logo

Inferno Drainer: A Deep Dive into Crypto Wallet-Draining Malware

ID: 384c83cd-8e89-52e2-b739-c1b306b83a70

STIX ID: report--384c83cd-8e89-52e2-b739-c1b306b83a70

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2024-01-16

Date Updated: 2026-04-27

...
...

Group-IB details Inferno Drainer, a multichain wallet-draining malware active from November 2022 to November 2023 that operated as a scam-as-a-service: attackers hosted over 16,000 phishing domains impersonating more than 100 crypto brands, used spoofed Seaport/WalletConnect/Coinbase JavaScript libraries to trick users into approving malicious transactions, and reportedly stole at least USD $80 million; the report provides infrastructure analysis (domains, IPs, Telegram channels, panel behavior), script and ZIP file hashes, indicators of compromise, attack workflow, and recommendations to detect and mitigate these phishing drainers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.