Cybersecurity threats targeting cryptocurrency users have escalated through the misuse of Node.js and fake applications. Since October 2024, threat actors have launched a malware campaign deploying fake Binance and TradingView installers, leveraging Node.js and PowerShell to deliver malicious payloads including ClickFix tricks, SectopRAT malware, fake PDF tools, and HR-themed phishing attacks. Additionally, Chinese Android phones have been found pre-installed with counterfeit WhatsApp and Telegram apps aimed at crypto users. WhatsApp has been a frequent vector for scams, with hackers now exploiting calls, messages, and photos to target users. In response, WhatsApp plans to notify users with guidance on protecting themselves from scams. These developments highlight ongoing cybersecurity challenges in the cryptocurrency and messaging app ecosystems.
Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView Installers: https://t.co/4OowKZIs8W by The Hacker News #infosec #cybersecurity #technology #news
🚨 Microsoft Alert: Node.js-Powered Malware Campaign Ongoing... Since Oct 2024, fake Binance & TradingView installers have been used to deploy malware via Node.js and PowerShell. Linked threats include ClickFix tricks, SectopRAT malware, fake PDF tools, and HR-themed phishing https://t.co/0J9mNK8xzS
WhatsApp to message users about protecting themselves from scams https://t.co/KAZ9qU7X1J