· April 2, 2018 · 4:30 pm
Cryptocurrency Malware ComboJack Targets Clipboard Data – Here’s How to Protect Yourself
Capitalizations Index – B ∞/21M
Malware identified by Palo Alto Networks targets data held on user clipboards from cut, copy and paste actions. ComboJack is a trojan able to replace unsuspecting user’s wallet data with the wallet address of an attacker.
ComboJack embeds itself on user systems with a possible source identified by Palo Alto Networks as phishing or malspam email. ComboJack will then frequently check the system clipboard for copied cryptocurrency wallet information.
If a genuine wallet address is identified, it is then replaced with a hardcoded wallet address presumed to belong to the attacker. Users unwittingly paste the incorrect wallet address when making a cryptocurrency transaction and send funds to the attacker instead of their desired location.
discovered the malspam targeting Japanese and American users with a campaign that could look something like this:

Opening an attached PDF file results in a message referring to an embedded doc file, which if opened, releases the ComboJack trojan to a user’s system.
The malware has been found to target bitcoin, Litecoin, Monero and Ethereum cryptocurrency wallet addresses as well as Yandex and WebMoney in USD and rubles.
The vulnerability exploited by ComboJack has been patched by Microsoft, so as long as users are running up to date operating systems they should be protected.
Users can also add protection for themselves from ComboJack and similar malware by not opening or downloading files with an unknown origin, and by ensuring that they are running active virus protection software.
Owners of beware! is attacking, using phishing emails.
— IntelliSyn (@intellisyn)
Cryptocurrency owners should also when copying and pasting that their entered transaction information matches the information they originally copied to ensure they are not mistakenly using an incorrect wallet address.
Checking transaction destination addresses before finalizing a transaction is a measure that may also prevent accidental transfers to incorrect wallets.
A quick double check of data can help to protect against losing funds to malware like ComboJack and CryptoShuffler, a similar malware program, and identify if a potential problem exists on a user’s system.
Have you lost coins in a malware attack or been hit by ComboJack? Let us know in the comments.
Image Courtesy of Shutterstock, Palo Alto Networks
Published at Mon, 02 Apr 2018 20:30:47 +0000
Altcoin News
India’s Supreme Court Sets 4-Week Deadline for Government to Regulate Cryptocurrency Time is running out for the Indian government and the Reserve Bank of India to ignore/wholesale ban cryptocurrency, according to a local publication called […]
News – CCN Cryptos on the Brink: Ethereum, Ripple Prices Plunge as Coins Post 2018 Lows The cryptocurrency markets continued to sour on Thursday, as the first quarter’s bearish wave continued to reverberate throughout the […]
New 31 THS Canaan Avalon A10 bitcoin ASIC Miner is Coming 29 Mar 2019 Canaan Creative has announced heir second generation 7nm AvalonMiner ASIC – the A10 that should be capable of delivering 31 THS […]