Monero download site and binaries compromised
ID: 73a2e213-9b2c-59ca-97e3-9c0ff75fcf7a
STIX ID: report--73a2e213-9b2c-59ca-97e3-9c0ff75fcf7a
Feed Name: Blaze's Security Blog
A short-lived supply-chain compromise of Monero CLI wallet binaries led to trojanized Linux (and a separate malicious Windows) binaries that exfiltrate wallet seeds to node.hashmonero.com and transmit stolen funds to node.xmrsupport.co and 45.9.148.65; additional indicators include 91.210.104.245 and multiple file hashes. The report outlines detection steps (checking for connections to listed hosts/IPs, verifying hashes, YARA), remediation (remove compromised binaries, restore seed, monitor transactions), and notes the Monero team’s statement confirming the brief compromise window, mapping the activity to MITRE ATT&CK T1195 (Supply Chain Compromise) and T1199 (Trusted Relationship).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
