Summary:[/subscribe_to_unlock_form]
Summary:[emaillocker id="1283"]
A wave of trojanized Tor Browser installers is targeting Russians and Eastern Europeans with clipboard-hijacking malware that steals cryptocurrency transfers from infected users. They have also been seen attacking the United States, Germany, China, France, the Netherlands, and the United Kingdom. According to researchers, Russia had the second highest amount of Tor users.
Russian-speaking users receive trojanized Tor Browser bundles that malware authors have distributed. Tor Browser was provided a regional language pack by trojanized installers. Tor Browser is downloaded by the intended user from a third-party source, and it is launched as torbrowser.exe. It includes the original torbrowser.exe installer, a password-protected RAR archive, and a command-line RAR extraction tool with a random username.

Execution Flow
The SFX launches the genuine torbrowser.exe secretly while also launching the RAR extraction program on the password protected RAR archive that is encoded. It is password-protected to avoid security programs' static-signature detection. The trojanized torbrowser.exe executable contains the password and the extraction location, which can be retrieved through manual analysis. When an executable file is placed into one of the current user's AppData subdirectories, it launches as a new process and registers with the system AutoStart. Most of the time, the executable appears as the icon of a popular program, such as uTorrent. It is more difficult to analyze the malware because it is secured by the Enigma packer v4.0.
This installer's payload is malicious clipboard-injector malware that is inactive and uncommunicative. Using regular expressions, the malware scans the clipboard for recognized crypto wallet addresses, and when one is found, it replaces it with a related cryptocurrency address controlled by the threat actors. Each malware copy contains thousands of addresses chosen at random from a hardcoded list by the threat actor. This makes wallet monitoring, reporting, and banning difficult.
To prevent clipboard-based attacks, cryptocurrency users should be cautious to double-check the wallet address they are transferring money to and think about using alternative methods, such as QR codes.
Threat Profile:
| Tactic | Technique Id | Technique |
| Execution | T1204 | User Execution |
| Defense Evasion | T1055 | Process Injection |
| T1036 | Masquerading | |
| Credential Access | T1110 | Brute Force |
| Collection | T1056 | Input Capture |
| T1115 | Clipboard Data | |
| Command and Control | T1132 | Data Encoding |
| T1071 | Application Layer Protocol | |
| T1105 | Ingress Tool Transfer | |
| T1090 | Proxy | |
| Exfiltration | T1041 | Exfiltration Over Command and Control Channel |
| T1132 | Data Encoding | |
| Impact | T1496 | Resource Hijacking |
References:
The following reports contain further technical details:
[/emaillocker]