• About Us
  • Contact
  • Cookie Policy
  • Disclaimer
  • Privacy Policy
  • Editorial Charter
  • Corrections Policy
  • Sitemap
Freelanews
Advertisement
  • Home
  • News
    • Crime
  • Business
  • Brands
  • Banking
  • Opinion
  • Interview
  • Entertainment
  • Podcast
    • Àtẹ́lẹwọ́
  • Sports
  • Events
No Result
View All Result
  • Home
  • News
    • Crime
  • Business
  • Brands
  • Banking
  • Opinion
  • Interview
  • Entertainment
  • Podcast
    • Àtẹ́lẹwọ́
  • Sports
  • Events
No Result
View All Result
Freelanews
No Result
View All Result
Home Business & Finance Cryptassets

‘Over $500k worth lost’ Twizt used for crypto attacks in Nigeria, Ethopia, others

Freelanews by Freelanews
December 16, 2021
in Cryptassets
0 0
0
chaos in the crypto market falling to 50 per day
0
SHARES

Check Point Research has discovered new attacks targeting cryptocurrency users in Ethiopia, Nigeria, India and 93 other countries. The cybercriminals behind the attacks are using a variant of the Phorpiex botnet — which Check Point called “Twizt” — to steal cryptocurrency through a process called “crypto clipping.”

Because of the length of wallet addresses, most systems copy a wallet address and allow you to paste it in during transactions simply. With Twizt, cybercriminals have been able to substitute the intended wallet address with the threat actor’s wallet address.

Researchers with Check Point said they have seen 969 transactions intercepted, noting that Twizt “can operate without active command and control servers, enabling it to evade security mechanisms,” meaning each computer that it infects can widen the botnet.

In the last year, they have seen 3.64 Bitcoin, 55.87 Ether, and $55,000 in ERC20 tokens stolen by Twizt operators, amounting to about $500,000. In one instance alone, 26 ETG was taken. Between April 2016 to November 2021, Phorpiex bots hijacked about 3,000 transactions worth nearly 38 Bitcoin and 133 Ether. The cybersecurity company noted that this was only a portion of the attacks taking place.

Phorpiex was originally known as a botnet used for sextortion and crypto-jacking but evolved to include ransomware. Check Point said Phorpiex has been operating since at least 2016 and was initially known as a botnet that operated using IRC protocol.

perfect aesthetic dental clinic perfect aesthetic dental clinic perfect aesthetic dental clinic

“In 2018-2019, Phorpiex switched to modular architecture and the IRC bot was replaced with Tldr — a loader controlled through HTTP that became a key part of the Phorpiex botnet infrastructure. In our 2019 Phorpiex Breakdown research report, we estimated over 1,000,000 computers were infected with Tldr,” Check Point explained.

In May, Microsoft’s Defender Threat Intelligence Team released a lengthy blog post warning that Phorpiex “began diversifying its infrastructure in recent years to become more resilient and to deliver more dangerous payloads.”

In August, the activity of Phorpiex command and control servers dropped sharply, and one of the people behind the botnet posted an ad on the darknet offering the source code for sale. Check Point’s Alexey Bukhteyev told The Record that even though the command and control servers were down, any buyer of the source code could set up a new botnet using all of the previously infected systems.

It is unclear if the botnet was actually sold, but Check Point said the command and control servers were back online at another IP address within weeks. When the command and control servers were restarted after their hiatus in August, they began distributing Twizt, which enables the botnet “to operate successfully without active command and control servers, since it can operate in peer-to-peer mode.”

“This means that each of the infected computers can act as a server and send commands to other bots in a chain. As a really large number of computers are connected to the Internet through NAT routers and don’t have an external IP address, the Twizt bot reconfigures home routers that support UPnP and sets up port mapping to receive incoming connections,” Check Point explained.

“The new bot uses its own binary protocol over TCP or UDP with two layers of RC4-encryption. It also verifies data integrity using RSA and RC6-256 hash function.”

Now, Check Point said the new features to Twizt make them believe the botnet “may become even more stable and, therefore, more dangerous.” Check Point has seen attacks stay consistent even when the command and control servers are inactive. Over the last two months, there has been an uptick in attacks, with incidents hitting 96 different countries.

Alexander Chailytko, cybersecurity research & innovation manager at Check Point Software, said two main risks are involved with the new variant of Phorpiex.

“First, Tiwzt is able to operate without any communication with C&C; therefore, it is easier to evade security mechanisms, such as firewalls, in order to do damage. Second, Twizt supports more than 30 different cryptocurrency wallets from different blockchains, including major ones such as Bitcoin, Ethereum, Dash, Monero,” Chailytko said.

“This makes for a huge attack surface, and basically anyone who is utilizing crypto could be affected. I strongly urge all cryptocurrency users to double-check the wallet addresses they copy and paste, as you could very well be inadvertently sending your crypto into the wrong hands.”

Check Point urged cryptocurrency owners always to double-check the original and pasted addresses to make sure they match. People should also send test transactions before any large trades.

Researchers said the Phorpiex crypto-clipper supports more than 30 wallets for different blockchains in the report. They also noted that the botnet operators may be in Ukraine because evidence indicates that the bot does not execute if the user’s default locale abbreviation is “UKR.”

Even though it served a variety of purposes, Check Point’s report says Phorpiex was originally not considered a sophisticated botnet.

“All of its modules were simple and performed the minimal number of functions. Earlier versions of the Tldr module did not use encryption for the payloads. However, this did not prevent the botnet from successfully achieving its goals. Malware with the functionality of a worm or a virus can continue to spread autonomously for a long time without any further involvement by its creators,” Check Point explained.

“We showed that a cryptocurrency clipping technique for a botnet of this scale can generate significant profits (hundreds of thousands US dollars annually) and does not require any kind of management through command and control servers. In the past year, Phorpiex received a significant update that transformed it into a peer-to-peer botnet, allowing it to be managed without having a centralized infrastructure. The command and control servers can now change their IP addresses and issue commands, hiding among the botnet victims.”

freelanews
Freelanews

Freelanews is the editorial byline of Freelanews.com, used for staff reports, news updates, press releases, and collaborative stories produced by the Freelanews Editorial Team.

Related Posts

quotes 29
Cryptassets

‘Needs investigating’ Probe rising crypto adoption despite restrictions, expert tasks senate

by Freelanews
November 27, 2021
whatsapp image 2022 10 14 at 10.11.21 pm
Cryptassets

‘Deepening knowledge’ Cyberchain to hold talks on cybersecurity, blockchain with Abuja, Lagos Oct. 22, Nov. 12

by Rtn. Victor Ojelabi
October 16, 2022
Full Frame 100 Euro Banknotes Overhead View
Cryptassets

‘Optimistic’ Digital Euro could come out within four years, European cenbank discloses

by Freelanews
May 18, 2022
901440 cryptocurrency
Cryptassets

CBN Ban on Crypto Currency: A Rejoinder

by Freelanews
February 25, 2021
MEXC
Cryptassets

MEXC urges caution as crypto hype fuels risky bets

by David Okere
December 15, 2025

Leave a ReplyCancel reply

ADVERTISEMENT

Recent News

EFCC

EFCC, immigration, Amotekun deployed to Ekiti polling unit

June 20, 2026
FUOYE

FUOYE suspends two students over alleged cyberbullying of ex-SUG president

June 20, 2026
PETROAN

PETROAN urges fuel price cuts as crude oil falls

June 20, 2026
Tulsi Gabbard COVID-19 documents

Tulsi Gabbard drops explosive COVID-19 documents accusing US-funded research

June 20, 2026
  • Trending
  • Comments
  • Latest
N250k signature

Abiodun vs Amosun: N250k signature plot deepens Ogun political crisis ahead Tinubu visit

April 3, 2026
Omoge Saida

Omoge Saida sparks Nigerian social media over leaked video

October 28, 2025
james akaie

Nollywood SFX makeup artist James Akaie allegedly dies after explosion on Abeokuta movie set

January 13, 2026
Political persecution in Ogun State

Political persecution in Ogun State: Abiodun moves against Otunba Gbenga Daniel with demolition threats again

August 9, 2025
amoke

‘Meals by Amoke’ We serve traditional dishes in a modern way, Bukoye Fasola reveals

19
Image 2024 03 26 at 120645 AM jpeg

Charles Inojie, Ali Nuhu call on communities to #MakeWeHalla against domestic violence

11
Meran Primary Health Centre Lagos father Meran hospital

Lagos father shares heartbreaking experience at Meran Primary Health Centre (Photos)

4
fls2

‘Disarticulated system’ Gov’t confused about Nigerian education, expert laments

3
EFCC

EFCC, immigration, Amotekun deployed to Ekiti polling unit

June 20, 2026
FUOYE

FUOYE suspends two students over alleged cyberbullying of ex-SUG president

June 20, 2026
PETROAN

PETROAN urges fuel price cuts as crude oil falls

June 20, 2026
Tulsi Gabbard COVID-19 documents

Tulsi Gabbard drops explosive COVID-19 documents accusing US-funded research

June 20, 2026
June 2026
SMTWTFS
 123456
78910111213
14151617181920
21222324252627
282930 
« May    
Freelanews

Freelanews is a Nigerian digital news platform that delivers timely, credible, and engaging stories across politics, business, entertainment, lifestyle, and the creative industry, with a strong focus on promoting innovation, integrity, and inclusivity in storytelling.

Today’s Popular

  • Abidemi Rufai released from US prison

    Former Ogun Governor’s aide Abidemi Rufai released early from US prison

    0 shares
    Share 0 Tweet 0
  • Ogun govt rejects controversial Awujale nomination letter

    0 shares
    Share 0 Tweet 0
  • Five princes nominated for Awujale of Ijebuland throne

    0 shares
    Share 0 Tweet 0
  • US-based Nigerian reported to FBI for inciting election officials’ murder

    0 shares
    Share 0 Tweet 0

Just Published!

EFCC

EFCC, immigration, Amotekun deployed to Ekiti polling unit

June 20, 2026
FUOYE

FUOYE suspends two students over alleged cyberbullying of ex-SUG president

June 20, 2026
PETROAN

PETROAN urges fuel price cuts as crude oil falls

June 20, 2026
Tulsi Gabbard COVID-19 documents

Tulsi Gabbard drops explosive COVID-19 documents accusing US-funded research

June 20, 2026
Fauci no science COVID 19 scaled

Fauci admits no science or trials behind key COVID-19 measures

June 20, 2026
No Result
View All Result
  • About Us
  • Contact
  • Advertisement
  • Editorial Charter
  • Corrections Policy
  • Sitemap

© 2025 Freelanews | by Iretura.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
    • Crime
  • Business
  • Brands
  • Banking
  • Opinion
  • Interview
  • Entertainment
  • Podcast
    • Àtẹ́lẹwọ́
  • Sports
  • Events

© 2025 Freelanews | by Iretura.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.