Menu
Bitcoin market price app, 'Bitcoin Alarm,' is carefully cloaked malware

Bitcoin market price app, 'Bitcoin Alarm,' is carefully cloaked malware

The application contains a remote access Trojan, Arbor Networks said

Bitcoin Alarm, an application that sends bitcoin market price alerts, contains suspicious functions that may be used to steal the virtual currency, according to Arbor Networks.

Bitcoin Alarm, an application that sends bitcoin market price alerts, contains suspicious functions that may be used to steal the virtual currency, according to Arbor Networks.

If you get a spam message advertising an application called "Bitcoin Alarm," the name may tell you all you need to know.

The desktop Windows application sends price alerts by SMS to a mobile phone. But closer examination of its code turned up several suspicious traits that indicate it may try to steal the virtual currency, wrote Kenny MacDermid, a research analyst with security company Arbor Networks.

Bitcoin's skyrocketing value this year has drawn wide interest from investors as well as from cybercriminals. Bitcoins are secured by public key cryptography, and if the private key for a bitcoin is obtained, the virtual currency can be stolen in a flash.

MacDermid received three spam messages in one day promoting Bitcoin Alarm.

"I ignored it the first two times, but they must have really wanted me to look at it, so who am I not to oblige?" he wrote.

Tucked inside Bitcoin Alarm is a script that checks whether security software from Avast is running. If so, it stays quiet for 20 seconds. "It's a pretty solid chance that if software is checking for an antivirus engine, that it's up to no good," MacDermid wrote.

An encrypted file inside Bitcoin Alarm turned out to be a remote-access Trojan called NetWiredRC, which can be used to steal login credentials and, in this case, bitcoins, he wrote.

MacDermid submitted Bitcoin Alarm to VirusTotal, an online service that runs suspicious software programs through more than four dozen antivirus suites. On the first pass, only Kaspersky Lab's product detected Bitcoin Alarm, although more antivirus suites are picking it up now, MacDermid wrote.

"This free utility is nothing more than malware with very low detection rate being spammed to anyone that might have a bitcoin sitting around," he wrote.

A website for Bitcoin Alarm was created on Nov. 19, according to data from Domain Tools. A YouTube video showing how to install the application was uploaded there two weeks ago. The demonstration video uses a Windows computer set for German.

Efforts to reach Bitcoin Alarm via an email address on its website were not immediately successful.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or
Error: Please check your email address.

Tags securityinternetmalwarearbor networksInternet-based applications and services

Featured

Slideshows

Bumper channel crowd kicks off first After Hours of 2018

Bumper channel crowd kicks off first After Hours of 2018

After Hours made a welcome return to the channel social calendar with a bumper crowd of partners, distributors and vendors descending on The Jefferson in Auckland to kick-start 2018. Photos by Gino Demeer.

Bumper channel crowd kicks off first After Hours of 2018
Looking back at the top 15 M&A deals in NZ during 2017

Looking back at the top 15 M&A deals in NZ during 2017

In 2017, merger and acquisitions fever reached new heights in New Zealand, with a host of big name deals dominating the headlines. Reseller News recaps the most important transactions of the Kiwi channel during the past 12 months.

Looking back at the top 15 M&A deals in NZ during 2017
Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Show Comments