Wallet Guard Profile picture
Jul 26 10 tweets 4 min read
1/ ⚠️ New Open-Source Malware⚠️
🎯 Targeting Web3 🧵
Code Named: Luca Stealer 🥷

🔍 High Level:
- Primarily an info stealer
- Targets cold/hot wallets
- Steals discord tokens
- Steals from over 17 different extensions 👇
2/ Why should you care?

“The malware, which the author claims to have developed in just six hours, is quite stealthy, with VirusTotal returning a detection rate of around 22%.” - Bleeping Computer

The entire code-base for this malware was released for free. 👇
3/ What makes this malware interesting?

🔍 Uses Discord web-hooks OR Telegram bots to communicate back to attacker
🔍 Written in Rust which allows for easy porting to macOS or Linux
🔍 Can modify clipboard to attempt to steal crypto by replacing the copied address with theirs.
4/ Why should Web3 Care?

🔲 This malware targets your hot/cold wallets.
🔲 Could replace copied addresses on clipboard
🔲 Easy to impact Windows, macOS and Linux
🔲 Low Detection Rate
5/ What can I do to protect myself?

🔲 Download @Malwarebytes and get premium
🔲 Never download random files
🔲 Always open documents via Google Docs or something similar
🔲 Check the copied address every-time before sending any transactions.
7/ If you liked this thread, please consider giving us a follow & sharing the thread 🙂

Website: walletguard.app
Discord: discord.gg/wQQZgjxxPR
8/ Twitter Spaces:

🎙Web3 Security Radio: Episode 9🎙

📝 Topics:
- Luca Stealer
- Malware/Threats in Web3
- Virtual Machines
- Requests topics in our discord! 🙂

If you’d like to be a panelist send a DM🎙
#spaceshost
twitter.com/i/spaces/1DXxy…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Wallet Guard

Wallet Guard Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @wallet_guard

Jun 1
🚨 CRITICAL ALERT

A severe 0-day vulnerability called #Follina has been exposed (since May 27th) in MS Word Documents.

It could allow hackers to take full control of your computer, in some cases WITHOUT even opening the file. 🧵
1/ This exploit is a mountain of exploits stacked on top of eachother. However, it is unfortunately easy to re-create and cannot be detected by anti-virus. Strap in as we try to explain.
2/ The 0-day starts with a feature in MS Word called Templates.

This feature allows Word to load and execute HTML and JS from external sources.

Sound concerning? Don’t worry it gets way worse.
Read 19 tweets
Mar 25
A brief intro to wallet security (from beginner to advanced)

(1/19) 🧵
2) Let’s start with the basics. Your private key is for you and you only.

Many scammers will host fake giveaways, phishing sites, malicious code and more to try and steal this from you.

(2/19)
Practicing perfect security practices all the time is difficult. Even just doing half of these habits consistently will improve your wallet security 10x. 👇

(3/19)
Read 20 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(