CyberSecurity SEE

Underground Crypto Theft Operation Extracts $100K

Underground Crypto Theft Operation Extracts 0K

Cryptocurrency-Theft Operation Targets Victims with Browser Hijacking

A sophisticated and alarming operation targeting cryptocurrency users has officially drained approximately $100,000 from unsuspecting victims by hijacking their authenticated browser sessions, as detailed in recent research from Netskope Threat Labs. This intricate malware campaign, aptly named "Underground" after the folder path utilized—C:\ProgramData\Underground—has employed a multi-stage infection methodology to inject malicious code directly into legitimate browsing sessions on Google Chrome and Microsoft Edge. The operation has reportedly been active since at least October 2023, with telemetry data confirming its inception during this time.

The mechanics of this malicious operation commence with victims extracting Trojan-laden archive files that contain seemingly harmless components: a legitimate-looking setup.exe, a compromised msys-crypto-3.dll library, and an encrypted data.bin file. While the specific delivery method for these files remains uncertain, the execution process is pivotal to the malware’s success. Once these components are launched, the Underground loader initiates a series of extensive anti-analysis checks, scanning for an impressive 67 different security tools. These tools include popular debuggers like IDA, x64dbg, and OllyDbg, as well as network monitors such as Wireshark and Fiddler. Moreover, the loader checks for virtual machine environments to hinder detection and analysis.

Following these preventive measures, the loader proceeds with a covert operation to decrypt an embedded payload using unique AES keys tied to the specific build. This malicious payload is then injected into a suspended dllhost.exe process. Consequently, the malware activates the victim’s browser using their pre-existing profile, complete with all saved credentials intact. This seamless integration into the browser’s session represents a remarkable technical achievement for the attackers, allowing the malware to operate efficiently while going undetected.

Once operational, the malware establishes communication with one of seven rotating command-and-control (C2) domains through an /api/machine/* protocol. This connection facilitates the retrieval of a 9 MB JSON configuration file that contains a range of injection scripts designed for over 15 cryptocurrency exchanges and web platforms. Surprisingly, the focus on Binance accounts is particularly notable; the malware displays a fake overlay that masquerades as the legitimate two-factor authentication prompt. This deceptive overlay, available in approximately 25 languages, is employed to disable withdrawal allowlists, convert account balances into USDC and subsequently Bitcoin, ultimately allowing the attackers to siphon off 100% of smaller account balances and 90% of larger ones. The illicit funds are then funneled to a reserve pool consisting of 11 Bitcoin addresses.

Additionally, the malware showcases its capability by monitoring accounts across various webmail platforms, including Gmail, Outlook, Yahoo, and ProtonMail. It intercepts withdrawal confirmation emails by altering their subject lines and content in about 24 languages to mimic ordinary messages, thereby evading detection.

Netskope researchers estimate that there are at least 350 to 430 paying victims based on the unique sending addresses discovered within blockchain transactions. However, the actual number may be higher, given that funds drained from exchange accounts often originate from the exchanges’ own wallets, preventing precise individual tracking. Transactions extracted from victims varied significantly in value, with most averaging around $82 but some reaching as high as $18,800 in a single transfer. The malware also includes a clipboard clipper featuring 32 rules that govern approximately two dozen cryptocurrencies, systematically replacing copied wallet addresses with those controlled by the operators across more than 80 destination addresses spanning roughly 23 different blockchain networks. Notably, as of September 2026, these wallets are still active and continue to receive new deposits.

In light of these developments, organizations are advised to interpret any blocked connection attempts to identified gate domains as indicators of active infection. Infected machines have demonstrated the capability to poll these blocked gates for extended periods, searching for any new domains that may emerge. Security defenders should be vigilant in scanning for dllhost.exe injection activity, as well as any Chrome or Edge browser processes initiated by dllhost.exe. Furthermore, careful examination of artifacts within C:\ProgramData\Underground\ is essential, although it should be noted that the malware typically deletes this folder after use.

Netskope recommends implementing behavioral URI detection mechanisms for the /api/machine/* endpoint alongside domain reputation blocking. This defensive strategy is vital, as the malware’s operators are adept at rotating domains much faster than reputation systems can classify them. Moreover, due to the stealthy design of the malware’s stealer component—which never stores files on the disk as standalone entities—traditional file-based detection methods are likely insufficient for identifying compromised systems.

Organizations and individuals must remain vigilant in light of the intricacies of this operation, reassessing their security protocols to mitigate the risk of such sophisticated cyber intrusions.

For further reading, the full report can be accessed at Netskope Threat Labs Blog.

Source link

Exit mobile version