As Bitcoin (BTC) prices surge, cybercriminals are capitalizing on the renewed interest in cryptocurrency with a sophisticated malware campaign. Security firm Intezer Labs has revealed a long-running operation, active since January 2020, that uses three fraudulent crypto-related applications to distribute a Remote Access Tool (RAT) named ElectroRAT.
The Three Malicious Apps: Jamm, eTrade/Kintum, and DaoPoker
According to the research, the threat actors developed versions of their malicious software for Windows, Mac, and Linux to maximize credibility and target a global audience. The three apps are: Jamm and eTrade/Kintum (both fake crypto trading platforms) and DaoPoker (a fake crypto poker app). Intezer Labs states that “thousands of victims” have been affected by the campaign, which includes domain registrations, trojanized applications, and fake social media accounts used for promotion.
The fake apps were promoted on crypto-themed forums such as bitcointalk and Steemcoinpan, where fake profiles encouraged users to download the infected applications.
ElectroRAT: An Uncommon and Dangerous Malware
Once installed, ElectroRAT drains victims’ crypto wallets. Intezer Labs describes its capabilities as “extremely intrusive,” including keylogging, taking screenshots, uploading files from disk, downloading files, and executing commands on the victim’s console. The malware variants for Windows, Linux, and macOS share similar functionalities.
The research firm highlights that it is “very uncommon” to see such malware targeting cryptocurrency users, and “even more rare” to see such a wide-ranging and targeted campaign that incorporates fake apps, websites, and marketing efforts on relevant forums and social media.
How to Protect Yourself
Security experts advise users to only download crypto-related apps from official sources, be wary of recommendations from unknown users on forums, and regularly check for unusual processes or files on their devices. Never enter private keys or seed phrases into any platform that is not verified.

