• bitcoinBitcoin (BTC) $ 66,266.00
  • ethereumEthereum (ETH) $ 1,995.99
  • tetherTether (USDT) $ 0.999330
  • bnbBNB (BNB) $ 612.36
  • xrpXRP (XRP) $ 1.34
  • usd-coinUSDC (USDC) $ 0.999734
  • solanaSolana (SOL) $ 82.84
  • tronTRON (TRX) $ 0.314051
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.091236
  • usdsUSDS (USDS) $ 0.999794
  • whitebitWhiteBIT Coin (WBT) $ 51.35
  • bitcoin-cashBitcoin Cash (BCH) $ 477.56
  • hyperliquidHyperliquid (HYPE) $ 39.49
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.247885
  • leo-tokenLEO Token (LEO) $ 9.58
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 8.53
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 324.50
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999170
  • canton-networkCanton (CC) $ 0.148295
  • stellarStellar (XLM) $ 0.166245
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999443
  • daiDai (DAI) $ 0.999837
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 54.01
  • hedera-hashgraphHedera (HBAR) $ 0.089994
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 2.21
  • avalanche-2Avalanche (AVAX) $ 8.80
  • rainRain (RAIN) $ 0.007894
  • wethWETH (WETH) $ 2,268.37
  • zcashZcash (ZEC) $ 218.13
  • suiSui (SUI) $ 0.881681
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 320.10
  • the-open-networkToncoin (TON) $ 1.24
  • crypto-com-chainCronos (CRO) $ 0.071877
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.098069
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,491.25
  • pax-goldPAX Gold (PAXG) $ 4,499.80
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.677380
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • polkadotPolkadot (DOT) $ 1.28
  • uniswapUniswap (UNI) $ 3.38
  • global-dollarGlobal Dollar (USDG) $ 0.999792
  • falcon-financeFalcon USD (USDF) $ 0.998018
  • pi-networkPi Network (PI) $ 0.175412
  • okbOKB (OKB) $ 82.99
  • skySky (SKY) $ 0.070679
  • aster-2Aster (ASTER) $ 0.660319
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.17
  • aaveAave (AAVE) $ 96.98
  • ripple-usdRipple USD (RLUSD) $ 0.999857
  • pepePepe (PEPE) $ 0.000003
  • bitget-tokenBitget Token (BGB) $ 1.94
  • bfusdBFUSD (BFUSD) $ 0.998900
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ondo-financeOndo (ONDO) $ 0.267840
  • ethereum-classicEthereum Classic (ETC) $ 8.13
  • internet-computerInternet Computer (ICP) $ 2.25
  • siren-2Siren (SIREN) $ 1.72
  • gatechain-tokenGate (GT) $ 6.51
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 7.85
  • quant-networkQuant (QNT) $ 71.06
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pump-funPump.fun (PUMP) $ 0.001721
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.091647
  • kaspaKaspa (KAS) $ 0.035309
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • usdtbUSDtb (USDTB) $ 0.998158
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • render-tokenRender (RENDER) $ 1.68
  • nexoNEXO (NEXO) $ 0.868436
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • cosmosCosmos Hub (ATOM) $ 1.68
  • worldcoin-wldWorldcoin (WLD) $ 0.269253
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • midnight-3Midnight (NIGHT) $ 0.050242
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • morphoMorpho (MORPHO) $ 1.51
  • usddUSDD (USDD) $ 0.999091
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.090748
  • aptosAptos (APT) $ 0.949292
  • wbnbWrapped BNB (WBNB) $ 759.61
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.03
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.082105
  • official-trumpOfficial Trump (TRUMP) $ 2.97
  • flare-networksFlare (FLR) $ 0.007714
  • hash-2Provenance Blockchain (HASH) $ 0.011446
  • beldexBeldex (BDX) $ 0.082826
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • filecoinFilecoin (FIL) $ 0.821404
  • ousgOUSG (OUSG) $ 114.73
  • xdce-crowd-saleXDC Network (XDC) $ 0.030620
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • yldsYLDS (YLDS) $ 0.999934
  • ghoGHO (GHO) $ 0.999149
  • vechainVeChain (VET) $ 0.006692
  • usual-usdUsual USD (USD0) $ 0.998224
  • stable-2​​Stable (STABLE) $ 0.025879
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • arbitrumArbitrum (ARB) $ 0.090315
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.234749
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • justJUST (JST) $ 0.060169
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • layerzeroLayerZero (ZRO) $ 2.04
  • jupiter-exchange-solanaJupiter (JUP) $ 0.144132
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • true-usdTrueUSD (TUSD) $ 0.997581
  • a7a5A7A5 (A7A5) $ 0.012221
  • fasttokenFasttoken (FTN) $ 1.09
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.37
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.657543
  • euro-coinEURC (EURC) $ 1.15
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • blockstackStacks (STX) $ 0.223448
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006462
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 31.85
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998635
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • chilizChiliz (CHZ) $ 0.037465
  • tezosTezos (XTZ) $ 0.354812
  • sei-networkSei (SEI) $ 0.054594
  • decredDecred (DCR) $ 21.02
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • ether-fiEther.fi (ETHFI) $ 0.460603
  • hastra-primePRIME (PRIME) $ 1.03
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • usxUSX (USX) $ 0.999375
  • kinesis-goldKinesis Gold (KAU) $ 146.82
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • dexeDeXe (DEXE) $ 7.12
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017111
  • cocaCOCA (COCA) $ 1.30
  • adi-tokenADI (ADI) $ 4.05
  • apenftAINFT (NFT) $ 0.00000033
  • curve-dao-tokenCurve DAO (CRV) $ 0.214257
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • gnosisGnosis (GNO) $ 118.60
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • kite-2Kite (KITE) $ 0.173166
  • bittorrentBitTorrent (BTT) $ 0.00000031
  • usdaiUSDai (USDAI) $ 0.999606
  • aerodrome-financeAerodrome Finance (AERO) $ 0.318385
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • conflux-tokenConflux (CFX) $ 0.056368
  • riverRiver (RIVER) $ 14.79
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 2.86
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • venice-tokenVenice Token (VVV) $ 6.10
  • fraxLegacy Frax Dollar (FRAX) $ 0.990258
  • bitcoin-svBitcoin SV (BSV) $ 13.60
  • kaiaKaia (KAIA) $ 0.046418
  • flokiFLOKI (FLOKI) $ 0.000028
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • celestiaCelestia (TIA) $ 0.298796
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • jasmycoinJasmyCoin (JASMY) $ 0.005327
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • crvusdcrvUSD (CRVUSD) $ 0.994930
  • official-foOfficial FO (FO) $ 0.263223
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kinesis-silverKinesis Silver (KAG) $ 68.71
  • the-graphThe Graph (GRT) $ 0.023871
  • lido-daoLido DAO (LDO) $ 0.303007
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • spx6900SPX6900 (SPX) $ 0.273216
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • doublezeroDoubleZero (2Z) $ 0.070207
  • olympusOlympus (OHM) $ 15.39
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • iotaIOTA (IOTA) $ 0.055178
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • monadMonad (MON) $ 0.021999
  • btse-tokenBTSE Token (BTSE) $ 1.45
  • syrupMaple Finance (SYRUP) $ 0.200214

Solana memo feature exploited to run hidden malware

0 3

Solana memo feature exploited to run hidden malware

Hackers are moving away from normal servers and using decentralized systems to attack developers and steal their crypto funds. They are are replacing traditional command-and-control (C2) servers entirely with decentralized options.

In this attack, the malware abuses the Solana blockchain. It uses the memo field of Solana transactions to run stealth malware that steals crypto wallet data, and even hardware wallet recovery phrases.

The memo field was originally designed for simple transaction notes, but attackers are now using it as a hidden communication layer. This turns a public blockchain feature into a covert channel for malware control.

Decentralized memos like Solana’s are public and permanent and they cannot be taken down by any single party. In addition, attackers can update instructions without changing malware.

The campaign is considered a new version of the GlassWorm malware, which has been active since at least 2022.

Solana memos act as a dead drop resolver

According to security researchers from Aikido, the attack has three stages or three payloads. The first stage/payload is just an entry point. It begins when a developer installs a malicious package from open source repositories like npm, PyPI, GitHub, or the Open VSX marketplaces.

The malware then checks if the system locale is Russian and if so, it does not proceed with the attack. This is because the attackers are likely based in Russia and do not want to get caught by authorities. Once installed, the malware uses the Solana blockchain to fetch the attacker’s command-and-control (C2) server IP address. It looks for a specific transaction on Solana that contains the C2 server’s IP address in the memo field.

The malware then connects to the C2 server and starts the second stage of the attack. In this stage, the malware looks for crypto data like seed phrases, private keys, and even screenshots of wallets. It targets browser extension wallets like MetaMask, Phantom, Coinbase, Exodus, Binance, Ronin, Keplr, and more.

The malware also looks for browser data like login sessions, session tokens, and cloud access. This means it can access centralized exchange accounts, npm, GitHub, and AWS accounts.

After collecting the data, the malware compresses it into a ZIP file, and sends it to the attacker’s server.

Solana memo feature exploited to run hidden malware

Source: Aikido Security.

Hardware wallets targeted via phishing

The last payload splits into two parts. The first part is a .NET binary that looks for hardware wallets like Ledger and Trezor. If it finds one, it shows a fake error message that tricks the user into entering their recovery phrase.

The second part is a WebSocket-based JavaScript RAT (remote access trojan) that steals browser data. It also installs a fake Chrome extension that monitors specific sites like exchanges and steals cookies in real time. It’s downloaded through a Google Calendar event as a dead drop resolver. This approach allows the attacker to hide the real server, bypass security filters and it acts as an indirect delivery layer.

Unlike the second stage, where the malware only steals browser data, this RAT has live control. It stays active and monitors the browser. It captures new cookies, tracks active sessions like logged-in exchange accounts, logs keystrokes, and takes screenshots. Moreover, it allows the attacker to run commands on the victim’s machine.

Its difficult to remove GlassWorm. The malware can re-download itself and it can survive reboots. It also uses fallback methods like DHT (Distributed Hash Table) lookups and Solana memos to find the control server.

Since there’s no central server, and the data is shared across many computers, it becomes difficult for defenders to block the attack at the network level.

This attack is very dangerous. It highly severe because it combines crypto theft, full system control, and unremovable network.

Source

Leave A Reply

Your email address will not be published.