-1.00% Bitcoin (BTC) 90801.4 EUR
-0.93% Ethereum (ETH) 2087.38 EUR
-0.55% Litecoin (LTC) 73.22 EUR
+4.60% B-Cash (BCH) 449.46 EUR
+0.26% Ethereum (ETH) 0.0232401 BTC
+0.49% Litecoin (LTC) 0.00081406 BTC
+5.81% B-Cash (BCH) 0.00496617 BTC
-0.60% Bitcoin (BTC) 108035.8014 USDC
-0.38% USD Coin (USDC) 0.84 EUR
-1.01% Chainlink (LINK) 11.33 EUR
+0.08% Chainlink (LINK) 0.00012482 BTC
-2.01% Dogecoin (DOGE) 0.13 EUR
-1.29% Dogecoin (DOGE) 0.00000153 BTC
-3.28% Uniswap (UNI) 6.03 EUR
-2.07% Uniswap (UNI) 0.00006666 BTC
-0.67% Cardano (ADA) 0.48 EUR
+0.37% Cardano (ADA) 0.00000531 BTC
-0.09% Tron (TRX) 0.23 EUR
+1.15% Tron (TRX) 0.00000263 BTC
-1.61% Shiba Inu (SHIB) 0.00000974 EUR
-6.97% Zcash (ZEC) 31.93 EUR
0.00% Zcash (ZEC) 0.0004242 BTC
0.00% TradeFlow (TFLOW) 0.12216892 BUSD
-10.16% Arbitrum (ARB) 0.3253 USDC
-0.57% Chainlink (LINK) 13.2 USD
-0.63% Chainlink (LINK) 13.21831 USDC
-2.78% Uniswap (UNI) 7.051 USDC
-2.39% Ondo (ONDO) 0.64 EUR
-2.16% Ondo (ONDO) 0.75602 USDC
-4.93% Gala (GALA) 0.01 EUR
-4.35% Gala (GALA) 0.01385 USDC
-5.57% Wormhole Token (W) 0.05 EUR
-5.29% Wormhole Token (W) 0.0698 USDC
-3.05% Chiliz (CHZ) 0.02 EUR
-2.66% Chiliz (CHZ) 0.03474 USDC
-2.38% Sand (SAND) 0.2 EUR
-2.11% Sand (SAND) 0.2358 USDC
-1.05% Aave (AAVE) 228.84 EUR
-1.05% Aave (AAVE) 269.5 USDC
-0.50% Curve DAO (CRV) 0.43 EUR
-0.29% Curve DAO (CRV) 0.5065 USDC
-4.77% Immutable X (IMX) 0.36 EUR
-4.26% Immutable X (IMX) 0.4327 USDC
0.00% Skale (SKL) 0.07 USDC
-4.20% Beam (BEAM) 0 EUR
-3.63% Beam (BEAM) 0.00557 USDC
0.00% Axelar (AXL) 1.05 USDC
-4.44% Livepeer Token (LPT) 5.19 EUR
-4.09% Livepeer Token (LPT) 6.114 USDC
-3.07% Compound (COMP) 37.2 EUR
-2.79% Compound (COMP) 43.8 USDC
+5.18% Coti (COTI) 0.04 EUR
+5.89% Coti (COTI) 0.0521 USDC
0.00% Portal (PORTAL) 1.1 USDC
+4.94% Sushi (SUSHI) 0.51 EUR
+4.77% Sushi (SUSHI) 0.6034 USDC
+6.74% Pepe (PEPE) 0 EUR
+6.81% Pepe (PEPE) 0.00000988 USDC
+7.79% Optimism (OP) 0.48 EUR
0.00% Polygon (MATIC) 0.2 EUR
+10.10% Solana (SOL) 133.64 EUR
+10.67% Solana (SOL) 0.001463 BTC
+7.89% Solana (SOL) 0.063179 ETH
+0.34% USD Coin (USDC) 0.72 GBP
0.00% USD Coin (USDC) 1 USDT
0.00% USD Coin (USDC) 145.58 JPY

Blackberry warns Mexican crypto exchanges of lurking cyberthreat

01-25-2024

The threat pattern suggests that attackers mainly target large companies in Mexico with over $100 million in gross revenues.

The research and intelligence arm of Blackberry, a tech giant previously dominating the cellphone market, identified and alerted about a financially motivated attacker targetting numerous high-net-worth Mexican cryptocurrency exchanges and banks. 

Blackberry’s report identified an attack that attempted to steal sensitive user information from banks and crypto trading services using an open-source remote access tool named AllaKore RAT. The threat aims to install the tool in company-run computers and databases, often bypassing employees' suspicion by hiding behind official naming schemes and links. The report added:

“The AllaKore RAT payload is heavily modified to allow the threat actors to send stolen banking credentials and unique authentication information back to a command-and-control (C2) server for the purposes of financial fraud.”

The threat pattern suggests that attackers mainly target large companies with gross revenues over $100 million. Such companies report directly to the Mexican Social Security Institute (IMSS), Blackberry noted.

Most of the attacks were traced back to Mexico Starlink IPs. Additionally, considering the use of Spanish-language instructions to the modified RAT payload, Blackberry concluded that the threat actor is based in Latin America.

The newer iterations of AllaKore RAT follow a more complex process of installation, wherein the software is delivered to the targets in a Microsoft software installer (MSI) file. The software executes only after confirming Mexico as the current location of the victim.

However, the scope of the threat is not limited to large banks and crypto trading services. The same method is being used to target large Mexican corporations from other business verticals, including retail, agriculture, public sector, manufacturing, transportation, commercial services and capital goods.

The cyber attacks conducted via basic phishing continues to increase along with its success rate in stealing funds. On Jan. 20, contact information of nearly 66,000 users of hardware wallet manufacturer Trezor were leaked in a security breach. While alerting the users, Trezor said:

“We want to stress that none of our users’ funds have been compromised through this incident. Your Trezor device remains as secure today, as it was yesterday.”

At the time of reporting, at least 41 users had received direct email messages from the attacker requesting sensitive information about their recovery seeds. Considering the myriad of data leaks across the crypto ecosystem, investors are advised to refrain from sharing sensitive information unless verified.

Source: Cointelegraph.