Research by Kaspersky has unveiled a new cyber attack, highlighting the use of SourceForge as a platform for distributing malware targeting cryptocurrency users.
Fraudulent Scheme on SourceForge
Cybercriminals set up a fake project named 'officepackage' that mimics Microsoft Office add-ons. Users would see a fake list of office applications with download links intended to initiate the malware infection.
How the Malware Functions
Clicking on these fake links routes users through several redirects before delivering a zip file. Once unzipped, it provides a bloated 700MB installer that uses hidden scripts to grab additional files and deploys malware aimed at stealing cryptocurrency.
Geography of Attacks and User Threats
Kaspersky researchers report that 90% of affected users are in Russia, with over 4,600 hits recorded between January and March. The primary aim of this campaign is to steal cryptocurrency, but infected machines may also be sold to other malicious actors.
This campaign underscores the need for vigilance among cryptocurrency users and awareness of effective device protection against malware.