Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems
ID: 4c0b8c3b-178c-5cd7-a515-4a64c6964a27
STIX ID: report--4c0b8c3b-178c-5cd7-a515-4a64c6964a27
Feed Name: LevelBlue SpiderLabs Blog
Date Published: 2026-04-23
Date Updated: 2026-04-28
Author: Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley
This report analyzes a convergence between traditional malware and Web3-focused crypto theft, using two case studies: StepDrainer, a multichain drainer-as-a-service that uses polished AI/web lures, Web3Modal abuse, and automated extraction across >20 networks (with staging found across ~3,000 domains and on-chain configuration), and EtherRAT, a hybrid Windows implant distributed via a trojanized Tftpd64 MSI that establishes persistence, performs host reconnaissance, and includes Web3-aware RPC endpoints—demonstrating how browser-based drainers and host-level RATs now form blended attack chains targeting digital assets and enterprise hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
