Inferno Drainer Malware Returns, Stealing $9M from Crypto Wallets in Six Months

By: bitcoin ethereum news|2025/05/10 00:30:07
0
Share
copy
Crypto-stealing malware Inferno Drainer remains in operation despite publicly shutting down—and has has been used to snatch over $9 million from crypto wallets over the past six months. According to cybersecurity firm Check Point Research, over 30,000 crypto wallets have been drained by the resurgent malware campaign, whose developers claimed to have ceased operations in November 2023. Deep Dive into Inferno Drainer Reloaded: tracing malicious smart contracts, decrypting drainer configs, and fully uncovering the Discord phishing attack via a fake CollabLand bot. Over 30K new victims in just six months.https://t.co/xgcg9AaMRu — Check Point Research (@_CPResearch_) May 7, 2025 A spokesperson for CPR told Decrypt that the figure was based on “data obtained from reverse-engineering the drainer’s JavaScript code, decrypting its configuration received from the C&C server, and analyzing its on-chain activity.” The majority of observed was on Ethereum and Binance Chain , they added. CPR analysts reported that Inferno Drainer smart contracts deployed in 2023 are still active to this day, while the current version of the malware appears to have been improved upon over the previous iteration. The malware is reportedly now able to use single-use smart contracts and on-chain encrypted configurations, making it far harder to detect and prevent attacks. In addition, command-and-control server communication has been obfuscated via proxy-based systems, meaning tracking has become even more difficult. Inferno Drainer’s resurgence comes alongside a phishing campaign targeting Discord users. According to CPR analysts, the campaign leveraged social engineering techniques to redirect users from a legitimate Web3 project’s website to a counterfeit site mimicking the verification UX for popular Discord bot Collab.Land. The fake Collab.Land site hosted a cryptocurrency drainer, which tricked victims into signing malicious transactions—enabling attackers to gain access to their funds. By combining “targeted deception and effective social engineering tactics,” the malware campaign has generated a “stable financial flow identified through blockchain transaction analysis,” CPR analysts said. Crypto users are advised to exercise extra caution whenever they are interacting with unfamiliar platforms. The fake Collab.Land bot identified by CPR contained only “subtle visual differences” to the legitimate bot, and the cybercriminals behind the deception are likely to “continue refining their imitation,” the researchers said. Because the legitimate Collab.Land service requires users to verify their wallet by signing, they noted, “even experienced cryptocurrency users may lower their guard” when presented with the fake bot—making it even more important to verify authenticity before connecting wallets to any service. The revival of Inferno Drainer is just one of a number of malware campaigns to surface in recent months. Hackers are adopting increasingly sophisticated techniques to deliver crypto-stealing malware, targeting hacked mailing lists, open-source Python libraries and even preloading trojans on counterfeit Android phones. Daily Debrief Newsletter Start every day with the top news stories right now, plus original features, a podcast, videos and more. Source: https://decrypt.co/318561/inferno-drainer-malware-returns-stealing-9m-from-crypto-wallets-in-six-months

You may also like

What Is Futures Trading? Hours, Platforms, and How to Start Trade Futures(2026 Guide)

Learn how to start futures trading, understand trading hours, and choose the best futures trading platform. Includes real data, strategies, and ways to maximize returns with rebates.

The Rise of Composable RWA

27 billion RWA funds are undergoing a major reshuffle: U.S. Treasury bonds are "cooling off," while high-yield credit assets are quietly dominating the DeFi lending market with permissionless designs. This article reveals the explosive logic behind composable RWA.

MAGA Up 350% in 24 Hours, PEPE Up 46% in One Day: Which Memecoins Are Next in 2026?

MAGA +350% in 24hrs. PEPE +46% in one day. RAVE +4,500% then -90%. In 2026's memecoin market, the gains are real. So are the traps? Here's how to tell the difference before you buy.

RCD Espanyol vs Real Madrid: Can the Pericos Delay the Inevitable?

RCD Espanyol vs Real Madrid lineups, standings, and stats for May 3, 2026. Real Madrid visits RCDE Stadium as Barcelona closes in on the LALIGA title. Full preview inside.

MegaETH goes live with an FDV exceeding 2 billion USD. Which ecological projects are worth paying attention to?

The financing and team backgrounds of many projects in the MegaETH ecosystem are rich, making it the most prosperous ecosystem among unlaunched public chains, and it is currently the focus of attention for profit-seekers.

Dialogue with "Wood Sister" Cathie Wood: The next bull market is about to arrive

The correlation coefficient between gold and Bitcoin is only 0.14. In the past two cycles, gold started before Bitcoin, and this time is no different.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com