Kaspersky uncovers malware on SourceForge targeting crypto users with address swaps

Source Cryptopolitan

Security firm Kaspersky has warned about new malware targeting crypto users through the software-hosting website SourceForge. In a recent publication, the firm said the software project on the website, Office Package, contains an address-poisoning malware targeting crypto users.

According to the report, the Office package software is a legitimate project containing Microsoft Office add-ins. However, a closer investigation reveals more about the package, as it contains download links that lead to a different URL.

It said:

“The project under investigation has been assigned the domain officepackage.sourceforge[.]io, but the page displayed when you go to that domain looks nothing like officepackage on sourceforge.net.”

Interestingly, the malware download process is quite complex, with users going through three URLs before they can download the file. The complex process appears to be part of the scheme to lure users into believing they are downloading a genuine application.

Kaspersky security experts noted the final installation file is installer.msi, a 700-megabyte file that bad actors inflated size to make it look like an authentic software installer. After stripping away the junk bytes, the real size is seven megabytes.

Infection chain for the malware (Kaspersky)

By running the installer, users unwittingly install two malicious applications into their devices, a miner and a ClipBanker. The ClipBanker allows address poisoning by replacing crypto addresses copied onto the clipboard with those of the attacker, leading users to send funds to the wrong addresses.

The security experts wrote:

“The key malicious actions in this campaign boil down to running two AutoIt scripts. Icon.dll restarts the AutoIt interpreter and injects a miner into it, while Kape.dll does the same but injects ClipBanker.”

Meanwhile, they also noted that the attack focused mostly on Russian targets. Signs of this include the Russian interface for the officepackage.sourceforge[.]io site and the fact that 90% of the 4,604 users encountered the malware between January and late March are Russian.

Address poisoning scams increasing

The Kaspersky report corresponds with the recent rise in address poisoning attacks on crypto users, as reported by several blockchain security firms. According to data from Scam Sniffer, the third-biggest phishing incident in March was due to address poisoning.

Cyvers also reported that address poisoning scams caused a loss of more than $1.2 million within the first three weeks of March, adding to the $1.8 million in February. The firm said its AI threat detection system identified an increase in address poisoning attacks.

While most address poisoning attacks result from attackers manually sending small transactions to the victims with addresses similar to the ones they frequently use, the use of sophisticated malware that allows attackers to change addresses from the clipboard shows how bad actors continue to evolve.

Security experts believe the number one solution to this problem is for users to avoid downloading software from untrusted sources. They noted that bad actors usually exploit unofficial software websites to distribute malicious applications, and people using such websites must be aware of that risk.

However, they noted that this malware presents an even bigger problem as provides an inventive way for attackers to gain access to infected systems. Thus, there is a possibility that the creators can decide to use it for more than targeting crypto users and start selling it to more dangerous bad actors.

Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
US Dollar's Decline Predicted in 2026: Morgan Stanley's Outlook on Currency VolatilityMorgan Stanley forecasts a 5% drop in the dollar by mid-2026, attributed to continued Fed rate cuts. A recovery may follow as growth improves and funding currency dynamics shift favorably toward the euro and Swiss franc.
Author  Mitrade
Nov 25, Tue
Morgan Stanley forecasts a 5% drop in the dollar by mid-2026, attributed to continued Fed rate cuts. A recovery may follow as growth improves and funding currency dynamics shift favorably toward the euro and Swiss franc.
placeholder
Gold's Historic 2025 Rally: Can the Momentum Last Through 2026?Following a historic surge in 2025 that saw prices climb over 60% and break records more than 50 times, gold investors are now looking ahead to assess whether the precious metal can sustain its momentum into 2026. Despite outperforming most major asset classes and heading for its best annual performance since 1979, analysts are divided on the outlook—with some seeing further room for gains and others cautioning that risks are rising.
Author  Mitrade
Dec 09, Tue
Following a historic surge in 2025 that saw prices climb over 60% and break records more than 50 times, gold investors are now looking ahead to assess whether the precious metal can sustain its momentum into 2026. Despite outperforming most major asset classes and heading for its best annual performance since 1979, analysts are divided on the outlook—with some seeing further room for gains and others cautioning that risks are rising.
placeholder
Oracle's Weak Earnings Prompt Concerns Over AI Spending, Pressuring Nvidia and Industry RivalsOracle's disappointing earnings and soaring expenses have raised fears about AI spending sustainability, causing Nvidia and other related stocks to decline amidst heightened competition and concerns over mounting debt.
Author  Mitrade
Dec 11, Thu
Oracle's disappointing earnings and soaring expenses have raised fears about AI spending sustainability, causing Nvidia and other related stocks to decline amidst heightened competition and concerns over mounting debt.
placeholder
XRP Spot ETFs Notch 30 Straight Days of Inflows, Bucking Wider Crypto TrendSince their debut on November 13, U.S.-listed spot exchange-traded funds (ETFs) for XRP have recorded net inflows for 30 consecutive trading days, a steady performance that stands in contrast to the more volatile flows seen in larger bitcoin and ether funds.
Author  Mitrade
Dec 15, Mon
Since their debut on November 13, U.S.-listed spot exchange-traded funds (ETFs) for XRP have recorded net inflows for 30 consecutive trading days, a steady performance that stands in contrast to the more volatile flows seen in larger bitcoin and ether funds.
placeholder
BOJ Set to Hike Rates Amid Inflation Pressures and Yen Weakness The Bank of Japan is expected to raise its benchmark interest rate to 0.75% on December 19, marking its first increase since early 2025, amidst ongoing inflation and a weakening yen. Analysts predict additional hikes in 2026 as the central bank navigates renewed monetary policy normalization under Governor Kazuo Ueda.
Author  Mitrade
Dec 18, Thu
The Bank of Japan is expected to raise its benchmark interest rate to 0.75% on December 19, marking its first increase since early 2025, amidst ongoing inflation and a weakening yen. Analysts predict additional hikes in 2026 as the central bank navigates renewed monetary policy normalization under Governor Kazuo Ueda.
goTop
quote