Babadeda Crypter Obfuscates RATs Targeting Cryptocurrency Communities
Crypter may sound like a synonym of ransomware, but these two words mean entirely different things in the world of cybercrime. Crypters are tools that hackers use to obfuscate and mask malicious files. These crypters work in different ways – some inject tons of junk code to confuse antivirus products, while others use complicated encryption routines and obfuscation techniques. The Babadeda Crypter is one of the latest projects of this sort, and it appears to be rapidly gaining popularity among cybercriminals. The good news is that antivirus vendors are not far behind, and many of the modern anti-malware scanners area already able to identify files modified by the Babadeda Crypter.
What is the Babadeda Crypter Used With?
Many of the payloads encrypted with the Babadeda Crypter appear to be Remote Access Trojan – such as Remcos and BitRAT. However, it is possible that the criminals might quickly expand their collection of implants by introducing other RATs or information stealers.
It seems that members of the decentralized finance (DeFi,) NFT, and cryptocurrency communities are the primary targets of the Babadeda Crypter. The criminals infiltrate various Discord communities in the aforementioned groups, and then impersonate known personalities and companies in the field. For example, some of the Babadeda Crypter payloads were hosted on sites impersonating the names of popular NFT marketplaces, or NFT companies.
NFT communities are not just the target of malware – scams are also running rampant. There are many con artists trying to steal credentials, wallets, and other information from victims. If you participate in such communities, always be wary of random private messages that ask you to visit sites, download apps, or perform other tasks. Do not trust them unless you can verify the identity of the sender. Keep your computer safe by using an up-to-date anti-malware application at all times. Antivirus tools are already able to identify the Babadeda Crypter and cease the execution of its payloads.








