|

Gluptepa malware using the Bitcoin blockchain to stay alive?

  • The malware uses the Bitcoin blockchain to update itself continuously.
  • Protect yourself against it by not clicking on suspicious links and emails and by keeping your router firmware up-to-date.

As per TrendMicro, cybersecurity researchers have discovered a new strain of the infamous Gluptepa malware. The malware uses the Bitcoin blockchain to stay alive. Analysts confirm that this strain is capable of invading systems to mine Monero and steal sensitive data like passwords and cookies. It also exploits a vulnerability in MicroTik routers to transform target machines into a SOCKS proxy. After that, it executes spam attacks on Instagram users.

The malware uses the Bitcoin blockchain to automatically update and run smoothly even if the antivirus software blocks its connection to remote command and control (C&C) servers run by the attackers. As investigated by TrendMicro’s researchers, Gluptega attackers will first send a Bitcoin transaction via the Electrum wallet. It will then make its way through a public list of the wallet’s servers to find every transaction made by the attacker. Within those transactions, Gluptega will exploit the OP_RETURN opcode containing the encrypted C&C domain. The domain gets decrypted by a ScriptHash string which is hardcoded within the malware.

TrendMicro said:

“This technique makes it more convenient for the threat actor to replace C&C servers. If they lose control of a C&C server for any reason, they simply need to add a new Bitcoin script and the infected machines obtain a new C&C server by decrypting the script data and reconnecting.”

There are two ways to protect yourself against the malware - Don’t click on suspicious links and emails and ensure that your router’s firmware is up-to-date.

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

Ripple Price Forecast: XRP potential bottom could be in sight

Ripple edges up above the intraday low of $1.35 at the time of writing on Friday amid mixed price actions across the crypto market. The remittance token failed to hold support at $1.40 the previous day, reflecting risk-off sentiment amid a decline in retail and institutional sentiment. 

Crypto Today: Bitcoin, Ethereum, XRP in choppy price action, weighed down by falling institutional interest 

Bitcoin holds above support at $65,118 at the time of writing on Friday. Ethereum remains choppy in a narrow range between support at $1,900 and resistance at $2,000, while Ripple attempts another upward move toward the pivotal $1.40 level.

PancakeSwap Price Analysis: Bearish momentum suggests further downside

PancakeSwap (CAKE) is trading below $1.26 at the time of writing on Friday, extending the losses by over 8% so far this week. The weakening derivatives market further supports the bearish outlook, with bears aiming for levels below $1.18.

Decred Price Forecast: DCR rebounds toward key resistance zone on volume spike

Decred (DCR) rebounds over 7% at press time on Friday after a three-day decline of almost 14%. Roughly 60% increase in trading volume over the last 24 hours supports the recovery, suggesting heightened spot-market demand. 

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: BTC bears aren’t done yet

Bitcoin (BTC) price slips below $67,000 at the time of writing on Friday, remaining under pressure and extending losses of nearly 5% so far this week.