logo

Scammers mass-mailing the Efimer Trojan to steal crypto

ID: 5f579ddd-3f63-5397-a288-8394af759a2d

STIX ID: report--5f579ddd-3f63-5397-a288-8394af759a2d

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2025-08-08

Date Updated: 2026-04-29

Author: Artem Ushkov, Vladimir Gursky

...
...

Kaspersky describes the Efimer campaign: a ClipBanker/infostealer that spreads via malicious email attachments, compromised WordPress sites and torrent lures, installs a Tor proxy for C2, replaces copied cryptocurrency wallet addresses and exfiltrates mnemonic seeds and screenshots; the threat includes additional modules for WordPress brute-force and email harvesting, with multiple file hashes, onion C2 URLs, and ~5,015 affected Kaspersky users (highest activity in Brazil).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.