Inferno Drainer: A Deep Dive into Crypto Wallet-Draining Malware
ID: 384c83cd-8e89-52e2-b739-c1b306b83a70
STIX ID: report--384c83cd-8e89-52e2-b739-c1b306b83a70
Feed Name: Group-IB Blog
Group-IB details Inferno Drainer, a multichain wallet-draining malware active from November 2022 to November 2023 that operated as a scam-as-a-service: attackers hosted over 16,000 phishing domains impersonating more than 100 crypto brands, used spoofed Seaport/WalletConnect/Coinbase JavaScript libraries to trick users into approving malicious transactions, and reportedly stole at least USD $80 million; the report provides infrastructure analysis (domains, IPs, Telegram channels, panel behavior), script and ZIP file hashes, indicators of compromise, attack workflow, and recommendations to detect and mitigate these phishing drainers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
