Styx Stealer, a brand new malware, stealthily swipes cryptocurrency from Home windows-based computer systems.
Cybersecurity agency Verify Level Analysis first recognized Styx as a beefier model of Phemodrone Stealer in April. The malware exploited a now-patched Home windows vulnerability, hijacking cryptocurrency transactions and stealing delicate knowledge from compromised techniques, similar to personal keys, browser cookies, and even autofill browser knowledge.
Phemodrone first made waves in early 2024. Not like Styx Stealer, it targeted on net browsers to empty crypto from wallets alongside different info.
Each malware exploit the identical loophole in Home windows Defender, the working system’s native antivirus, benefiting from an outdated vulnerability within the antivirus’s SmartScreen function designed to warn customers about probably dangerous web sites and downloads.
Nevertheless, Styx presents new threats with the addition of the crypto-clipping mechanism. Principally, the malware displays the clipboard for adjustments after which replaces copied cryptocurrency pockets addresses with these belonging to the attacker.
Beforehand, the Phorpiex botnet was identified to make use of this system to hijack crypto transactions.
In accordance with Verify Level Analysis’s findings, Styx can determine pockets addresses throughout 9 blockchains, together with Bitcoin (BTC), Ethereum (ETH), Monero (XMR), Ripple (XRP), Litecoin (LTC), Bitcoin Money (BCH), Stellar (XLM), Sprint (DASH) and Neo (NEO).
Chromium- and Gecko-based browsers, knowledge from browser extensions, Telegram and Discord are particularly susceptible.
The malware’s builder has an autorun function and a user-friendly graphical interface, making it simpler for cybercriminals to customise and deploy it.
Styx can be outfitted with fundamental anti-analysis methods to masks its operations. To evade detection, it terminates processes related to debugging instruments and detects digital machine environments. If such an surroundings is detected, Styx Stealer initiates self-deletion.
Accessible by way of Telegram
The malware’s distribution and gross sales are managed manually by means of the Telegram account @styxencode and the styxcrypter[.]com web site. CPR has additionally found commercials and YouTube movies that promote the malicious software program.
A minimum of 54 people had despatched the Styx developer roughly $9,500 in funds utilizing varied cryptocurrencies like Bitcoin and Litecoin. Not like its successor, which was free, this malware is offered with a month-to-month license for $75, $230 for 3 months, and $350 for lifetime entry.
The quantity of crypto funds stolen or the size of the techniques contaminated utilizing Styx stays unclear.
Crypto-stealing malware has additionally been discovered on Apple’s MacOS, as reported by antivirus developer Kaspersky earlier this yr. The malware focused Bitcoin and Exodus wallets by changing the precise software program with an altered model.
Hacks and thefts have develop into fairly worthwhile because the crypto sector expands, with tens of millions of {dollars} price of funds misplaced yearly. However, some notorious menace actors have determined to name it quits.
Final month, Angel Drainer, a drainer-as-a-service malware accountable for over $25 million in thefts, shut down operations. In November, multi-chain crypto rip-off service Inferno Drainer halted companies.

