Automatically translated.View original post

Beware of New Torg Grabber data theft malware

Beware of Malware Data Theft New Torg Grabber Headed to Steal Money From More Than 700 Krypto Pockets

Despite the recent volatility of the Cryptocurrency industry, the malware focused on stealing Cryptokerrency money is still popular, especially this malware that has the ability to steal up to 700 wallets from a variety of developers.

According to a report by the website, Bleeping Computer has mentioned the detection of a malware distribution campaign, Torg Grabber, a malware-focused type that steals data from the victim's machine, or Infostealer that spreads by using fake error alerts to trick the victim into installing malware via the website, or ClickFix. According to a research team from Gen Digital, a cybersecurity software development specialist, this malware has an insidious ability because it can steal data from

A web browser built on the basis of Chromium to 25 web browsers.

The malware has the ability to break through the security system on the application or App-Bound Encryption (ABE).

It has the ability to shoot the DLL Injection into the web browser to steal the Encryption Key from Chrome's COM Elevation Service.

A web browser built on the basis of Firefox of 8 web browsers.

The web browser add-on arrived at 850.

Of these, it is an add-on that serves as up to 728 Krypto wallets, or it covers almost every bag available on the market, such as MetaMask, Phantom, TrustWallet, Coinbase, Binance, Exodus, TronLink, Ronin, OKX, Keplr, Rabby, Sui, and Solflare, among others.

Up to 103 Password Manager software covering LastPass, 1Password, Bitwarden, KeePass, NordPass, Dashlane, ProtonPass, Enpass, Psono, Pleasant Password Server, heylogin, 2FAAuth, GAuth, TOTP Authenticator, and Akamai MFA etc.

19 Note-Taking Applications

Various other popular applications such as Discord, Telegram, Steam, VPN app, FTP app, and Email Clients app, etc.

There are also many different capabilities: theft of system information, creation of hardware identity information (Hardware Fingerprints), compiling a list of all the software installed on the machine, secretly logging the screen, and stealing data from various folders of the victim's machine. Not only that, the malware also has the ability to run Shellcode code that will be sent from the C2 or Command and Control server in a Cha-Cha encoded file format. It can be called a malware with insidious capabilities that all readers need to be careful about.

# Trending # Lemon 8 Howtoo # lemon 8 diary # Krypto # freedomhack

4/16 Edited to

... Read moreจากประสบการณ์ส่วนตัวและการติดตามข่าวสารด้านไซเบอร์ซีเคียวริตี้ พบว่า New Torg Grabber เป็นหนึ่งในมัลแวร์ประเภท Infostealer ที่มีความซับซ้อนและอันตรายมาก เพราะไม่เพียงแต่ขโมยเงินในกระเป๋าคริปโต แต่ยังสามารถขโมยข้อมูลสำคัญจากแอปและส่วนเสริมในเบราว์เซอร์ถึง 850 ตัว ซึ่งส่วนใหญ่เป็นกระเป๋าเงินคริปโตที่นิยมใช้กันในตลาด เช่น MetaMask หรือ TrustWallet สิ่งที่ควรระวังเป็นพิเศษคือวิธีแพร่กระจายผ่านการแจ้งเตือนข้อผิดพลาดปลอมและการติดตั้งมัลแวร์จากเว็บไซต์ปลอม ทำให้ควรติดตั้งเฉพาะโปรแกรมจากแหล่งที่เชื่อถือได้เท่านั้น และไม่คลิกลิงก์หรือไฟล์ที่ไม่แน่ใจ ที่สำคัญมากคือมัลแวร์นี้สามารถฝ่าระบบความปลอดภัยอย่าง App-Bound Encryption และใช้วิธี DLL Injection เพื่อขโมยกุญแจเข้ารหัส ซึ่งหมายความว่าแม้จะใช้ฟีเจอร์ความปลอดภัยของแอปก็อาจถูกหลอกได้ ในฐานะผู้ใช้คริปโตและผู้ดูแลความปลอดภัยส่วนตัว ผมแนะนำให้ทุกคนติดตั้งและเปิดใช้งานโปรแกรมป้องกันไวรัสที่มีชื่อเสียง รวมถึงอัพเดทระบบและเบราว์เซอร์อยู่เสมอ อีกทั้งควรตั้งค่ารหัสผ่านที่ซับซ้อนและใช้การยืนยันตัวตนแบบสองขั้นตอน (2FA) เพื่อเพิ่มความปลอดภัย สุดท้าย การสำรองข้อมูลกระเป๋าคริปโตในที่ปลอดภัยและการใช้งานฮาร์ดแวร์วอลเล็ต (Hardware Wallet) จะช่วยลดความเสี่ยงจากการถูกขโมยข้อมูลโดยมัลแวร์ประเภทนี้ได้มาก ผมเองหลังจากรู้เรื่องมัลแวร์นี้ ก็ได้ทำตามคำแนะนำเหล่านี้เพื่อปกป้องทรัพย์สินดิจิทัลของตัวเองและแนะนำให้เพื่อนๆ พี่ๆ น้องๆ กลุ่มคริปโตได้ระวังตัวเช่นกันครับ