ended3월 19일· 1 sources
GlassWorm Malware Campaign Steals Crypto Seeds via Obfuscation, Chrome Exploit, and Social Engineering: Mitigation Strategies
GlassWorm 악성코드 캠페인: 난독화·Chrome 취약점·사회공학 기법을 결합한 암호화폐 시드 구문 탈취와 대응 전략
Why it matters
The GlassWorm malware campaign targets cryptocurrency wallet seed phrases using a three-pronged attack: xorshift-based runtime obfuscation to evade detection, exploitation of an unpatched Chrome HMAC vulnerability for arbitrary code execution, and spear-phishing for initial delivery. Once installed, it intercepts seed phrases via keylogging or clipboard capture, then exfiltrates encrypted data to a C2 server disguised as normal traffic.
1
Sources
+0
24h
—
Growth
186d
Active
GlassWormcrypto seed phrasesChrome HMACxorshift obfuscationspear-phishingC2 exfiltration