In recent years, cryptocurrency has become a trend, and its almost crazy rise has attracted many people to join the ranks of mining, investment and trading even if they don’t know much about it. Since it is a profitable field, there will naturally be malicious people who are eyeing it and deliberately trying to obtain ill-gotten gains. Recently, Check Point discovered that a botnet variant “Twizt” successfully stole nearly $500,000 worth of cryptocurrency through a Crypto Clipping attack method.

Cryptocurrency-stealing botnet variant Twizt, victims have reached $500,000
Check Point Research, the threat intelligence department of Check Point, recently discovered the mutant virus “Twizt”. This virus mutates from the botnet virus “Phorpiex”. It automatically replaces the original wallet address with the attacker’s wallet address and steals cryptocurrency during the transaction without connecting to the C&C server. It can bypass security mechanisms.

“Phorpiex” is a botnet well-known for ransomware and crypto-jacking, and its new variant “Twizt” can operate without connecting to the C&C server, which means that every infected computer can expand into a botnet. Check Point Research believes that the new features of this botnet will make it more stable and more dangerous. Twizt uses Crypto Clipping technology, using malware that automatically replaces the target wallet address with the attacker’s wallet address to steal cryptocurrency during the transaction, allowing the funds to fall into the wrong hands.

In the year from November 2020 to November 2021, Phorpiex hijacked a total of 969 transactions and stole 3.64 Bitcoin, 55.87 Ethereum, and ERC-20 tokens worth $55,000. Based on the current market value, the value of the stolen assets is nearly $500,000. Phorpiex has also successfully hijacked huge transactions on multiple occasions, the largest of which was 26 Ether.

In order to prevent users from being attacked by the botnet variant Twizt virus, Check Point Software puts forward five suggestions. Everyone can be more vigilant and protect their property security:
- Check wallet address
When traders copy and paste the crypto wallet address, be sure to carefully check whether the originally copied address matches the one after pasting. - test transaction
Before sending large amounts of cryptocurrency, send a minimum amount as a “test” transaction. - Maintain the latest version
Make sure your operating system is up to date and never download software from unverified sources. - Don’t be fooled by advertisements
If you are looking for a crypto wallet or cryptocurrency trading/exchange platform, be sure to choose the first website in the search results rather than the website recommended by the advertisement; because the website recommended by the advertisement is more likely to mislead traders, Check Point Research has discovered that scammers are using Google ads to steal crypto wallets. - Check URL
Be sure to double check the URL.
Source: KOCPC Chinese