FatalRAT Targets Cryptocurrency Users
ID: 0a257b2c-abe8-5470-add7-74c6fd735f4d
STIX ID: report--0a257b2c-abe8-5470-add7-74c6fd735f4d
Feed Name: Cyble Blog
CRIL discovered a targeted phishing campaign that mimics the Exodus cryptocurrency wallet to deliver a trojanized installer which uses DLL side‑loading to load FatalRAT (a remote access trojan), an address‑swapping clipper, and a keylogger; the malware monitors clipboards, replaces crypto addresses with attacker wallets, logs keystrokes, and exfiltrates data to C2 servers. The report provides a detailed technical analysis of the multi‑stage infection chain, artifacts, YARA rule, multiple SHA256 file hashes, C2 domains/IPs, and recommended mitigations for crypto users and platform operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
