Connect with us

Published

on

Understanding recent credential leaks and the rise of InfoStealer malware

Opinion by: Jimmy Su, Binance chief security officer

The threat of InfoStealer malware is on the rise, targeting people and organizations across digital finance and far beyond. InfoStealers are a category of malware designed to extract sensitive data from infected devices without the victim’s knowledge. This includes passwords, session cookies, crypto wallet details and other valuable personal information.

According to Kaspersky, these malware campaigns leaked over 2 million bank card details last year. And that number is only growing.

Malware-as-a-service

These tools are widely available via the malware-as-a-service model. Cybercriminals can access advanced malware platforms that offer dashboards, technical support and automatic data exfiltration to command-and-control servers for a subscription fee. Once stolen, data is sold on dark web forums, Telegram channels or private marketplaces.

The damage from an InfoStealer infection can go far beyond a single compromised account. Leaked credentials can lead to identity theft, financial fraud and unauthorized access to other services, especially when credentials are reused across platforms.

Recent: Darkweb actors claim to have over 100K of Gemini, Binance user info

Binance’s internal data echoes this trend. In the past few months, we’ve identified a significant uptick in the number of users whose credentials or session data appear to have been compromised by InfoStealer infections. These infections don’t originate from Binance but affect personal devices where credentials are saved in browsers or auto-filled into websites.

Distribution vectors

InfoStealer malware is often distributed via phishing campaigns, malicious ads, trojan software or fake browser extensions. Once on a device, it scans for stored credentials and transmits them to the attacker.

The common distribution vectors include:

  • Phishing emails with malicious attachments or links.

  • Fake downloads or software from unofficial app stores.

  • Game mods and cracked applications are shared via Discord or Telegram.

  • Malicious browser extensions or add-ons.

  • Compromised websites that silently install malware (drive-by downloads).

Once active, InfoStealers can extract browser-stored passwords, autofill entries, clipboard data (including crypto wallet addresses) and even session tokens that allow attackers to impersonate users without knowing their login credentials.

What to watch out for 

Some signs that might suggest an InfoStealer infection on your device:

  • Unusual notifications or extensions appearing in your browser.

  • Unauthorized login alerts or unusual account activity.

  • Unexpected changes to security settings or passwords.

  • Sudden slowdowns in system performance.

A breakdown of InfoStealer malware

Over the past 90 days, Binance has observed several prominent InfoStealer malware variants targeting Windows and macOS users. RedLine, LummaC2, Vidar and AsyncRAT have been particularly prevalent for Windows users. 

  • RedLine Stealer is known for gathering login credentials and crypto-related information from browsers.

  • LummaC2 is a rapidly evolving threat with integrated techniques to bypass modern browser protections such as app-bound encryption. It can now steal cookies and crypto wallet details in real-time.

  • Vidar Stealer focuses on exfiltrating data from browsers and local applications, with a notable ability to capture crypto wallet credentials.

  • AsyncRAT enables attackers to monitor victims remotely by logging keystrokes, capturing screenshots and deploying additional payloads. Recently, cybercriminals have repurposed AsyncRAT for crypto-related attacks, harvesting credentials and system data from compromised Windows machines.

For macOS users, Atomic Stealer has emerged as a significant threat. This stealer can extract infected devices’ credentials, browser data and cryptocurrency wallet information. Distributed via stealer-as-a-service channels, Atomic Stealer exploits native AppleScript for data collection, posing a substantial risk to individual users and organizations using macOS. Other notable variants targeting macOS include Poseidon and Banshee.

At Binance, we respond to these threats by monitoring dark web marketplaces and forums for leaked user data, alerting affected users, initiating password resets, revoking compromised sessions and offering clear guidance on device security and malware removal.

Our infrastructure remains secure, but credential theft from infected personal devices is an external risk we all face. This makes user education and cyber hygiene more critical than ever.

We urge users and the crypto community to be vigilant to prevent these threats by using antivirus and anti-malware tools and running regular scans. Some reputable free tools include Malwarebytes, Bitdefender, Kaspersky, McAfee, Norton, Avast and Windows Defender. For macOS users, consider using the Objective-See suite of anti-malware tools

Lite scans typically don’t work well since most malware self-deletes the first-stage files from the initial infection. Always run a full disk scan to ensure thorough protection.

Here are some practical steps you can take to reduce your exposure to this and many other cybersecurity threats:

  • Enable two-factor authentication (2FA) using an authenticator app or hardware key.

  • Avoid saving passwords in your browser. Consider using a dedicated password manager.

  • Download software and apps only from official sources.

  • Keep your operating system, browser and all applications up to date.

  • Periodically review authorized devices in your Binance account and remove unfamiliar entries.

  • Use withdrawal address whitelisting to limit where funds can be sent.

  • Avoid using public or unsecured WiFi networks when accessing sensitive accounts.

  • Use unique credentials for each account and update them regularly.

  • Follow security updates and best practices from Binance and other trusted sources.

  • Immediately change passwords, lock accounts and report through official Binance support channels if malware infection is suspected.

The growing prominence of the InfoStealer threat is a reminder of how advanced and widespread cyberattacks have become. While Binance continues to invest heavily in platform security and dark web monitoring, protecting your funds and personal data requires action on both sides.

Stay informed, adopt security habits and maintain clean devices to significantly reduce your exposure to threats like InfoStealer malware.

Opinion by: Jimmy Su, Binance chief security officer.

This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts, and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Continue Reading

Politics

No 10 decline to say if Palestine will be recognised with Hamas in power

Published

on

By

No 10 decline to say if Palestine will be recognised with Hamas in power

The prime minister’s spokesman has refused eight times to confirm whether recognition of Palestine could go ahead if Hamas remain in power and the hostages are not released. 

Keir Starmer’s spokesman was questioned by journalists for the first time since the announcement last week that the UK will formally recognise the state in September – unless Israel meets certain conditions including abiding by a ceasefire and increasing aid.

The policy has been criticised by the families of UK hostages, campaigners and some Labour MPs, who argue it would reward Hamas and say it should be conditional on the release of the remaining hostages.

A senior Hamas politician, Ghazi Hamad, speaking to Al Jazeera, said at the weekend that major nations’ decision to recognise a Palestinian state “is one of the fruits of 7 October”.

Gaza latest: Trump pressed to recognise Palestinian state

The PM’s spokesman said on Monday: “The PM is clear that on 7 October, Hamas committed the worst act of terror in Israel’s history. That horror has continued since then.

“As the foreign secretary said over the weekend, Hamas are rightly pariahs who can have no role in Gaza’s future, there is a diplomatic consensus on that. Hamas must immediately release all hostages and have no role in the governance of Gaza.”

But asked whether removing Hamas from power and releasing hostages were conditions for statehood, he said a decision on recognition would be made at the UN General Assembly meeting in September, based on “an assessment of how far the parties have met the steps we have set out. No one side will have veto on recognition through their actions or inactions.”

Please use Chrome browser for a more accessible video player

Up to 300 children could be evacuated from Gaza and given NHS treatment in the UK. The plans are reportedly set to be announced within weeks.

He added: “Our focus is on the immediate situation on the ground, getting more aid in to end the suffering in Gaza and supporting a ceasefire and a long-term peace for Israelis and Palestinians based a two-state solution.”

Starmer, who recalled his cabinet for an emergency meeting last week before setting out the new position, is following the lead of French president Emmanuel Macron, who first pledged to move toward recognising Palestinian statehood in April.

Read more:
New US plan for Gaza starting to emerge
Hamas responds to disarmament reports

Canada has also backed recognition if conditions are met, including by the Palestinian Authority.

The prime minister had previously said he would recognise a state of Palestine as part of a contribution to a peace process.

Please use Chrome browser for a more accessible video player

Efforts to bring Gazan children to the UK for urgent medical treatment are set to be accelerated under new government plans.

In his announcement last Tuesday, he said: “We need to see at least 500 trucks entering Gaza every day. But ultimately, the only way to bring this humanitarian crisis to an end is through a long-term settlement.

“So we are supporting the US, Egyptian and Qatari efforts to secure a vital ceasefire. That ceasefire must be sustainable and it must lead to a wider peace plan, which we are developing with our international partners.

“I’ve always said we will recognise a Palestinian state as a contribution to a proper peace process, at the moment of maximum impact for the two-state solution. With that solution now under threat, this is the moment to act.”

Adam Rose, a lawyer acting for British families of hostages in Gaza, has said: “Why would Hamas agree to a ceasefire if it knew that to do so would make British recognition of Palestine less likely?”

Continue Reading

Politics

Coinbase turns lobbying efforts to UK in scathing op-ed

Published

on

By

Coinbase turns lobbying efforts to UK in scathing op-ed

Coinbase turns lobbying efforts to UK in scathing op-ed

Former UK Chancellor and current Coinbase adviser George Osborne says the UK is falling behind in the cryptocurrency market, particularly when it comes to stablecoins.

Continue Reading

Politics

Nigel Farage dared me to walk in London after 9pm: Here’s my response

Published

on

By

Nigel Farage dared me to walk in London after 9pm: Here's my response

At a press conference today in which Reform UK announced the Tory police and crime commissioner for Leicestershire was joining their ranks, as well as former prison governor Vanessa Frake, I asked Nigel Farage a simple question.

But his answer wasn’t what I expected.

I asked the Reform UK leader if the six-week campaign on law and order, with the tagline “Britain is Lawless”, was in fact project fear scaring people into voting for his party.

He utterly rejected that claim and responded to me saying: “No, they are afraid. They are afraid. I dare you, I dare you to walk through the West End of London after 9 o’clock of an evening wearing jewellery. You wouldn’t do it. You know that I’m right. You wouldn’t do it.”

I am not afraid to walk in the West End of London after 9pm wearing jewellery.

I have done it many times before and will continue to do so… but perhaps that is because I do not own a Rolex.

However, just because Farage is wrong on that point, doesn’t mean he isn’t tapping into other legitimate fears across the country.

More on Nigel Farage

Snatch theft does worry me, hence why I now have a phone case with a strap attached to it that I can put around my body.

And I worry about knife crime in my area and what the impact could be if I were to have children – on the weekend someone was stabbed to death a stone’s throw from my house.

Please use Chrome browser for a more accessible video player

Farage ‘not mincing his words’

However, if we look at the statistics, it is invariably a more nuanced picture than Farage or social media might have us believe.

According to police reports, thefts from a person in London are almost five times the national average, and they’ve been going up since the pandemic.

And the Office for National Statistics (ONS) also notes that thefts outside of the home, eg phone snatching, has increased.

However, possession of weapons has fallen in London by 29% over the last three years.

And according to the ONS, crime in England and Wales is 30% lower than in 2015, and 76% lower than 1995.

And it is a similar picture for violent crime.

In short, am I right to be more worried that snatch theft and knife crime in London is increasing? Yes, and no.

But Nigel Farage is tapping into voters’ emotions – their feelings that the country is broken. It’s a picture the Conservative Party helped to create and the Labour Party happily painted to great effect during the general election campaign of 2024.

And the more politicians of all colours tell voters that “the system is broken”, the more voters might start to believe them.

That is what Nigel Farage is banking on.

Continue Reading

Trending