logo

Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems

ID: 4c0b8c3b-178c-5cd7-a515-4a64c6964a27

STIX ID: report--4c0b8c3b-178c-5cd7-a515-4a64c6964a27

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-28

Author: Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley

...
...

This report analyzes a convergence between traditional malware and Web3-focused crypto theft, using two case studies: StepDrainer, a multichain drainer-as-a-service that uses polished AI/web lures, Web3Modal abuse, and automated extraction across >20 networks (with staging found across ~3,000 domains and on-chain configuration), and EtherRAT, a hybrid Windows implant distributed via a trojanized Tftpd64 MSI that establishes persistence, performs host reconnaissance, and includes Web3-aware RPC endpoints—demonstrating how browser-based drainers and host-level RATs now form blended attack chains targeting digital assets and enterprise hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.