Security Report: Organized Malware Campaign Targeting Crypto Users via Fake Balance Tools #185783
Unanswered
LotusHirasawaSusumu
asked this question in
Code Security
Replies: 1 comment
-
|
Thanks for sharing this reports like this are crucial since these “fake balance” tools keep trapping new users. A good reminder to stick to verified wallets and legit Real Earning APPs only. Hopefully this helps others avoid getting burned. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Security Report: Organized Malware Campaign Targeting Crypto Users via Fake Balance Tools
Report Date: January 28, 2026
Reporter: Previous malware victim
Status: Active distribution, immediate community action requested
Summary
An organized criminal group is currently operating a network of repositories on GitHub distributing malware disguised as "fake balance" or "flash" tools for cryptocurrency wallets (Phantom, Trust, OKX, Electrum, Atomic, Exodus).
These repositories are not harmless prank tools. They distribute actual malware designed to display fake balances and trick victims into sending real cryptocurrency to attackers. Multiple samples contain confirmed trojans and downloaders.
Technical Evidence
Confirmed Malicious Sample
93a9b82398bea54ea98d0e4ddcfbb24f81f4bc861db57c72b567288cde992924Notable Detections:
HEUR:Trojan-Downloader.Script.Agent.genTrojan.Siggen32.19580Win64:Evo-gen [Trj]Mal/Generic-SThis is a confirmed trojan, not a false positive.
Attack Pattern Analysis
This operation shows characteristics of an organized criminal effort:
Confirmed Malicious Repositories
The following repositories are confirmed to be part of this campaign and should be reported:
Astrivaapt/Phantom-Wallet-Fake-Web3-Flash-Balance-CryptoCurrencies-Crypto(Jun 2025)Aide1978/okx-fake-balance(Updated 1 week ago)dariavoronin6/trust-fake-balance(Updated 1 week ago)Aestrivuapt/Okx-Wallet-Fake-Balance-CryptoCurrencies-Web3-Flash-Crypto(Oct 2025)Aestrivuapt/Trust-Wallet-Fake-Web3-Flash-Balance-CryptoCurrencies-Crypto(Oct 2025)Astrivaopd/Phantom-Wallet-Fake-Web3-Flash-Balance-CryptoCurrencies-Crypto(Jul 2025)Daeena75/Phantom-Wallet-Fake-Web3-Flash-Balance-CryptoCurrencies-Crypto(Oct 2025)Dalcna75/Phantom-Wallet-Fake-Web3-Flash-Balance-CryptoCurrencies-Crypto(Dec 2025)HangTheD14/Electrum-Fake-Balance-Flash-Crypto-CryptoCurrencies-Wallet(Oct 2025)HangTheDrt/Electrum-Fake-Balance-Flash-Crypto-CryptoCurrencies-Wallet(Dec 2025)Aestrivuapt/Atomic-Wallet-Fake-Balance-Flash-Crypto-CryptoCurrencies(Oct 2025)Syedaayan/Electrum-Fake-Balance-Flash-Crypto-CryptoCurrencies-Wallet(Updated 1 hour ago, contains live trojan)logan0311/Electrum-Fake-Balance-Flash-Crypto-CryptoCurrencies-WalletHarmo7niasz/Trust-Wallet-Web3-Balance-CryptoCurrencies-CryptoAesopEabt/Atomic-Wallet-Crypto-CryptoCurrenciesspiderwebsdk/Exodus-Fake-BalanceHyzetva/Electrum-Crypto-CryptoCurrencies-WalletAdditional similar repositories continue to appear.
Note: Additional similar repositories are being identified daily.
Recommended Actions
For GitHub Users (Community Action)
Please report each repository:
For GitHub Security Team
Impact
These repositories actively distribute malware that results in direct financial loss to victims. The tools are designed to socially engineer users into transferring real cryptocurrency to attacker-controlled addresses, resulting in irreversible transactions.
Community reports help accelerate takedowns. If you encounter additional repositories matching this pattern, please comment below.
Thank you for helping maintain the security of the GitHub community.
Beta Was this translation helpful? Give feedback.
All reactions