Close Menu
    What's Hot

    US Ethereum ETFs Record 4 Consecutive Weeks Of Positive Inflows — Details

    Here’s why Sonic erased $1.3 billion in value

    Whales lose SYRUP sweet tooth despite Maple Finance’s growth

    Facebook X (Twitter) Instagram
    yeek.io
    • Crypto Chart
    • Crypto Price Chart
    X (Twitter) Instagram TikTok
    Trending Topics:
    • Altcoin
    • Bitcoin
    • Blockchain
    • Crypto News
    • DeFi
    • Ethereum
    • Meme Coins
    • NFTs
    • Web 3
    yeek.io
    • Altcoin
    • Bitcoin
    • Blockchain
    • Crypto News
    • DeFi
    • Ethereum
    • Meme Coins
    • NFTs
    • Web 3
    Blockchain

    Kaspersky Flags Crypto-Stealing Malware Hidden in Fake Microsoft Office Add-Ins

    Yeek.ioBy Yeek.ioApril 9, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity firm Kaspersky has flagged a new sophisticated malware that steals crypto using fake Microsoft Office add-ins. These legit-looking extensions are uploaded to SourceForge, a website hosting platform, with descriptions copied from the legitimate GitHub project.

    Per the malware description posted on Tuesday, appears with the SourceForge domain name and web hosting. “Pages like that are well-indexed by search engines and appear in their search results,” Kaspersky cybersecurity experts wrote.

    Dubbed “officepackage,” the extension displays a list of office applications complete with version numbers and “Download” buttons.

    Fake Downloads are Smaller in Size, Raises “Red Flags”

    Kaspersky noted that the downloads are roughly seven-megabyte in size. “This raises some red flags, as office applications are never that small, even when compressed.”

    The download pages takes victims to another page with a download button, containing a password-protected archive. However, the zip file after downloading the software exceeds 700 megabytes.

    Attackers use the pumping technique to inflate the file size to look legit by appending junk data, Kaspersky flagged.

    “As users seek ways to download applications outside official sources, attackers offer their own,” the report said. “They keep looking for new ways to make their websites look legit.”

    Cybersecurity firm @Kaspersky has issued a warning about a widespread malware campaign targeting users on @GitHub. #Kaspersky #GitHubhttps://t.co/TJg8BmgHiV

    — Cryptonews.com (@cryptonews) February 26, 2025

    Kaspersky Finds ‘ClipBanker’ Malware

    The firm highlighted that the campaign injects the ClipBanker trojan through SourceForge. “ClipBanker is a malware family that replaces cryptocurrency wallet addresses in the clipboard with the attackers’ own,” it explained.

    Crypto wallet users usually copy addresses rather than typing them. With the ClipBanker malware, the victim’s money will end up somewhere entirely unexpected.

    Further, attackers could also sell system access to more dangerous actors apart from stealing cryptos.

    “We advise users against downloading software from untrusted sources. If you are unable to obtain some software from official sources for any reason, remember that seeking alternative download options always carries higher security risks,” Kaspersky warned.

    The post Kaspersky Flags Crypto-Stealing Malware Hidden in Fake Microsoft Office Add-Ins appeared first on Cryptonews.

    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleCourt approves $11m settlement in Shaquille O’Neal’s Astrals NFT lawsuit
    Next Article Ethereum Precipitously Fell to the Lowest of 2024-2025
    Avatar
    Yeek.io
    • Website

    Yeek.io is your trusted source for the latest cryptocurrency news, market updates, and blockchain insights. Stay informed with real-time updates, expert analysis, and comprehensive guides to navigate the dynamic world of crypto.

    Related Posts

    Samourai Wallet Dismissal Bid Gains Steam After DOJ Policy Pivot, 16-Day Delay

    April 29, 2025

    The crypto grift call is coming from inside the (White) house

    April 29, 2025

    Bunq, Europe’s second-largest neobank, expands into crypto

    April 29, 2025
    Leave A Reply Cancel Reply

    Advertisement
    Demo
    Latest Posts

    US Ethereum ETFs Record 4 Consecutive Weeks Of Positive Inflows — Details

    Here’s why Sonic erased $1.3 billion in value

    Whales lose SYRUP sweet tooth despite Maple Finance’s growth

    Ethereum Prepares For A Parabolic Move – ETH/BTC Chart Signals Strong Bullish Setup

    Popular Posts
    Advertisement
    Demo
    X (Twitter) TikTok Instagram

    Categories

    • Altcoin
    • Bitcoin
    • Blockchain
    • Crypto News

    Categories

    • Defi
    • Ethereum
    • Meme Coins
    • Nfts

    Quick Links

    • Home
    • About
    • Contact
    • Privacy Policy

    Important Links

    • Crypto Chart
    • Crypto Price Chart
    © 2025 Yeek. All Copyright Reserved

    Type above and press Enter to search. Press Esc to cancel.