ZeroHour

Search: “crypto-theft”

26 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency

Cisco Talos tracks a ClickFix crypto-theft campaign using Google Sheets as C2 to swap deposit addresses in Chrome.

Cisco Talos uncovered a cryptocurrency theft campaign that abuses Google Sheets and the Google Visualization API as a covert C2 channel, delivering obfuscated JavaScript into victims' Chrome browser sessions via ClickFix-style social engineering. Victims are lured with a fake "API Logic Flaw" report promising 25-38% bonuses on SimpleSwap and SwapZone swaps; the injected payload acts as a browser-based web skimmer that replaces deposit addresses, overrides the fetch API, and hijacks the clipboard. Later variants use the legitimate Tampermonkey extension with a user script for persistence without OS-level compromise. Talos identified 49 Bitcoin wallets, with 24 reused addresses receiving about 0.159 BTC (~$10,000) before mixing through more than 3,000 addresses.

GBHackers · 7d agoPhishing & fraud in the wild

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Talos tracks a crypto-theft campaign abusing the Google Visualization API for C2, using browser-based ClickFix lures to inject web-skimmer JavaScript.

Criminal actors convinced targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey extension, injecting a web skimmer into sessions on two cryptocurrency trading websites; Tampermonkey also provides persistence. Since March 2026 the campaign retrieved obfuscated scripts via the Google Visualization API from public Google Sheets documents, hooking the fetch API and replacing cryptocurrency deposit addresses in responses and the clipboard. Lures pose as leaked reports of a nonexistent API flaw at cryptocurrency swap services and spread via Telegram, DarkForums, and paste sites since early October 2025. Talos warns the legitimate-service-abuse techniques could enable wider supply-chain attacks on e-commerce and customer-facing systems.

Cisco Talos · 8d agoPhishing & fraud in the wild

Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks

Cisco Talos details a crypto-theft ClickFix campaign abusing Google Sheets to swap wallet addresses, with about $10,000 in observed Bitcoin losses.

Cisco Talos tracks a ClickFix-style campaign that tricks cryptocurrency traders into pasting JavaScript into Chrome's address bar or a Tampermonkey extension, promising fake bonuses on SwapZone and SimpleSwap. The loader pulls obfuscated JavaScript from cells in a public Google Sheet via the Visualization API, then behaves like a web skimmer, rewriting deposit addresses on screen, in web responses, and in the clipboard. Researchers counted 49 attacker-controlled Bitcoin addresses, with 24 receiving a combined 0.159 BTC, roughly $10,000, by early August 2026. A Tampermonkey variant re-injects the payload on every return visit, giving the attackers persistence despite takedown efforts.

Cyber Security News · 7d agoPhishing & fraud in the wild

Party’s over for scammers who went on spending spree after $240M bitcoin theft

AP report on scammers' spending spree after a $240 million bitcoin social engineering theft, as ringleader Malone Lam nears a plea agreement.

DataBreaches.net syndicates AP reporting on the $240 million bitcoin theft from a Washington, D.C. resident via social engineering calls impersonating Google and Gemini. Alleged ringleader Malone Lam, 22, faces a plea hearing; the scam network spent stolen funds on cars, jets, and mansions before FBI arrests. Crypto investment fraud complaints to the FBI rose nearly 50% in 2025.

DataBreaches.net · 8d agoPolicy & legal

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 16d agoPolicy & legal

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle

Malone Lam pleaded guilty in D.C. federal court to a racketeering conspiracy that stole and laundered over $245 million in cryptocurrency via social engineering.

Malone Lam, a 22-year-old Singapore citizen, pleaded guilty in Washington D.C. federal court to running a racketeering conspiracy that stole and laundered more than $245 million in cryptocurrency. The operation ran from at least October 2023 through May 2025, grew out of online gaming platforms, and relied on social engineering to trick victims into surrendering wallet access, sometimes including break-ins to victims' homes. Lam was arrested on September 18, 2025 in Miami; prosecutors said members spent lavishly on nightclubs, private jets, and exotic cars priced from $100,000 to $3.8 million.

Help Net Security · 7d agoPhishing & fraud

International Operation Disrupts Sality P2P Botnet

US-led international operation with Europol, CrowdStrike, and Shadowserver sinkholed the 20-year-old Sality P2P botnet, once exceeding one million infected machines.

On August 31, 2026, authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, disrupted the Sality P2P botnet by sinkholing communications and seizing domains. Sality has operated for over 20 years, at its peak controlling more than one million infected machines used for credential theft, spam, proxy services, crypto-theft, and DDoS attacks, with over 11 million unique IP addresses linked to its infrastructure since 2017. The disruption exploited the botnet's super-peer reputation mechanism by removing legitimate peers via protocol-level manipulation and inserting sinkhole entries into emptied peer lists.

Infosecurity Magazine · 13d agoMalware

Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

Malone Lam's plea hearing approaches in the $240 million bitcoin social engineering theft; the case highlights surging crypto fraud and limited enforcement.

Malone Lam, accused of organizing a social engineering attack that stole over $240 million in bitcoin (4,100+ BTC) from a Washington, D.C. resident in August 2024, has a plea agreement hearing set. Callers impersonating Google and Gemini staff tricked the victim into revealing security codes. Lam and 17 co-defendants spent lavishly before FBI arrests; crypto investment fraud complaints to the FBI rose nearly 50% in 2025 while DOJ disbanded its crypto crimes unit.

SecurityWeek · 8d agoPolicy & legal

Scammer behind $245 million crypto heist pleads guilty to RICO charges

Malone Lam, leader of a social engineering ring that stole over $245 million in cryptocurrency, pleaded guilty to US RICO charges.

Singaporean national Malone Lam, 22, pleaded guilty to RICO conspiracy charges for leading the 'Social Engineering Enterprise,' which stole more than $245 million in cryptocurrency. The group posed as Apple and Google customer support, tricked victims into installing remote desktop software, and even burgled homes to steal hardware wallets, including $263 million from a single Washington, D.C. victim. At least nine others have already pleaded guilty; Lam faces a December 8 sentencing hearing and a possible 7-to-20-year term.

The Record · 8d agoPhishing & fraud

The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT

Huntress found tampered Exodus crypto wallet installers delivering a modular RAT that steals credentials rather than wallet funds.

Huntress analysts analyzed tampered installers for the Exodus cryptocurrency wallet that bundle a modular remote access trojan. The implant focuses on harvesting credentials instead of draining wallet balances, suggesting broader access theft. The case highlights installer tampering as a supply-chain-style delivery vector for credential-stealing tooling.

Huntress · 15d agoMalware in the wild

Fraudsters steal $6 million from Tectonic crypto platform after inflating token price

Attackers inflated Tectonic's Tonic token price 100x in 20 minutes and borrowed $74 million against it, stealing $6 million before Cronos halted activity.

Attackers manipulated the price of Tectonic's thinly traded Tonic token, raising it more than 100-fold in 20 minutes, then used the inflated tokens as collateral to borrow assets in an attempted $74 million theft. About $6 million left the platform; Cronos halted blockchain activity and later restored roughly $69 million in frozen funds via an on-chain rollback. Tectonic plans a phased reopening and a postmortem. TRM Labs says market manipulation now accounts for one in eight crypto hacks, with 32 incidents in 2026, and compares the case to the 2022 Mango Markets manipulation that led to a criminal conviction.

The Record · 16d agoPhishing & fraud

Go-Based macOS Malware Steals Crypto and Secrets

Security researchers detected Go-based macOS malware stealing cryptocurrency, passwords, and other secrets from infected systems.

A Go-based malware variant targeting macOS has been detected in active use. The malware steals cryptocurrency, passwords, and other sensitive secrets from infected Macs.

Infosecurity Magazine · Aug 10, 2026Malware in the wild

A hacker stole $340M in a crypto heist, then returned most of it

A hacker exploited a bug to steal about 4,000 BTC (~$340M) from Blockstream's Liquid Network, then returned roughly 3,400 BTC after the bug was fixed.

A hacker exploited a bug to withdraw roughly 4,000 bitcoins worth about $340 million from Liquid Network, a settlement service launched in 2018 by crypto firm Blockstream and used by several cryptocurrency exchanges. Liquid Network paused operations, and the hacker, described as a white hat, offered to return the funds once the bug was fixed. Former Blockstream executive Samson Mow said the bug was fixed and about 3,400 BTC (~$293M) returned, leaving roughly 600 BTC (~$47M) under the hacker's control pending further security improvements. Rekt's leaderboard ranks the heist among the largest cryptocurrency thefts to date.

TechCrunch · Security · 8d agoExploit / PoC in the wild

Singaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty in Washington D.C.

Singaporean Malone Lam pleaded guilty in Washington D.C. to leading a social-engineering conspiracy that stole and laundered over $245 million in cryptocurrency.

Malone Lam, a 22-year-old Singaporean citizen residing in Miami, pleaded guilty in U.S. District Court in Washington D.C. for his role as ringleader of an international cybercrime conspiracy. The group used social engineering to steal cryptocurrency valued at more than $245 million and launder the proceeds. U.S. Attorney Jeanine announced the plea, which marks a major milestone in the prosecution of the crypto theft ring.

DataBreaches.net · 8d agoPolicy & legal

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

CrowdStrike links previously unseen Slim Spider group to crypto custody secret theft at Brazilian financial institutions since March 2026.

CrowdStrike is tracking Slim Spider, a previously undocumented financially motivated group attacking Brazilian financial institutions since at least March 2026. The actor used custom Bash scripts to steal temporary cloud credentials, exfiltrated digital asset custody secrets, and used Foundry's cast tool to derive Ethereum wallet addresses, while deploying Go-based backdoor MikeDor and an implant impersonating Brazil's SPI instant payment infrastructure. Slim Spider also pivoted to Azure DevOps and Kubernetes clusters and used panels including NEXUS // Scanner, Painel de Emails Entra ID, and Painel Pix for reconnaissance and unauthorized Pix transfers. Separately, Google Threat Intelligence Group and Mandiant disclosed Breeze Comet (CL-CRI-1163), a Portuguese-speaking group since 2024 that breaches Brazilian payment infrastructure to run fraudulent Pix, Boleto, and STR transactions.

The Hacker News · 8d agoThreat actor in the wild

From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline

Cyble walkthrough maps how infostealer logs move from endpoint infection through aggregation and enrichment to dark web credential marketplace sales.

Cyble breaks the credential theft pipeline into stages: infostealer execution harvesting browser credential stores, cookies, session tokens, crypto wallets, and FTP configurations; aggregation of stealer logs via C2 panels into bundled archives; parsing and enrichment against previously leaked datasets; and final listing on dark web marketplaces. Enrichment adds employer and role context that raises prices and enables credential stuffing across reused passwords. The report advises SOC teams to monitor stealer logs and marketplace chatter early rather than waiting for breach alerts.

Cyble · 6d agoMalware1

Risky Bulletin: BEC campaign steals €35 million from French notaries

Hackers stole over €35 million from 500+ French notary offices in a four-year BEC campaign; ANSSI spent two years helping evict the attackers.

A business email compromise campaign breached more than 500 French notary offices — about 7% of all French notaries per the Conseil Supérieur du Notariat — over four years, stealing more than €35 million by phishing initial access and silently modifying wire transfer details. France's cybersecurity agency ANSSI worked for two years behind the scenes to help notaries remove the persistent attackers, who had deep access; officials also feared hackers could issue fake notarized acts such as marriage certificates or forged real estate deals. No forged documents have been found so far, but notaries have added two-factor authentication and in-person requirements for banking details, and banks added extra checks in 2024. The newsletter also notes other incidents, including a $320 million Bitcoin extraction from Blockstream's Liquid Network and a JetBrains Cadence breach via TeamCity servers.

Risky Business News · 9d agoPhishing & fraud in the wild1

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 exposed infrastructure behind a cryptocurrency fraud pipeline using phishing panels, voice-dialing scripts, fake wallets, and AI coding assistants.

Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation tracked as Operation ASTERIX. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Recovered prompts, shell history, and project files show the operator relied on AI coding assistants to package Electron applications, obfuscate code, troubleshoot builds, and modify phishing infrastructure.

Rapid7 Blog · Aug 17, 2026Phishing & fraud

Berlin refuses to be blackmailed after network breach

Rhysida extorts Berlin's state government after stealing 5.79 TB across 1.44 million files, demanding roughly 2 million euros in bitcoin.

Berlin's state government confirmed an extortion attempt after data theft from its administrative network between August 7 and 12, with affected departments disconnected only on August 14. The Rhysida ransomware gang lists 5.79 TB across 1.44 million files on its leak site, including HR files, contracts, 148 IBANs, personal data on 12,076 individuals, and plaintext credentials from internal systems including Berlin's leadership. Der Spiegel reports a 30 bitcoin demand of about 2 million euros; officials say the city will not pay and investigators include the State Criminal Police Office and federal agencies. Forensics revealed additional leaks in the Senate Department for Mobility, Transport, Climate Protection and the Environment, while the Berlin House of Representatives election environment is reported secure.

Help Net Security · 15d agoRansomware in the wild

Hackers are stealing Claude tokens from subscribers

Infostealer malware is stealing Claude login sessions, letting attackers mint OAuth tokens and burn subscribers' paid usage largely undetected.

Anthropic confirmed a bad actor used common infostealer malware to steal Claude login sessions from users' computers and consume their paid usage. A UK consultant saw idle token usage climb, and Anthropic suspended his account, invalidated sessions and Claude Code tokens, and issued a £44.49 partial refund on his $200-per-month plan. Multiple other users on Reddit and GitHub reported similar theft; Anthropic signed out affected users and issued refunds, but still lacks itemized usage reporting to help users detect misuse.

TechCrunch · AI · 8d agoAI safety & security in the wild1

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

Microsoft correlates over 30 rotating domains to track MacSync Stealer, which steals passwords, SSH keys, wallets and AWS credentials.

Microsoft Defender Experts tracked MacSync Stealer, a macOS information stealer, by analyzing recurring behaviors rather than individual domains, linking over 30 domains to the campaign. The infection chain uses the ClickFix social engineering technique, tricking victims into pasting commands in Terminal, then uses curl, AppleScript, and native macOS tools to deploy the payload. The stealer targets Keychain data, browser passwords and cookies, SSH keys, AWS credentials, Kubernetes configurations, and Ledger and Trezor wallet data, staging data before exfiltration via chunked HTTP PUT requests. RST Cloud identified rapid C2 infrastructure replacement after initial public disclosure.

Security Affairs · 28d agoMalware

ClickFix Moves into the Browser to Steal Cryptocurrency

Cisco Talos details a ClickFix campaign injecting browser JavaScript via Google Sheets to skim crypto deposits, stealing at least ~0.159 BTC since October 2025

Cisco Talos reported a months-long ClickFix campaign that shifted from OS command execution to injecting JavaScript through Chrome's address bar or the Tampermonkey extension into sessions on two cryptocurrency trading sites. Since March 2026 the operators fetch obfuscated payloads via the Google Visualization API from public Google Sheets, replacing displayed deposit addresses and amounts and overriding the fetch API, and the campaign survived two disruption attempts. Talos observed 49 Bitcoin addresses with 24 receiving at least 0.159 BTC (~$10,000) by early August, with proceeds routed through roughly 30 wallets and more than 3,000 addresses in apparent mixing. Lures posed as leaked vulnerability reports describing non-existent API flaws at crypto swap services, promising payouts up to 38% higher.

Infosecurity Magazine · 7d agoPhishing & fraud in the wild

Revolut handed customer data to fraudsters using government email account

Revolut handed sensitive KYC data of high-net-worth crypto customers to fraudsters submitting fake emergency data requests from a compromised government email domain.

Revolut confirmed it disclosed sensitive customer data—including passport and driver's license copies, verification selfies, bank statements, IBANs, and Bitcoin transaction histories—to attackers who submitted fraudulent emergency data requests from a legitimate government agency email account, apparently an Italian domain. Targets were high-net-worth individuals involved in crypto, including Marc Karpelès and entrepreneur Marc Zeller. A Telegram account claiming responsibility posted stolen data as proof and demanded an extortion payment; the account has since been suspended. Revolut says only a limited number of customers were affected and has alerted the relevant government agency, law enforcement, and regulators. The technique mirrors 2021-2022 Lapsus$-linked fraudulent emergency data request scams against Apple, Meta, and Discord.

The Record · 2d agoData breach