Babadeda Crypter is being leveraged by cybercriminals to keep their malware untraceable
Summary
A new malware effort has been uncovered that uses Discord channels to spread a Crypter known as “Babadeda” that can evade antivirus software and perform a range of cyberattacks against cryptocurrency, non-fungible token (NFT), and Defi enthusiasts. The hackers sent misinformation to potential clients on Discord channels dedicated to blockchain-based games like Mines of Dalarnia, enticing people to install an app, according to Morphisec. When a user hits on a link in the text, they will be led to a spoofing site that looks like the game’s official web page and contains a URL to a Trojan launcher that comprises the Babadeda Crypter. When the launcher runs, it starts an attack process that decrypts and inserts the encoded payload in order to capture vital data. Because one of the spoof webpages contained Russian words, Morphisec associated the cyberattacks with a cybercriminal located in a Russian-speaking country.