Threat actors are targeting cryptocurrency users with the ImBetter information stealer malware.
Adversaries are hosting malicious phishing websites that masquerade as crypto-wallets and online file converters to lure victims into downloading and executing the malicious software.
The malware terminates itself if the system belongs to multiple regions including Russian Kazakh Tatar Bashkir Belarusian Yakut or Russian Moldova.
The stealer collects a range of sensitive information and exfiltrates the data to command-and-control servers.