As cryptocurrency prices, particularly Bitcoin, continue to surge, cybercriminals are stepping up their game. Intezer Labs, a cybersecurity research firm, recently revealed a sophisticated malware campaign that has been operating since January 2020, leveraging three fake cryptocurrency-related applications to drain users' digital wallets.
Three Bogus Crypto Trading and Poker Apps
According to Intezer Labs, the threat actors have been using a Remote Access Tool (RAT) named ElectroRAT spread through a marketing campaign. The malware is distributed via three applications: Jamm and eTrade/Kintum (both fake crypto trading platforms), and DaoPoker (a fake crypto poker app). These apps come with professional-looking websites, domain registrations, and are promoted using fake social media accounts on crypto forums like BitcoinTalk and Steemcoinpan.
To maximize reach and credibility, the hackers developed versions of their malicious software for Windows, Mac, and Linux operating systems. Intezer Labs estimates there are “thousands of victims” globally affected by this campaign.
An ‘Uncommon’ Malware with Powerful Capabilities
Once installed, ElectroRAT begins stealing cryptocurrency wallet data. Intezer Labs describes the malware as “extremely intrusive,” featuring capabilities such as keylogging, taking screenshots, uploading files from disk, downloading files, and executing commands on the victim’s console. The same capabilities are present across all three OS variants.
Security researchers emphasize that it is “very uncommon” to see such ransomware targeting cryptocurrency users directly. It is even more rare to witness a wide-ranging campaign that includes fake apps, websites, and coordinated marketing efforts across forums and social media.
Protection Recommendations
Users are advised to exercise extreme caution when downloading any crypto-related applications. Only obtain apps from official app stores or verified project websites. Enable two-factor authentication (2FA) for wallets and regularly monitor account activity. If suspicious behavior is detected, disconnect from the internet immediately and run a full antivirus scan.

