A collaborative advisory report has unveiled the emergence of a new strain of malware known as “Infamous Chisel,” which is believed to have Russian origins. This malware has been identified as a threat to various targets, including cryptocurrency wallet and exchange applications, among other sensitive data systems.
The report highlights the evolving landscape of cyber threats and emphasizes the need for robust cybersecurity measures to safeguard against such malicious activities, especially within the cryptocurrency sector where the protection of digital assets and sensitive information is paramount.
The advisory report was the result of a collaborative effort involving several prominent cybersecurity and law enforcement agencies. Key contributors to the report included the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), as well as the National Cyber Security Centre (NCSC), a division of the UK’s Government Communications Headquarters (GCHQ), among others.
This collective collaboration underscores the global nature of cyber threats and the importance of international co-operation in addressing cybersecurity challenges and protecting critical infrastructure, including cryptocurrency systems and services.
The Infamous Chisel malware has been linked to the activities of a hacking unit operating within Russia’s GRU military intelligence agency, known as Sandworm. Sandworm has previously been identified for its cyber operations targeting the Ukrainian military. Infamous Chisel is designed to enable persistent access to a compromised Android device through the Tor network.
Additionally, it collects and transmits victim data from the compromised devices, periodically. This information further highlights the connection between this malware and state-sponsored cyber activities, underlining the importance of vigilance and cybersecurity measures to counter such threats.
The Infamous Chisel malware conducts unauthorized actions related to data copying, transfer, and retrieval. During these activities, the malware specifically targets directories associated with various applications and platforms on the compromised Android device.
Notable targets include: Web3 browser Brave, Binance and Coinbase apps (cryptocurrency exchange platforms), Trust crypto wallet (a cryptocurrency wallet application), Communication platforms Telegram and Discord, and Android Keystore system (used for storing private keys)
Within these directories, the malware extracts every file it encounters. This comprehensive approach to data theft underscores the malware’s intent to compromise and retrieve a wide range of sensitive information, including cryptocurrency-related data and private keys, posing significant risks to affected individuals and organizations.
The components utilized by the Infamous Chisel malware exhibit a relatively low to medium level of sophistication. Notably, these components lack fundamental obfuscation or stealth techniques that would typically be employed to conceal malicious activities.
It is suggested in the report that the actor behind this malware may not have deemed such concealment necessities. This is possibly because many Android devices lack host-based detection systems that could potentially detect and counteract such malicious activity.
Nonetheless, the lack of sophistication in the malware does not diminish the potential risks it poses, especially when targeting devices without adequate security measures.









