Bitcoin market price app, 'Bitcoin Alarm,' is carefully cloaked malware
The application contains a remote access Trojan, Arbor Networks said
IDG News Service - If you get a spam message advertising an application called "Bitcoin Alarm," the name may tell you all you need to know.
The desktop Windows application sends price alerts by SMS to a mobile phone. But closer examination of its code turned up several suspicious traits that indicate it may try to steal the virtual currency, wrote Kenny MacDermid, a research analyst with security company Arbor Networks.
Bitcoin's skyrocketing value this year has drawn wide interest from investors as well as from cybercriminals. Bitcoins are secured by public key cryptography, and if the private key for a bitcoin is obtained, the virtual currency can be stolen in a flash.
MacDermid received three spam messages in one day promoting Bitcoin Alarm.
"I ignored it the first two times, but they must have really wanted me to look at it, so who am I not to oblige?" he wrote.
Tucked inside Bitcoin Alarm is a script that checks whether security software from Avast is running. If so, it stays quiet for 20 seconds. "It's a pretty solid chance that if software is checking for an antivirus engine, that it's up to no good," MacDermid wrote.
An encrypted file inside Bitcoin Alarm turned out to be a remote-access Trojan called NetWiredRC, which can be used to steal login credentials and, in this case, bitcoins, he wrote.
MacDermid submitted Bitcoin Alarm to VirusTotal, an online service that runs suspicious software programs through more than four dozen antivirus suites. On the first pass, only Kaspersky Lab's product detected Bitcoin Alarm, although more antivirus suites are picking it up now, MacDermid wrote.
"This free utility is nothing more than malware with very low detection rate being spammed to anyone that might have a bitcoin sitting around," he wrote.
A website for Bitcoin Alarm was created on Nov. 19, according to data from Domain Tools. A YouTube video showing how to install the application was uploaded there two weeks ago. The demonstration video uses a Windows computer set for German.
Efforts to reach Bitcoin Alarm via an email address on its website were not immediately successful.
Send news tips and comments to email@example.com. Follow me on Twitter: @jeremy_kirk
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The Threat Landscape Hardly a day goes by without the discovery of a new cyberthreat somewhere in the world! But how do you keep up with...
- Security for Virtualization In the rush to implement virtualization, security has become second. So while the business benefits are clear, the risks are less well documented...
- System and Data Protection, Recovery and Availability This white paper describes how ARCserve works and the benefits it can provide IT environments of all sizes.
- Simplifying Data Protection, Reducing Risk of Data Loss and System Downtime This white paper outlines what IT organizations should look for in a data protection solution, including simplicity and ease of deployment, comprehensive protection,...
- Four Myths of High-Productivity App Dev Debunked Debunk the main myths surrounding high-productivity application development and how both platforms have overcome them.
On-Demand Webcast: 7 Reasons to Choose VoIP
Thinking about a new phone system for your business?
Be sure to watch this informative webcast. Steve Strauss, small business columnist for USA...
All Malware and Vulnerabilities White Papers |