The new malicious software Infamous Chisel is capable of stealing data from cryptocurrency wallets, trading platforms, and other sources.
According to a report by BlockBeats on September 1st, the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the UK Government Communications Headquarters (GCHQ) have jointly issued an advisory warning users to be vigilant against the new Russian malware Infamous Chisel, which steals data from encrypted wallets and trading platforms.
The report states that the malware is associated with the Sandworm hacker group within the Russian GRU military intelligence agency. Its design purpose is to allow continuous access to the attacked Android devices through the Tor network, and to collect and send data from these devices regularly. The malware also searches for Web3 browsers such as Brave, Binance and Coinbase applications, encrypted wallets like Trust Wallet, communication platforms like Telegram and Discord file directories, and extracts files from directories that allow users to store private keys in the Android Keystore system.