February 15, 2026

Be careful on Bitcoin (BTC) Transactions – Cryptos City

Be careful on Bitcoin (BTC) Transactions – Cryptos City

Stealing Your Bitcoin Transactions from Your Own Browser, The malware “Masad Clipper and Stealer”. It steals browser data, which might contain usernames, passwords + information. Masad Stealer also automatically replaces cryptocurrency wallets from the clipboard with its own.

“I found this after it happen to me”

Juniper Threat Labs discovered a new Trojan-delivered spyware that uses Telegram to exfiltrate stolen information. Using Telegram as a Command and Control (CnC) channel allows the malware some anonymity, as Telegram is a legitimate messaging application with 200 million monthly active users.The malware is being advertised on black market forums as “Masad Clipper and Stealer”. It steals browser data, which might contain usernames, passwords and credit card information. Masad Stealer also automatically replaces cryptocurrency wallets from the clipboard with its own.Masad Stealer sends all of the information it collects — and receive commands from — a Telegram bot controlled by the threat actor deploying that instance of Masad. Because Masad is being sold as off-the-shelf malware, it will be deployed by multiple threat actors who may or may not be the original malware writers.

What it does

This malware is written using Autoit scripts and then compiled into a Windows executable. Most samples we have seen are about 1.5 MiB in size, however, Masad Stealer can be found in larger executables as it is sometimes bundled into other software.
When Masad Stealer is executed, it drops itself in %APPDATA%folder_name}, where folder_name and file_name are defined in the binary. Examples include amd64_usbhub3.inf.resources and ws2_32.exe, respectively. As a persistence mechanism, mMasad Stealer creates a scheduled task that will start itself every one minute.

Stealing routine

After installing itself, Masad Stealer starts by collecting sensitive information from the system, such as:

Cryptocurrency Wallets
PC and system information
Credit Card Browser Data
Browser passwords
Installed software and processes
Desktop Files
Screenshot of Desktop
Browser cookies
Steam files
AutoFill browser fields
Discord and Telegram data
FileZilla files

complete article here on cryptoscity

Published at Sun, 29 Sep 2019 02:31:53 +0000

{flickr|100|campaign}

Previous Article

Bitcloud Pro AMA with G Crypto Chat – Bitcloud Pro

Next Article

La Economía de Ethereum 2.0 en Español – Crypto Patoruzú

You might be interested in …