Three Fake Crypto Apps Used to Deploy ElectroRAT and Drain Users’ Wallets

Three Fake Crypto Apps Used to Deploy ElectroRAT and Drain Users’ Wallets

N
News Editor 01
2026-07-08 20:02:13
Security researchers say three bogus crypto-related apps were used in a broad ElectroRAT malware campaign targeting users across Windows, macOS, and Linux, with thousands of victims reportedly affected.
crypto securitymalwareElectroRATwallet theftcybercrime

As cryptocurrency prices climb, scams and malware campaigns tend to follow the momentum. Security firm Intezer Labs said it uncovered a long-running operation that used three fake crypto-related applications to infect users with a remote access trojan known as ElectroRAT, ultimately putting victims’ wallets and sensitive data at risk.

According to the research, the campaign had been active since January 2020 and was supported by a relatively sophisticated distribution and promotion strategy. Rather than relying on a single phishing page or a one-off lure, the threat actors appear to have built a broader ecosystem around the malware, including fake websites, malicious desktop applications, domain registrations, and social media personas used to market the products to cryptocurrency users.

Fake Trading and Poker Apps as the Infection Vector

Intezer Labs identified three applications at the center of the operation: Jamm, eTrade/Kintum, and DaoPoker. The first two were presented as cryptocurrency trading platforms, while DaoPoker was described as a crypto poker app. In reality, the applications were designed to distribute ElectroRAT.

The malware campaign stood out in part because the operators did not limit themselves to one operating system. Researchers said the attackers developed versions for Windows, macOS, and Linux, a move that likely helped them appear more legitimate while also widening the pool of potential victims. Cross-platform support is not always seen in lower-effort scams, and its presence here suggests a deliberate attempt to maximize reach across the global crypto community.

This approach also meant that users who may have assumed desktop software was safer than browser-based scams were still exposed. By offering downloadable applications with polished branding and multiple system versions, the operators could create the appearance of a real product rather than a quick fraud attempt.

A Year-Long Campaign Backed by Marketing Efforts

One of the more notable aspects of the case is the campaign’s promotional layer. Intezer Labs said the malware operation spread faster with the help of a marketing effort that ran alongside the technical infrastructure. The campaign reportedly involved fake social media accounts and forum activity intended to direct users toward the malicious apps.

Some of the bogus products were promoted on crypto-focused forums such as bitcointalk and Steemcoinpan. Researchers said attackers used fabricated profiles to endorse the apps and encourage downloads. This kind of social engineering is especially effective in crypto communities, where users often discover early-stage projects through forums, niche channels, and peer recommendations rather than through mainstream app marketplaces.

Intezer Labs said the campaign has already affected thousands of victims. That estimate highlights the scale of the operation and suggests the attackers succeeded in building enough trust to convince a meaningful number of users to install the software.

What ElectroRAT Can Do After Infection

Once installed, ElectroRAT is described as highly intrusive. According to the researchers, the malware is capable of keylogging, taking screenshots, uploading files from disk, downloading files, and executing commands on the victim’s console. These capabilities give attackers broad visibility into what a user is doing and can provide access to credentials, wallet-related activity, and sensitive local files.

Importantly, Intezer Labs said the Windows, Linux, and macOS versions offered similar functionality. That means the malware was not simply a basic loader or a single-purpose wallet stealer. Instead, it appears to have been engineered as a full-featured remote access tool that could support ongoing surveillance and follow-on actions after the initial compromise.

For cryptocurrency users, that level of access can be especially dangerous. Keylogging can capture passwords and recovery-related data typed into wallets or exchanges. Screenshots can reveal seed phrases, balances, and account dashboards. File upload functionality may expose locally stored wallet files or backups. Command execution can allow attackers to deepen persistence or move toward additional theft.

An Uncommon but Serious Threat Pattern

Intezer Labs said it is “very uncommon” to see malware of this type specifically focused on stealing sensitive information from cryptocurrency users. The firm also noted that it is even rarer to see such a broad and targeted operation combining fake applications, fraudulent websites, and coordinated promotional efforts across forums and social channels.

That observation is significant because it points to a shift in how some crypto-targeting campaigns are organized. Rather than relying purely on opportunistic phishing, the actors behind ElectroRAT appear to have invested in presentation, distribution, and credibility-building. In other words, the attack was not just about malicious code; it was also about constructing an environment in which potential victims would believe they were installing a legitimate crypto product.

The case also reinforces a longstanding lesson in digital asset security: visual polish and community buzz do not equal legitimacy. In crypto, where new apps, trading tools, gaming products, and experimental platforms regularly emerge, users may be more willing to test software before it has established a clear reputation. That creates fertile ground for attackers willing to imitate startup-style branding and community engagement.

Why the Findings Matter for Crypto Users

The reported campaign underscores the risks tied to downloading software from unofficial or poorly verified sources. If a malicious actor can combine forum promotion, fake identities, multi-platform binaries, and convincing websites, even relatively experienced users may be caught off guard.

While the research focused on the specific apps and malware family involved, the broader takeaway is relevant across the crypto sector. Wallet security is no longer only about protecting private keys from direct theft. It also requires caution around software provenance, installation sources, and the behavioral signals of an application once it is running on a device.

For market participants, especially those interacting with newer platforms, the ElectroRAT case is a reminder that malware campaigns often evolve alongside market enthusiasm. When prices rise and user activity increases, attackers frequently intensify efforts to exploit trust, urgency, and fear of missing out. In that environment, a fake trading app or gaming platform can become a highly effective attack vehicle.

Intezer Labs’ findings present a clear warning: crypto-themed malware is becoming more deliberate, more polished, and in some cases more operationally mature. As a result, the burden on users to verify software legitimacy before installation remains as important as ever.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.