BPOI Banner
Fake Ross Ulbricht Accounts Used in New Malware Campaign Fake Ross Ulbricht Accounts Used in New Malware Campaign

Fake Ross Ulbricht Accounts Used in New Malware Campaign

Ross Ulbricht, the controversial creator of the Silk Road, has long been at the heart of debates about the intersection of technology and criminal activity. Following a full pardon from US President Donald Trump, a new wave of cybercrime has emerged, leveraging news of Ulbricht’s case to deliver malware to unsuspecting targets.

Exploiting the news surrounding him, threat actors on X are redirecting users to a Telegram channel where they are duped into running PowerShell scripts that infect their devices with malware.

Ross Ulbricht Malware Campaign

According to vx-underground researchers’ latest update, the attack uses a new variation of the popular “Click-Fix” tactic, but with a twist. Rather than disguising itself as a common error fix, this version pretends to be a captcha or verification process required to join the channel.

In this case, cybercriminals are impersonating Ulbricht using fake but verified accounts on X to lure users to Telegram channels falsely claimed to be official. Once on Telegram, users encounter a fraudulent “Safeguard” identity verification process, which leads them to a mini app that generates a fake verification dialog and automatically copies a PowerShell command to their clipboard.

Users are then instructed to run the command via the Windows Run dialog. As such, executing the command triggers a chain of events. Initially, it downloads a PowerShell script, which retrieves a ZIP file from http://openline[.]cyou. The ZIP file contains several files, including identity-helper.exe, suspected to be a Cobalt Strike loader – a tool frequently used by attackers for remote access and launching ransomware or data theft campaigns.

The entire process is carefully worded to avoid detection.

Ross Ulbricht Released

This development comes after Ulbricht was pardoned and released this week after being imprisoned since 2013 for founding and operating the infamous dark web marketplace Silk Road.

Silk Road was an online marketplace on the Tor network that allowed people to trade illegal items, such as narcotics. Ulbricht operated the site using the pseudonym “Dread Pirate Roberts.” The FBI arrested him in October 2013 and took the site offline.

In 2015, Ulbricht was found guilty of charges including drug distribution and money laundering. He received a life sentence without parole, and his appeals in 2017 and 2018 were denied.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Chayanika Deka

https://cryptopotato.com/fake-ross-ulbricht-accounts-used-in-new-malware-campaign/

2025-01-25 16:52:15

bitcoin
Bitcoin (BTC) $ 82,383.07 0.29%
ethereum
Ethereum (ETH) $ 1,805.99 1.22%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.14 0.06%
bnb
BNB (BNB) $ 601.76 0.29%
solana
Solana (SOL) $ 124.67 0.15%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.166501 1.72%
cardano
Cardano (ADA) $ 0.660386 1.93%
tron
TRON (TRX) $ 0.231437 0.35%
staked-ether
Lido Staked Ether (STETH) $ 1,804.25 1.31%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 82,128.00 0.46%
the-open-network
Toncoin (TON) $ 3.90 5.44%
chainlink
Chainlink (LINK) $ 13.39 1.14%
leo-token
LEO Token (LEO) $ 9.11 5.20%
stellar
Stellar (XLM) $ 0.266792 0.25%
avalanche-2
Avalanche (AVAX) $ 18.87 3.93%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,160.21 1.12%
usds
USDS (USDS) $ 1.00 0.01%
sui
Sui (SUI) $ 2.35 1.52%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 1.88%
hedera-hashgraph
Hedera (HBAR) $ 0.167806 2.43%
litecoin
Litecoin (LTC) $ 86.01 0.63%
mantra-dao
MANTRA (OM) $ 6.25 0.87%
polkadot
Polkadot (DOT) $ 4.04 0.28%
bitcoin-cash
Bitcoin Cash (BCH) $ 299.00 1.35%
bitget-token
Bitget Token (BGB) $ 4.59 0.89%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.02%
pi-network
Pi Network (PI) $ 0.774972 3.71%
weth
WETH (WETH) $ 1,805.69 1.26%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.09%
hyperliquid
Hyperliquid (HYPE) $ 12.45 2.73%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,917.12 1.34%
whitebit
WhiteBIT Coin (WBT) $ 28.25 0.24%
monero
Monero (XMR) $ 218.15 1.33%
uniswap
Uniswap (UNI) $ 5.87 1.54%
dai
Dai (DAI) $ 0.999679 0.04%
aptos
Aptos (APT) $ 5.29 1.29%
near
NEAR Protocol (NEAR) $ 2.59 0.97%
susds
sUSDS (SUSDS) $ 1.05 0.10%
pepe
Pepe (PEPE) $ 0.000007 3.88%
okb
OKB (OKB) $ 48.36 0.18%
crypto-com-chain
Cronos (CRO) $ 0.101899 0.94%
gatechain-token
Gate (GT) $ 22.29 0.32%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 82,301.05 0.40%
mantle
Mantle (MNT) $ 0.793269 1.64%
first-digital-usd
First Digital USD (FDUSD) $ 0.999266 0.03%
internet-computer
Internet Computer (ICP) $ 5.27 1.47%
ethereum-classic
Ethereum Classic (ETC) $ 16.48 0.70%
ondo-finance
Ondo (ONDO) $ 0.790118 1.45%
bitcoin
Bitcoin (BTC) $ 82,383.07 0.29%
ethereum
Ethereum (ETH) $ 1,805.99 1.22%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.14 0.06%
bnb
BNB (BNB) $ 601.76 0.29%
solana
Solana (SOL) $ 124.67 0.15%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.166501 1.72%
cardano
Cardano (ADA) $ 0.660386 1.93%
tron
TRON (TRX) $ 0.231437 0.35%
staked-ether
Lido Staked Ether (STETH) $ 1,804.25 1.31%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 82,128.00 0.46%
the-open-network
Toncoin (TON) $ 3.90 5.44%
chainlink
Chainlink (LINK) $ 13.39 1.14%
leo-token
LEO Token (LEO) $ 9.11 5.20%
stellar
Stellar (XLM) $ 0.266792 0.25%
avalanche-2
Avalanche (AVAX) $ 18.87 3.93%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,160.21 1.12%
usds
USDS (USDS) $ 1.00 0.01%
sui
Sui (SUI) $ 2.35 1.52%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 1.88%
hedera-hashgraph
Hedera (HBAR) $ 0.167806 2.43%
litecoin
Litecoin (LTC) $ 86.01 0.63%
mantra-dao
MANTRA (OM) $ 6.25 0.87%
polkadot
Polkadot (DOT) $ 4.04 0.28%
bitcoin-cash
Bitcoin Cash (BCH) $ 299.00 1.35%
bitget-token
Bitget Token (BGB) $ 4.59 0.89%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.02%
pi-network
Pi Network (PI) $ 0.774972 3.71%
weth
WETH (WETH) $ 1,805.69 1.26%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.09%
hyperliquid
Hyperliquid (HYPE) $ 12.45 2.73%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,917.12 1.34%
whitebit
WhiteBIT Coin (WBT) $ 28.25 0.24%
monero
Monero (XMR) $ 218.15 1.33%
uniswap
Uniswap (UNI) $ 5.87 1.54%
dai
Dai (DAI) $ 0.999679 0.04%
aptos
Aptos (APT) $ 5.29 1.29%
near
NEAR Protocol (NEAR) $ 2.59 0.97%
susds
sUSDS (SUSDS) $ 1.05 0.10%
pepe
Pepe (PEPE) $ 0.000007 3.88%
okb
OKB (OKB) $ 48.36 0.18%
crypto-com-chain
Cronos (CRO) $ 0.101899 0.94%
gatechain-token
Gate (GT) $ 22.29 0.32%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 82,301.05 0.40%
mantle
Mantle (MNT) $ 0.793269 1.64%
first-digital-usd
First Digital USD (FDUSD) $ 0.999266 0.03%
internet-computer
Internet Computer (ICP) $ 5.27 1.47%
ethereum-classic
Ethereum Classic (ETC) $ 16.48 0.70%
ondo-finance
Ondo (ONDO) $ 0.790118 1.45%