Cisco Talos has discovered two malicious files, MortalKombat ransomware and Laplas Clipper malware, that have been actively targeting crypto investors since December 2022. The campaign has mostly affected victims in the United States, with smaller percentages in the UK, Turkey, and the Philippines. The malware work together to replace wallet addresses with different ones, relying on users’ inattention to send cryptocurrencies to the attackers. MortalKombat ransomware encrypts the victim’s files and drops a ransom note with payment instructions. Talos’ report has revealed the download links associated with the attack campaign, with one reaching an attacker-controlled server in Poland. The malware is spread through a cryptocurrency-themed email containing a malicious attachment that runs a B
Leave a Reply