The US and UK Warn Crypto Users of Russian Malware
The US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the UK National Cyber Security Centre (NCSC) have issued a joint report advising crypto users to stay vigilant against newly discovered malware targeting wallets and exchanges. The report reveals a malware campaign conducted by Russian cyber actors against the Ukrainian military.
Main Breakdowns:
- A new strain of malware, called Infamous Chisel, targets Android devices used by Ukrainian military personnel.
- Infamous Chisel allows unauthorized access, scans files, monitors network traffic, and extracts sensitive data from compromised devices.
- The malware has been linked to Sandworm, a cyberwarfare unit operating under Russia’s military intelligence agency.
- Stolen data includes information from Binance, Coinbase, and Trust Wallet apps, with all files being exfiltrated indiscriminately.
- The components of Infamous Chisel lack basic obfuscation or stealth techniques.
CISA Executive Assistant Director for Cybersecurity Eric Goldstein emphasizes the need for collaboration and maintaining operational resilience against Russian cyber activity. The report also highlights the malware’s low to medium level of sophistication and its targeting of Android devices with weak detection systems.
Russian Entities Raise $20 Million in Crypto Funding
Despite sanctions, fundraising groups in Russia have accumulated $20 million in cryptocurrencies. The majority of these funds were traced to centralized crypto exchanges, indicating their popularity among sanctioned pro-Russian entities. These entities also engage with decentralized finance (DeFi) protocols, including cross-chain bridges, NFT services, and DEXes.
Hot Take: The joint report serves as a warning to crypto users about the ongoing threat of Russian cyber actors and the need for heightened vigilance. It also sheds light on the continued use of centralized exchanges and the emergence of DeFi protocols in the fundraising activities of sanctioned entities in Russia.