Nearly eight dozen cryptocurrency wallets, including MetaMask, Trust Wallet, and Phantom, have been targeted by the Meduza virus
The Meduza Stealer virus software has launched a hunt for 76 cryptocurrency wallets, including browser extensions. This is reported by cybersecurity specialists at Uptycs. According to the published blog post, the virus was probably developed in the Russian Federation or Belarus, since it does not attack victims' devices if their IP addresses originate from the territory of the CIS countries. Also, the developers of the virus conduct a public in Telegram both in Russian and dubbed in English.
The virus is distributed among attackers according to a subscription model: $199 for a month of work, $399 for three, or a perpetual license for $1199. By infecting the victim's Windows-based device, the owner of the virus can take screenshots of the victim's desktop, as well as steal browser data and other metadata related to Discord, Steam, and system files
The virus also pays special attention to cryptocurrencies. Meduza Stealer is hunting for seven dozen crypto wallets like MetaMask, Trust Wallet, Phantom, Binance Wallet, Guarda, OneKey, Opera Wallet, and so on. In addition to wallets, the virus also reads data from software clients such as Geth, Bitcoin Core, Dash Core, Monero Core, Dogecoin Core, and Litecoin Core. Uptycs urged users not to download files from unknown websites or open suspicious emails.
Subscription-based viruses have become especially popular among attackers in 2023. Earlier, the editors wrote that another infostealer BlackGuard is hunting for 57 cryptocurrency wallets.
At that time, the cost of a month of the virus cost attackers $200, and the unlimited version cost $700.
One of the Russian-speaking cybercriminals under the nickname hyipblock2 noted that "the stiller is dragging a pancake, really everything that is possible" [the style and spelling of the original is preserved].