These crooks have stolen millions of passwords. Here’s how to avoid becoming their next victim

Teilen:

A major malware operation has stolen vast numbers of passwords, according to security company researchers.

 

Image: Getty

Gangs targeting Amazon, PayPal, Steam and other accounts have stolen over 50 million passwords during the first half of 2022 alone, along with bank account details, cryptocurrency wallet data and other sensitive information from victims.

Detailed by cybersecurity researchers at security company Group-IB, the password-stealing campaign is attributed to 34 different Russian-speaking cyber criminal groups involved in distributing malware-as-a-service schemes.

People have fallen victim to the attacks across the world, with the US, Brazil, India, Germany, and Indonesia most commonly targeted.

By using information-stealing Malware including Raccoon und Redline stealers, cyber criminals have collectively infected over 890,000 users and stolen over 50 million passwords – as well as stealing details of over 103,000 bank cards and data which could be used to steal from over 113,000 crypto wallets, according to the security company.

The stolen passwords and compromised card details are thought to be worth a total of around $5.8 million on underground forums.

Analysis of cyber criminal activity suggests that the campaigns are organized in Telegram channels – researchers identified 34 active chat groups based around stealing passwords, with around 200 members in each.

The tasks of workers, the scammers of the lower-ranks is to drive traffic to scam websites impersonating well-known companies and convince victims to download malicious files. Cybercriminals embed links for downloading stealers into video reviews of popular games or into mining software or ‘lotteries’ on social media.

The most commonly stolen passwords are for PayPal accounts, followed by Amazon, Steam, Roblox and Epic Games accounts.

 

Also: A security researcher easily found my passwords and more: How my digital footprints left me surprisingly over-exposed

The malware-as-a-service model allows low-level crooks to access malware which they then use to infect victims. These attackers either pay an upfront fee for using the malware, or provide the author with a cut of the profits from their attacks.

“The popularity of schemes involving stealers can be explained by the low entry barrier. Beginners do not need to have advanced technical knowledge as the process is fully automated,” said a blog post by Group-IB’s Digital Risk Protection team.

Raccoon stealer is the most used malware in these attacks targeting passwords. The malware isn’t that sophisticated, but it’s been successful for years and is commonly distributed by abusing botnets to send out Phishing-Mails.

Redline stealer is also popular among the password-stealer attackers because it’s cheap for would-be criminals to acquire and easy-to-use and has been available since 2020. Redline is commonly distributed using phishing emails with malicious attachments designed to exploit unpatched vulnerabilities in applications.

According to Group-IB, other methods the cyber criminals use to deliver malware to victims include distributing it within software downloads on file-sharing sites, as well as taking control of social media accounts and sharing a malicious link with their followers.

 

Also: My stolen credit card details were used 4,500 miles away. I tried to find out how it happened

No matter what malware is being used or how it’s delivered, if a victim becomes infected, it can provide cyber criminals with access to their passwords, bank details, cryptocurrency wallets and more.

Stealing bank details or cryptocurrency will be costly for the victims, who could find that their accounts have been drained or used to make fraudulent purchases.

Meanwhile, stealing passwords can provide cyber criminals with a range of sensitive information which they can exploit for fraud themselves, or sell on underground forums. There’s also the possibility that if the same password is used across multiple accounts, cyber criminals will be able to access them too.

“For victims whose computers become infected with a stealer, the consequences can be disastrous,” warned researchers,” said Group-IB.

To avoid falling victim to this password-stealing malware campaign and other cyber attacks, researchers recommend that users avoid downloading software from suspicious or unknown sources, avoid saving passwords in their browser and regularly clear their cookies.

Other steps which users can take to avoid unauthorized access to accounts include using multi-factor authentication, so in the event a password is stolen, it’s much harder for a cyber criminal to use the account.

https://www.zdnet.com/article/these-crooks-have-stolen-millions-of-passwords-heres-how-to-avoid-becoming-their-next-victim/

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:47 am, Juni 1, 2025
Wetter-Symbol 14°C
L: 12° | H: 15°
klarer Himmel
Luftfeuchtigkeit: 81 %
Druck: 1014 mb
Wind: 3 mph WSW
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 15°°C 0.2 mm 20% 15 mph 81 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 7 mph 81 % 1014 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 80 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 17°°C 0 mm 0% 11 mph 57 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 37 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,818.16
0.49%
Ethereum(ETH)
€2,211.86
0.29%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.90
1.58%
Solana(SOL)
€136.65
0.59%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.167032
-0.80%
Shiba Inu(SHIB)
€0.000011
1.91%
Pepe(PEPE)
€0.000011
2.41%
Peanut das Eichhörnchen(PNUT)
€0.229042
5.25%
Nach oben scrollen