Home > Quick > Body

某黑客利用自动挖矿脚本远控木马窃取受害者钱包私钥,用户请勿下载来历不明的程序

clock
2024-04-14 06:27:57
X用户@0xAA_Science发文提醒,不要下载/运行别人所谓的挖矿工具。最近POW币很火,有粉丝因为运行了别人发给他的挖矿工具(Windows系统VBS自动挖矿脚本),导致全链钱包的私钥被盗,损失超过20万美元。黑客是@HansoraSora,受害人已报警(也鼓励其他受害人报警)。用户不要下载来历不明的程序。
慢雾创始人余弦对此在X平台发文表示,对这个“挖矿工具”的样本简单分析了下,很容易发现这个猫腻的过程:开始的Ore.vbs核心目标是下载执行IWmkZ.vbs,IWmkZ.vbs核心目标是下载执行臭名昭著的Remcos远控。攻击者最终用这个远控就可以完成后续盗窃助记词文件、监听钱包密码等操作。
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
New Tab Page - Desk3 | Plugin
Stay ahead of the game in the cryptocurrency space.