A sophisticated malware campaign, dubbed the "Efimer Trojan," is actively targeting cryptocurrency users worldwide, with a significant concentration of victims in Brazil. This malicious script, distributed through mass email campaigns and compromised websites, is designed to steal digital assets by stealthily replacing cryptocurrency wallet addresses in users' clipboards.
Key Takeaways
-
The Efimer Trojan is a sophisticated threat that steals cryptocurrency by replacing wallet addresses.
-
It spreads through phishing emails, compromised websites, and malicious torrents.
-
The malware uses the TOR network for C2 communication.
-
It possesses advanced capabilities like anti-VM features and WordPress site compromise.
-
Over 5,000 users have been impacted, with Brazil being a primary target.
Efimer Trojan's Deceptive Distribution Methods
The Efimer Trojan employs a multi-pronged approach to infect its victims. Initially detected in October 2024, its distribution methods have evolved. Early iterations spread via compromised WordPress websites. More recently, a mass mailing campaign emerged in June 2025, impersonating lawyers from a major company. These emails falsely claim domain name infringement, threatening legal action unless the recipient changes their domain or agrees to a buyout. The emails contain ZIP archives with password-protected files, leading to the execution of a malicious Windows Script File (WSF) that installs the Efimer Trojan.
Example of an ad on the page https://lovetahq[.]com/sinners-2025-torrent-file/
Sample letter of violations
How Efimer Steals Cryptocurrency
Once installed, the Efimer Trojan operates as a "clipper" malware. Its primary function is to monitor the user's clipboard for cryptocurrency wallet addresses. When a user copies a legitimate address, Efimer stealthily replaces it with an address controlled by the attackers. This means any funds sent to the swapped address will be irrevocably lost to the victim. The malware communicates with its command-and-control (C2) server via the TOR network, making its operations harder to trace. It can also harvest email addresses and compromise WordPress sites to further its propagation.
Advanced Capabilities and Propagation
Beyond its core clipping functionality, Efimer has demonstrated advanced capabilities. A second version of the malware incorporates anti-virtual machine features and actively scans web browsers for cryptocurrency wallet extensions, exfiltrating this information to its C2 server. Furthermore, additional scripts associated with Efimer have been observed to brute-force WordPress site passwords and harvest email addresses for future campaigns, creating a self-sustaining malicious infrastructure.
Global Impact and Key Takeaways
Kaspersky's telemetry indicates that the Efimer Trojan campaign has impacted over 5,000 users globally, with Brazil, India, Spain, Russia, Italy, and Germany being among the most affected countries. The malware's ability to propagate through various vectors, including torrent files disguised as popular movies and phishing emails targeting both individuals and corporations, makes it a significant threat.
Sources
-
AI Tools Fuel Brazilian Phishing Scam While Efimer Trojan Steals Crypto from 5,000 Victims, The Hacker News.
-
Efimer Trojan delivered via email and hacked WordPress websites, Securelist.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.