May 19, 2026

Capitalizations Index – B ∞/21M

Malware Targets Israeli Fintech Firms Working in Crypto, Forex Trading

Malware targets israeli fintech firms working in crypto, forex trading

Malware Targets Israeli Fintech Firms Working in Crypto, Forex Trading

Malware targets israeli fintech firms working in crypto, forex trading

Israeli fintech companies that work with forex and crypto trading are being targeted by malware, according to a blog post from threat research department Unit 42 of cybersecurity company Palo Alto Networks published on March 19.

Per the report, Unit 42 first encountered an older version of the malware in question, Cardinal RAT, in 2017. Since April 2017, Cardinal RAT has been identified when examining attacks against two Israel-based fintech companies engaged in developing forex and crypto trading software. The software is a Remote Access Trojan (RAT), which allows the attacker to remotely take control of the system.

The updates applied to the malware aim to evade detection and hinder its analysis. After explaining the obfuscation techniques employed by the malware, the researchers explain that the payload itself does not vary significantly compared to the original in terms of modus operandi or capabilities.

The software collects victim data, updates its settings, acts as a reverse proxy, executes commands, and uninstalls itself. It then recovers passwords, downloads and executes files, logs keypresses, captures screenshots, updates itself and cleans cookies from browsers. Unit 42 notes that it witnessed attacks employing this malware targeting fintech firms that engaged in forex and crypto trading, primarily based in Israel.

The report further claims that the threat research team discovered a possible correlation between Cardinal RAT and a JavaScript-based malware dubbed EVILNUM, which is used in attacks against similar organizations. When looking at files submitted by the same customer in a similar timeframe to the Cardinal RAT samples, Unit 42 reportedly also identified EVILNUM instances.

The post further notes that also this malware seems to only be used in attacks against fintech organizations. When researching the data, the company claims to have found another case where an organization submitted both EVILNUM and Cardinal RAT on the same day, which is particularly noteworthy since both those malware families are rare.

EVILNUM is reportedly capable of setting up to become persistent on the system, running arbitrary commands, downloading additional files and taking screenshots.

As Cointelegraph recently reported, a Google Chrome browser extension tricking users into participating in a fake airdrop from cryptocurrency exchange Huobi claimed over 200 victims.

Also, a report noted last week that cybercriminals are reportedly favoring unhurried approaches in attacks made for financial gains, with cryptojacking as a prime example of this shift.

Published at Wed, 20 Mar 2019 04:15:04 +0000

Previous Article

Crypto Winter Strikes Again, Leaves Gaping Hole In Bithumb’s Side

Next Article

Craig Wright Rage Quits Twitter

You might be interested in …

shoes

shoesBy keep_bitcoin_real on 2011-07-06 07:49:58

Here Is The Really Big Shocker With The World Now On The Edge Of Destruction

Here Is The Really Big Shocker With The World Now On The Edge Of Destructionkingworldnews.com / April 15, 2017

On the heels of wild couple of weeks that included a missile attack against Syria and major posturing against North Korea, here is the really big shocker with the world now on the edge of destruction. 

The World Edges Closer To War
Stephen Leeb:  “You have to go back to the Cuban missile crisis in 1962 to find the world as close to nuclear war as today. As tensions surrounding North Korea ratchet up, it’s all too easy to imagine it could lead to a conflict that is part nuclear, part conventional, part chemical, in which millions die and the world’s economy loses trillions of dollars…

READ MORE

The post Here Is The Really Big Shocker With The World Now On The Edge Of Destruction appeared first on Silver For The People.