Shares 110 Views

How to Defend Against Keyloggers That Are after Your Bitcoins

Threat to Bitcoin Wallets

Bitcoin.com (BC): How often are computers infected with keylogger malware that can steal bitcoin wallets?

Cyren (C): Malware that steals cryptocurrency wallets has been around since 2012. In 2013 there was a massive spike in this type of malware and it’s hard to say how many infections there have been, but:

We estimate that there are hundreds different types of cryptocurrency malware out there.

They are all after the same thing – the wallet, crypto addresses (Bitcoin address) and the password that protects the wallet. But the difference is how they do it and on what platform.

Common Ways to Get Infected

BC: How many different ways are there to get infected?

C: There are several ways to get infected.

The most common one would be from an email with attachment. The attachment can be in many different forms, for example an office document, pdf, JavaScript, or just an executable. Usually the email is a fake invoice from banks or delivery companies or something similar.

We then have the classic USB stick delivery method where the malware author drops USB sticks with the malware across the city or near an office building that he is targeting. When a victim picks it up to check what’s on the drive he gets infected by an auto run script on the USB stick.

Drive-by-downloads are also popular where the victim may accidentally visit a malicious web page that automatically downloads the malware. Malicious links or attachments via social media are also very popular these days.

Mobile Operating System

BC: Is the mobile operating system safer than a desktop PC?

C: The mobile operating system should be safer if the user sticks to the Google play store/iOS app store and is not installing apps from unknown sources.

There was a malware on android that exploited a bug in the android system to steal information from bitcoin wallets in 2013, but that has been fixed since then.

The most common mobile malware regarding cryptocurrency was to have a legitimate looking app, for example a flashlight app that was mining cryptocurrency in the background without the user knowing.

Android and iOS are pretty strict on the keylogging so it’s easier to exploit the desktop PC.

How to Check for Keyloggers

BC: How can we check if we are being keylogged?

C: For Windows users: Check which processes are running, using, for example, Task Manager, and look for something out of the ordinary.

Examining the outgoing network traffic from the PC is also effective. Look for strange outgoing connections.

Preventing Infection

BC: How do we prevent being infected with keylogger malware?

C: Obviously do not open strange attachments or click links from emails that you are unsure about. Always check who’s the sender by checking the email address, and if you are not expecting this document or attachment to be sent to you, then make sure you have someone with the proper knowledge to check it before exploring it further. Evidently, relying on users to police their email is a strategy which will have at best limited success.

Standard advice is also always to have anti-virus software on your PC which is up to date, but it’s known that traditional antivirus software recognizes less than half of malware attacks.  

Moreover, there can be quite a bit of latency from the time an endpoint anti-virus provider detects something to the time any black list is updated. So relying on user behavior and local anti-virus software is problematic. A better strategy is to use a first-rate secure email gateway which will detect and block delivery of the attachment in the first place. Also use a secure web gateway for internet traffic which inspects outbound connections, preventing the transmission of the data captured, even if infection happens. Make sure to install the latest operating system updates.

Removing Keyloggers

BC: What is the best way to get rid of keylogger malware?

C: First of all, scan the computer with an Anti-virus program that is up to date and see if it is able to remove the keylogger.

Open the task manager or activity monitor, depending on the operating system, and make sure every process that is running is safe and not malicious. If you find a process that is a keylogger, then make sure you remove it from the folder it starts up in, the registry, and any other places that it might be in. Search for the process name on the internet and if it’s a common one you will be able to find instructions on how to remove is.

After removing the keylogger it is good to reboot the system and monitor the process to see that it is not starting up and that it has been completely removed from the system.

Have any of your devices have been infected by keylogger malware? Let us know in the comments section below.


Images courtesy of Shutterstock, Cyren, Android, Apple, and Microsoft

Source: https://news.bitcoin.com/defend-keyloggers-bitcoins/

You may be interested

Buy Bitcoins in Europe With Bitmoney.eu
bitmoney.eu
shares319 views
bitmoney.eu
shares319 views

Buy Bitcoins in Europe With Bitmoney.eu

Brian Evans - Aug 10, 2017

Want to purchase bitcoins? Look no further! Buying bitcoins has never been easier, with Bitmoney.eu. Bitmoney.eu makes the process of buying Bitcoin easy and efficient, saving customers…

Goldman Sachs: ‘Real Dollars Are at Work’ in Cryptocurrency Markets
Bitcoin
shares398 views1
Bitcoin
shares398 views1

Goldman Sachs: ‘Real Dollars Are at Work’ in Cryptocurrency Markets

Brian Evans - Aug 10, 2017

Goldman Sachs has published a question-and-answer report focused on cryptocurrencies in which it suggests that clients should be keeping a closer eye on the market. According to…

Bitcoin’s Present Bubble Might Actually be the Beginning of Mainstream Adoption
Bitcoin
shares399 views
Bitcoin
shares399 views

Bitcoin’s Present Bubble Might Actually be the Beginning of Mainstream Adoption

Brian Evans - Aug 09, 2017

Bitcoin’s enthusiasts are torn between whether to celebrate Bitcoin’s arrival in the foothills of mass adoption, or to lament the upcoming burst that always happens with asset…

Most from this category

%d bloggers like this: