Digital attackers are leveraging ads on the Telegram messenger app to target cryptocurrency owners with samples of HackBoss malware. One notable element of this campaign is that it’s targeting people who want to make a buck through sketchy means themselves. Read on to learn how the HackBoss actors are tricking wanna-be attackers via their own Telegram messenger channel.

Avast found over 100 cryptocurrency wallet addresses belonging to the malware family’s creators. Together, those wallets contained a collective total of over $560,000 at the time of analysis.

The actual amount stolen by HackBoss could be less, however. The security firm found that some of those wallet addresses were also associated with scams designed to trick users into buying fake software. This could be a sign that HackBoss’s handlers used the same cryptocurrency wallet addresses to conduct other campaigns.

Become a HackBoss… by Getting Infected Yourself

The malware actors used a Telegram messenger channel called HackBoss. There, they advertised applications claiming to be “the best software for hackers (hack bank / dating / bitcoin).”

But they never were. These fake cracking applications contained a link to an encrypted or anonymous file storage to download the software as a .zip file. When opened, the file ran a .exe that displayed a simple interface. Clicking on any of the buttons caused the campaign to decrypt and execute its malicious payload. It also led the campaign to trigger the malware every minute using a scheduled task and at startup using a registry key.

Once active, HackBoss regularly checked the clipboard content for anything resembling a cryptocurrency wallet address. When it found that format, the malware replaced the wallet with one of its own in an attempt to steal users’ cryptocurrency.

The creators of HackBoss didn’t just use the Telegram messenger channel to promote their malware. They also relied on a website containing promotional blog posts, YouTube channels with promo videos and advertisements on public forums and other websites.

Not the Only Threat Involving Telegram Messenger

HackBoss wasn’t the only malware campaign that recently involved Telegram. In October 2020, for instance, G Data Software wrote that attackers could control a new threat called T-RAT 2.0 using text-based commands over the Telegram messenger. This malware enabled anyone who controlled it to steal passwords, make off with cryptocurrency using clipboard information and capture screenshots.

Several months later, a malicious ad led users to a fake Windows desktop version of Telegram. The cloned Telegram messenger websites ultimately led the campaign to drop samples of the AZORult infostealer.

In April Check Point Research uncovered ToxicEye, a remote access trojan. Digital attackers relied on phishing emails to spread a malicious .exe. Once activated, the malware stole data, deleted files and/or encrypted data.

How to Defend Against Malware like HackBoss

Attacks like this underscore the need for organizations and users alike to exercise caution around cryptocurrency. As part of that effort, they need to confirm the wallet address to which they’re sending money. They also might consider setting up multi-factor authentication (MFA) as a means of preventing attackers from stealing access to their accounts.

More from News

LastPass Breaches Cast Doubt on Password Manager Safety

In 2022, LastPass suffered a string of security breaches which sparked concern among cyber professionals and those impacted by the intrusions. Some called into question the way LastPass handled and responded to the incident. In addition, the situation ignited a wider conversation about the risks linked to utilizing password managers.A password manager helps users generate strong passwords and safeguards them within a digital locker. A master password secures all data, which enables users to conveniently access all their passwords for…

Good Guys Decrypt Ransomware Targeting Charitable Groups

Imagine you’re an IT manager amid a ransomware attack. While your team scrambles for solutions, the intruders demand a ransom. Of course, you don’t want to pay; you just want your files back. But as time ticks by and the extortionists turn up the heat, your bosses are about to give in and pay the ransom. But then, the FBI calls. “Don’t pay,” the agent says. “We’ve found someone who can crack the encryption.” Sound too good to be true?…

Threat Groups Offer $240k Salary to Tech Jobseekers

Dark web forums are home to various individuals interested in conducting illicit or questionable activities. These forums offer opportunities such as the transaction of stolen data, Malware-as-a-Service, hacking services and invitations to collaborate in hacktivism. Cyber crime team members are recruited directly from the source: the dark web. What does this activity look like? Kaspersky recently conducted an analysis of 155 dark web forums from January 2020 to June 2022. They examined job postings and resumes that contained information about…

Cryptocurrency-Related Crime Boomed in 2022

Cryptocurrency crime is flourishing, according to multiple year-end reports. For starters, cryptocurrency losses due to cyber theft rose to $3.7 billion last year. That’s a 58% increase over the $2.3 billion malicious actors stole from investors and exchanges in 2021, according to a new report by Immunefi. Meanwhile, illicit cryptocurrency activity reached an all-time high of $20.1 billion in 2022, a $2.1 billion increase from the previous year. The escalating U.S. sanctions targeting digital currencies have contributed to that rise,…