Skip to content

Malware Targets Crypto Wallets Via Fake Software

Malware Campaign Exploits Fake PDF Converters to Target Crypto Wallets

  • A malware campaign uses fake PDF to DOCX converters to install the Arechclient2 malware.
  • The Arechclient2 variant is part of the SectopRAT family, known for stealing sensitive data.
  • Victims are tricked into executing a PowerShell command that downloads a payload disguised as “adobe.zip”.
  • The malware can access crypto wallets, hijack browser credentials, and steal information.
  • It taps into Web3 APIs to drain assets by lifting seed phrases and checking extension stores.

This malware campaign exploits fake file converters to install the Arechclient2 variant, allowing attackers to access crypto wallets and steal sensitive data through malicious PowerShell commands.

Source (2.6)https://decrypt.co/315961/malware-campaign-targets-crypto-wallets-with-fake-pdf-conversion-software?rand=52368
Share