$100k in Crypto Drained by the Underground Operation

0k in Crypto Drained by the Underground Operation
Netskope Threat Labs uncovered the Underground builder, an Aotera/Tedy-based operation that injects a Vidar-class stealer into Windows processes and uses browser-session injection to drain cryptocurrency exchange accounts. The campaign rotates Cloudflare-fronted gates, abuses Chrome or Edge sessions, and has generated about $100,000 in on-chain proceeds from at least 350 to 430 victims. #Underground #Aotera #Tedy #Vidar #Binance #Cloudflare

Keypoints

  • The infection starts from versioned lure archives containing setup.exe, a trojanized msys-crypto-3.dll, and encrypted data.bin.
  • The Underground loader injects a self-decrypting payload into suspended dllhost.exe, then launches Chrome or Edge under the victim’s browser profile.
  • The payload is a Vidar-class stealer that collects cookies, passwords, Discord and Telegram data, wallet data, and screenshots.
  • The campaign uses a custom /api/machine/* command-and-control protocol and rotating gate domains behind Cloudflare rather than Vidar’s usual dead-drop C2.
  • The injected script performs automated Binance account draining by disabling withdrawal protections, converting balances to BTC, and withdrawing to operator-controlled reserve addresses.
  • A clipboard clipper replaces copied wallet addresses with attacker addresses across many cryptocurrencies and chains.
  • Researchers estimate roughly $100,000 in on-chain proceeds and at least 350 to 430 paying victims, with activity continuing through September 2026.

MITRE Techniques

  • [T1055 ] Process Injection – The loader injects a self-decrypting payload into a suspended process and later injects scripts into browser sessions (‘uses section-based injection to place a self-decrypting payload into a suspended dllhost.exe process’; ‘injects its scripts into those sessions’)
  • [T1204 ] User Execution – The infection begins when the victim opens a lure archive that contains the setup binary (‘The infection starts from a versioned lure archive, unencrypted 7z or zip files containing setup.exe’)
  • [T1105 ] Ingress Tool Transfer – The setup binary launches the loader and stages the malware components from the archive (‘The setup binary launches the Underground loader’; ‘contains setup.exe, a trojanized msys-crypto-3.dll, and an encrypted data.bin’)
  • [T1562.001 ] Impair Defenses: Disable or Modify Tools – The stealer disables withdrawal allow lists before draining the account (‘it disables the withdrawal allow list’)
  • [T1082 ] System Information Discovery – The loader checks running processes to detect analysis and monitoring environments (‘compares it against the running processes to detect an analysis or monitoring environment’)
  • [T1057 ] Process Discovery – The loader enumerates running processes and matches them against a hard-coded list (‘compares it against the running processes’)
  • [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – The anti-analysis list includes VM and sandbox tools to avoid execution in analysis environments (‘virtual-machine and sandbox agents (VMware, VirtualBox, QEMU guest tools)’)
  • [T1518.001 ] Software Discovery: Security Software Discovery – The loader checks for debugging, monitoring, and network-analysis tools such as IDA, Wireshark, and Process Explorer (‘covers debuggers and disassemblers … network sniffers … process monitors’)
  • [T1056.001 ] Input Capture: Keylogging – The clipper and webmail injection intercept user-entered or displayed sensitive payment and confirmation data in-browser (‘rewrites its subject and body’; ‘when the victim copies a wallet address, the clipper replaces it’)
  • [T1119 ] Automated Collection – The stealer automatically collects browser cookies, passwords, wallets, and screenshots (‘collecting Chromium and Gecko cookies and passwords … desktop and extension wallets, and screenshots’)
  • [T1021 ] Remote Services – The payload operates within authenticated browser sessions on the victim’s machine to interact with online services (‘launches Chrome or Edge … under the victim’s own browser profile’)

Indicators of Compromise

  • [Domains ] gate infrastructure and log endpoint – quick-neo[.]com, slow-sky[.]com, true-lie[.]com, easybooters[.]com
  • [IP address ] loader telemetry / builder panel – 95.164.53[.]76
  • [File names ] lure and loader artifacts – setup.exe, msys-crypto-3.dll, data.bin, stable_superior_verified.exe, easy_exceptional_instant.exe
  • [Directories ] loader logs and temporary artifacts – C:ProgramDataUnderground, AppDataLocal
  • [URLs / paths ] C2 and telemetry endpoints – /api/machine/commands, /api/machine/injections, /new/log//, /new/log///
  • [Wallet addresses ] clipper and reserve-pool destinations – bc1qwenpr55ekcs3a46ly4hqkjn652sppttdnsszhd, 0x4cC35bE54c358146E7b71E58f965532193848FDd, and other destination addresses
  • [Bitcoin addresses ] operator destinations and replacement values – 19hdEPSFQ4iUhtWoXHqg2E1kPCpUmaEgP8, 3H4ZCi9mhZsFpowmmVhUh1NF1C5NoSPPvH, bc1pfpwq9kd30e2hd2x2p90j302c9vtnnh5ejhw4vw46jc92rjtn259qlnv8wc
  • [Litecoin address ] clipper replacement value – LXnj7XNxmRkTnEbdDzKd7QfZSGaEriFu4m


Read more: https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation