• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Wednesday, May 14, 2025
  • Login
  • Register
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

This new virus could empty your crypto exchange wallet automatically

by Reshab Agarwal
April 6, 2023
in Crypto, Crypto Exchanges, News
Reading Time: 2 mins read
0
This new virus could empty your crypto exchange wallet automatically
TwitterWhatsappLinkedin

Crypto exchanges are not safe in themselves, and now a new virus has been found that could empty your exchange wallet automatically. It is called Rilide Masquerades and is used as a G-drive extension that can let hackers do a bunch of things. They can scour through your browsing history, take screenshots and, worst of all, withdraw your funds. All Chromium-based browsers like Edge, Opera and Chrome are vulnerable to this new virus.

You might also like

U.S.-Saudi business lunch attended by Elon Musk, Sam Altman, and Top U.S. CEOs

DHL to Lay Off Over 360 Workers as Major California Warehouse Shuts Down Amid Industry Upheaval

SoftBank Group Posted its First Annual Profit in Four Years Sparks Renewed Investor Confidence

Crypto hodlers are in danger

Spiderlabs, the company that reported this new virus, says that it fools users into giving their two-factor authentication code by showing them forged dialogue boxes. Once it gets access to the user’s crypto account, withdrawing the funds is a piece of cake. Crypto holders do not even have any idea that their account has been compromised, and till the time they know, it’s too late.

Talking about where the virus came from, it was found that many extensions of similar types are on sale. In fact, because of some payment dispute, a part of its code was also leaked in an underground forum.

Two malevolent campaigns resulting in the installation of the Rilide extension were discovered by the researchers. The first campaign utilized a module that contained a coded blob of data holding the Rilide loader’s URL. The second campaign, on the other hand, involved the execution of the payload via the start-process PowerShell cmdlet, which was hosted on Discord CDN and saved to the %temp% directory.

How does the virus work?

If Rilide identifies a Chromium-based browser, it utilizes a Rust loader to install the extension. The loader modifies shortcut files that open the targeted web browsers by adding the parameter –load-extension, which directs to the dropped malicious Rilide extension.

To enable the extension to execute an attack and load external resources that would typically be blocked by the Content Security Policy (CSP), the malware’s background script adds a listener to specific events and removes the CSP directive for all requests.

Rilide’s crypto exchange scripts include a withdrawal function that operates in the background. To obtain the user’s 2FA code, a forged device authentication dialogue is presented while the withdrawals are being processed. Additionally, if the user accesses their mailbox using the same web browser, email confirmations are replaced on the fly, leading the user to unknowingly provide the authorization code.


What are your thoughts as this new virus could empty your crypto exchange wallet? And have you come across it till now? Let us know in the comments below. And if you found our content informative, share it with your family and friends.

Also Read: What Elon Musk just did is unbelievable; he kept his promise!

Tags: #CryptoExchangeVirus
Tweet54SendShare15
Previous Post

American Airlines end traditional flyer award

Next Post

Bernard Arnault becomes the world’s richest person with net worth of $200 billion

Reshab Agarwal

Reshab is a tech-enthusiast who likes to write about all things crypto. He is a Bitcoin bull and believes in a decentralized future of finance. Follow him on Twitter for more!

Recommended For You

U.S.-Saudi business lunch attended by Elon Musk, Sam Altman, and Top U.S. CEOs

by Anochie Esther
May 14, 2025
0
Power lunch

In a moment that blended geopolitical symbolism with corporate ambition, some of the most powerful figures in American business gathered around a lunch table in Riyadh this week,...

Read more

DHL to Lay Off Over 360 Workers as Major California Warehouse Shuts Down Amid Industry Upheaval

by Anochie Esther
May 14, 2025
0
DHL

DHL is preparing to lay off more than 360 employees as it shutters a major warehouse in Ontario. The closure, set to begin this July and complete by...

Read more

SoftBank Group Posted its First Annual Profit in Four Years Sparks Renewed Investor Confidence

by Anochie Esther
May 14, 2025
0
SoftBank Group

In a much-needed win for Japan’s investment powerhouse, SoftBank Group has posted its first annual profit in four years a financial milestone that not only signals a rebound...

Read more
Next Post
Bernard Arnault becomes the world’s richest person with net worth of $200 billion

Bernard Arnault becomes the world's richest person with net worth of $200 billion

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at [email protected]

Advertise With Us

Reach out at - [email protected]

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook flipkart funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News NFT samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2024 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2024 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?