CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Malware Campaign Targets Crypto Wallets With Fake PDF Conversion Software
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Malware Campaign Targets Crypto Wallets With Fake PDF Conversion Software
News

Malware Campaign Targets Crypto Wallets With Fake PDF Conversion Software

CoinRSS
Last updated: April 23, 2025 11:02 pm
CoinRSS Published April 23, 2025
Share

Contents
In briefDaily Debrief Newsletter

In brief

  • A new malware campaign uses fake PDF to DOCX converters as a vector.
  • Victims are tricked into executing a PowerShell command, installing SectopRAT variant Arechclient2.
  • The malware can lift seed phrases and tap into Web3 APIs to drain assets.

A malware campaign is using fake PDF to DOCX converters as a vector for sneaking malicious PowerShell commands onto machines, enabling the attacker to access crypto wallets, hijack browser credentials and steal information.

Following an FBI alert last month, CloudSEK Security Research team has carried out an investigation revealing details about the attacks.

The goal is to trick users into executing a PowerShell command which installs the Arechclient2 malware, a variant of SectopRAT, an information stealing family known to harvest sensitive data from victims.

The malicious websites impersonate that of legitimate file converter PDFCandy, but instead of loading the real software, the malware is downloaded. The site features loading bars and even CAPTCHA verification in order to lull users into a false sense of security.

Ultimately, after several redirects, the victim’s machine downloads an “adobe.zip” file containing the payload—exposing the device to the Remote Access Trojan, which has been active since 2019.

This leaves users open to data theft, including browser credentials and cryptocurrency wallet information.

The malware “checks extension stores, lifts seed phrases, and even taps into Web3 APIs to ghost-drain assets post-approval,” Stephen Ajayi, Dapp Audit Technical Lead at blockchain security firm Hacken, told Decrypt.

CloudSEK advised people to use antivirus and antimalware software, and to “Verify file types beyond just extensions, as malicious files often masquerade as legitimate document types.”

The cybersecurity firm also advises that users rely on “trusted, reputable file conversion tools from official websites rather than searching for ‘free online file converters’,” and to consider using “offline conversion tools that don’t require uploading files to remote servers.”

Hacken’s Ajayi advised crypto users to remember that, “Trust is a spectrum, it’s earned, not given. In cybersecurity, assume nothing is safe by default.” He added that they should, “Apply a zero trust mindset, and keep your security stack up to date especially EDR and AV tools that can flag behavioral anomalies like rogue msbuild.exe activity.”

“Attackers evolve constantly and so should defenders,” Ajayi noted, adding that, “Regular training, situational awareness, and strong detection coverage are essential. Stay skeptical, prepare for worst-case scenarios, and always have a tested response playbook ready to go.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

FTM’s road to $3.38: Watch out for THESE key levels

Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

Mastercard Jumps Into Stablecoin Trend With New Crypto Payment Offering

Trump’s Crypto Picks Face Reality: XRP, ADA Hold Gains as Majors Slide

BONK price prediction: Assessing odds of a potential 22% rally

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article AI16Z gains 38% in a day: Mapping if this surge can continue
Next Article PEPE’s price to $0.00001500 next? – Yes, but first, it must…
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Musk-Trump Truce Sends Dogecoin Skyward, With Ethereum Along for the Ride: Analysis
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?