Fake Crypto Apps Spread Node.js Malware in New Attack Campaign
Microsoft has uncovered a malware campaign that uses fake cryptocurrency apps to spread malicious software. Since October 2024, attackers have been tricking users into downloading what looks like Binance or TradingView installers. These fake apps use Node.js and PowerShell to steal system data and send it to hackers.
The malware avoids detection by disabling Defender scans, stealing sensitive data like browser info, and staying active through scheduled tasks. Some versions use a method called “ClickFix” to hide malicious activity and keep the malware running on startup.
Hackers are also using fake PDF converter websites and HR-themed phishing attacks to install info-stealing malware and hijack payroll accounts. A group known as “Payroll Pirates” is linked to some of these scams.
Mitigation Tips:
- Download software only from official websites. Avoid clicking on ads or unfamiliar links.
- Use application control tools to block unauthorized PowerShell and Node.js activity.
- Monitor scheduled tasks and registry changes for suspicious entries.
- Be wary of phishing attempts, especially those that appear to come from HR or payroll.
- Use multi-factor authentication (MFA) and never share codes with unknown sources.
- Regularly audit network traffic for unusual activity disguised as normal services.
Source: https://thehackernews.com/2025/04/nodejs-malware-campaign-targets-crypto.html