You are welcome to discuss various security topics with our professional team and other users like you!
Read our Registration Agreement and create your FREE account here!

*

never

  • *****
  • 122
  • +26/-0
  • Network Administrator and Malware Researcher
      • View Profile
A new type of financial data stealing Trojan known as Coinbitclip has been reported to massively affect users, creating multiple files in the following locations:

%AppData%\Blizzard\Hearthstone.exe
%User’s Profile%\Application Data\hearthstone\updater.exe


I may also create registry entries to run the .exe files every time you start Windows in the following key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\

The trojan is believe to take advantage of users, playing the famous game Hearthstone by Blizzard to infect them. It may be distributed either via malicious web links or email attachments. Once activated, the trojan stars monitoring for any bitcoin addresses the affected user has copied to his/hers clipboard after which replaces the copied address with a foreign one. The threat has a database of addresses and it uses the closest one to the victim's address to make itself unnoticable. The Trojan may also use file obfuscation techniques to conceal its data.



This is an open topic discussion, regarding the Coinbitclip Trojan. You may share your experience, ask questions, ask for help in case you have been affected by the Trojan and we will attempt to assist you anyway we can.
« Last Edit: February 04, 2016, 04:08:54 pm by never »