Cryptocurrency

May 1, 2024 ยท View on GitHub

ID B0028
Objective(s) Collection, Credential Access
Related ATT&CK Techniques None
Version 2.3
Created 14 August 2020
Last Modified 27 April 2024

Cryptocurrency

Malware accesses files that contain sensitive data or credentials related to Bitcoin and other cryptocurrency wallets.

Methods

NameIDDescription
BitcoinB0028.001Access Bitcoin data.
EthereumB0028.002Access Ethereum data.
ZcashB0028.003Access Zcash data.

Use in Malware

NameDateMethodDescription
ElectroRAT2020--ElectroRat examines the disk for cryptocurrency addresses and keys to steal money from a wallet. It compromises multiple currencies, including Monaro, Doegecoin, Ethereum, Litecoin, and Bitcoin. [1]

Detection

Tool: CAPEMappingAPIs
infostealer_bitcoinCryptocurrency (B0028)--
infostealer_bitcoinCryptocurrency::Bitcoin (B0028.001)--

References

[1] https://www.intezer.com/blog/research/operation-electrorat-attacker-creates-fake-companies-to-drain-your-crypto-wallets/