Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Summer of crypto (regs): State of Crypto

June 16, 2026

Ethereum Research Proposal Targets Post-Quantum Wallet Security At Low Gas Cost

June 16, 2026

isolved Honors Top-Performing Partners at Annual Connect for Partners Event

June 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Crypto-Stealing Campaign Deploys MortalKombat Ransomware
Crypto-Stealing Campaign Deploys MortalKombat Ransomware
Security and Privacy

Crypto-Stealing Campaign Deploys MortalKombat Ransomware

May 28, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new financial fraud campaign has been spotted using a variant of the Xorist commodity ransomware “MortalKombat,” together with a variant of the Laplas Clipper malware.

The cyber-attacks reportedly aimed to steal cryptocurrency from victims and mainly targeted victims in the United States but also in the United Kingdom, Turkey and the Philippines.

“Leveraging cryptocurrency offers threat actors attractive benefits such as anonymity, decentralization, and lack of regulation, making it more challenging to track,” Cisco Talos wrote in a Tuesday advisory.

The company said it discovered the actor scanning the internet for victim machines with an exposed remote desktop protocol (RDP) port. They then employed one of their download servers to run an RDP crawler and facilitated MortalKombat ransomware deployments.

From a technical standpoint, the attacks seen as part of this campaign start with a phishing email, which initiates a multi-stage attack chain in which the actor delivers either malware or ransomware, then deletes evidence of their malicious presence on the infected machine.

“The malicious ZIP file attached to the initial phishing email contains a BAT loader script,” reads the advisory.

Once victims run the loader script, it downloads another malicious ZIP file from an attacker-controlled hosting server to the victim’s machine, inflates it automatically and executes the payload (the GO variant of Laplas Clipper malware or MortalKombat ransomware).

“The loader script will run the dropped payload as a process in the victim’s machine, then delete the downloaded and dropped malicious files to clean up the infection markers,” Cisco Talos wrote. 

To defend against this campaign, Cisco Talos encouraged companies to be careful while performing cryptocurrency transactions.

See also  Sen. Elizabeth Warren Calls Republican Opponent John Deaton’s Campaign a “Threat,” Presses Donor Base for Funding

Erich Kron, a security awareness advocate at KnowBe4, shared Cisco Talos’ security recommendations, adding that organizations should focus on email phishing defenses.

“Many organizations still allow .ZIP files as attachments, yet may not have a reason for most employees to be able to send this type of file,” Kron told Infosecurity in an email. “Because these types of archive files are used regularly when trying to spread malware, disallowing them could significantly improve the ability to defend against these campaigns.”

Phishing-based attacks were also at the center of a recent Cofense report, which suggested the use of Telegram bots as exfiltration destinations for phished information grew by 800% between 2021 and 2022.

Source link

campaign CryptoStealing deploys MortalKombat Ransomware
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

UK crypto advocates launch campaign against banks blocking exchange transfers

June 12, 2026

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

Coinbase-backed Stand With Crypto calls on members to campaign against banks blocking digital asset transactions

June 12, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Mapping whether Litecoin is really undervalued right now

December 13, 2023

Last Chance Migrate BEP2 Tokens Before Beacon Chain Sunset!

March 31, 2026

LayerZero V2 Launches, Redefining Blockchain Interoperability

January 31, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Summer of crypto (regs): State of Crypto

June 16, 2026

Ethereum Research Proposal Targets Post-Quantum Wallet Security At Low Gas Cost

June 16, 2026

isolved Honors Top-Performing Partners at Annual Connect for Partners Event

June 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$66,130.000.51%
  • ethereumEthereum(ETH)$1,777.223.44%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$614.61-0.43%
  • rippleXRP(XRP)$1.233.35%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$73.693.49%
  • tronTRON(TRX)$0.317531-1.09%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.27%
  • HyperliquidHyperliquid(HYPE)$69.586.77%