en
Back to the list

TrickBot virus can now steal Coinbase accounts

04 September 2017 21:00, UTC

The experts from Forcepoint stated in their blog that the Trickbot malware had been updated with a new feature that allows to steal money and altcoins from Coinbase user accounts.

This virus is regularly being updated by its creators, previous updates were focused on the PayPal payment system exploits. Most security experts believe that its author has also developed the Dyre virus. The new August code version contains the set of strings that activate the feature to replace the login page of Coinbase.com with a fake, phishing input form, once the user wants to enter his account.

Coinbase is one of the most popular cryptocurrency platforms, it is mainly used to store funds. This Trojan horse virus can potentially compromise accounts – leak logins and passwords to hackers, who then withdraw funds and hide traces.

The new Coinbase-focused version was found after fake email messages were disseminated to many email. These messages posed as official Canadian Imperial Bank of Commerce (CIBC) announcements. That leads the experts to believe it was primarily targeted at Canadians.