong>GreetingGhoul cryptocurrency thief and the Remcos Trojan.</strong></p>
<p style="text-align: justify;">Currently, <strong>cybercriminal</strong> interest in cryptocurrency is growing at a rapid pace, and in this case, malicious actors have come to develop criminal software very similar to <strong>Advanced Persistent Threats (APTs) to access these assets.</strong></p>
<p style="text-align: justify;">This is a campaign that uses a complex &#8216;software&#8217; of a high technical level based on a multi-phase execution, which is called DoubleFinger. This campaign has been launched with the aim of stealing <strong>cryptocurrency credentials</strong> from users in European and Latin American countries, as well as the United States, as detailed by a group of Kaspersky researchers.</p>
<p style="text-align: justify;">In this sense, according to the investigation carried out by the cybersecurity company, it is an a<strong>ttack deployed</strong>, on the one hand, by the GreetingGhoul cryptocurrency thief and, on the other hand, by the<strong> Remcos Remote Access Trojan (RAT).</strong></p>
<p style="text-align: justify;">The<strong> attack starts when a user unknowingly opens a malicious file with a</strong> <strong>PIF extension,</strong> which can be attached to an email, and which is a <strong>program information document.</strong> That is, it contains the information necessary for the <strong>Windows operating system t</strong>o execute its content.</p>
<p style="text-align: justify;">Once this malicious &#8216;software&#8217; is opened, the first phase of the attack begins, which uses a <strong>Windows</strong> <strong>binary DLL</strong>, this is a library that contains code and data, but modified <strong>to execute a &#8216;shellcode&#8217;.</strong></p>
<p style="text-align: justify;">This &#8216;shellcode&#8217;, which is the code used to execute a <strong>malicious activity</strong> on the victim&#8217;s computer, downloads a PNG image containing the malicious payload, which is launched at a <strong>later stage of the process.</strong></p>
<p style="text-align: justify;">At this point, as Kaspersky has learned, DoubleFinger records up to <strong>five phases to program GreetingGhoul,</strong> thus managing to activate its use every day at a specific time on the victim&#8217;s device.</p>
<p style="text-align: justify;">Thus, with GreetingGhoul up and running, they proceed to<strong> steal cryptocurrency credentials using two components.</strong> On the one hand, <strong>MS WebView2,</strong> which is based on the creation of overlays on the interfaces of the victim&#8217;s cryptocurrency wallet. Second, a service that steals confidential information, ie password recovery keys or phrases. With all this, <strong>cybercriminals gain access to cryptocurrencies.</strong></p>
<p style="text-align: justify;">On the other hand, <strong>Kaspersky</strong> has detailed that cybercriminals also use DoubleFinger to deploy the <strong>Remcos RAT remote access Trojan,</strong> which malicious actors often use for their attacks <strong>against companies and organizations.</strong></p>
<p style="text-align: justify;">Specifically, the &#8216;shellcode&#8217; of this Trojan has <strong>steganography capabilities</strong> (the ability to hide messages within messages) and uses Windows COM interfaces to carry out silent execution, making its detection more complex.</p>
<h2 style="text-align: justify;">Protection for cryptocurrencies</h2>
<p style="text-align: justify;">As explained by the principal security analyst at<strong> Kaspersky&#8217;s GReAT, Sergey Lozhkin,</strong> who belongs to the group of researchers who discovered this new DoubleFinger threat, against this type of attack, the <strong>protection of cryptographic wallets &#8220;is the responsibility of the providers of wallets,</strong> individuals, and the cryptocurrency community in general.&#8221;</p>
<p style="text-align: justify;">Based on this, he has warned that if users are <strong>&#8220;alert, informed and solid security measures</strong> are implemented&#8221; users can manage to mitigate these &#8220;valuable digital assets&#8221;.</p>
<p style="text-align: justify;">Within this framework, <strong>Kaspersky has provided some recommendations</strong> in order to keep crypto assets safe. First of all, he has highlighted the importance of<strong> buying wallets only from official sources and, furthermore, he has pointed out that with &#8216;hardware wallets&#8217; it will never be necessary to enter the seed phrase into the computer.</strong></p>
<p style="text-align: justify;">In case of buying a<strong> &#8216;hardware wallet&#8217;, u</strong>s<strong>ers must also check that it has not been tampered with.</strong> In fact, any trace of glue, scratch or foreign component could be an indication that it has been handled previously. Another measure to take into account is to verify the &#8216;firmware&#8217;, in addition to implementing passwords that are difficult to crack.</p>
<p style="text-align: justify;">Source: dpa</p>
<p style="text-align: justify;"><em>(Reference image source: KeepCoding, Unsplash)</em></p>
<p style="text-align: justify;"><em>Visit our news channel on </em><a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener"><strong><em>Google News</em></strong></a><em> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on </em><a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><strong><em>Twitter</em></strong></a><em> and </em><a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><strong><em>Instagram</em></strong></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/multi-phase-doublefinger-malware-steals-cryptocurrencies-in-europe-the-united-states-and-latin-america/">Multi-phase DoubleFinger malware steals cryptocurrencies in Europe, the United States and Latin America</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
