Attacker Targets Wealthy Crypto Funds Using Telegram Chats
Exchange owners cautioned against downloads of malicious as attackers zeroed in on gullible users with a very relevant and specific narrative.
In the latest type of crypto-focused attacks, an attacker known as DEV-0139 has targeted wealthy cryptocurrency funds through the use of Telegram group chats, Microsoft's (MSFT) Security Intelligence team said in a report on Wednesday.
Fees levied by crypto exchanges on transactions are a big challenge for investment funds and wealthy traders. They represent a cost and must be optimized to minimize the impact on margins and profits. As is the case with many other companies in this industry, the largest costs come from fees charged by exchanges.
The attacker or group of attackers capitalized on this specific problem to lure their crypto-fund targets.
DEV-0139 joined several Telegram groups, used by high-profile clients and exchanges for communication, and identified their target from among the group members. OKX, Huobi and Binance exchanges were targeted, data from the Microsoft report shows.
Posing as an exchange employee, DEV-0139 invited the target to a different chat group and pretended to ask for feedback on the fee structures used by exchanges. They then initiated a conversation to gain the target’s trust – using their knowledge of the industry and preparedness to lure victims gradually.
DEV-0139 then sent a weaponized Excel file containing accurate data on fee structures among cryptocurrency-exchange companies with the goal of increasing his or her credibility.
The Excel file initiated a series of activities, including using a malicious program to retrieve data and drop another Excel sheet. This sheet was then executed in invisible mode and used to download a picture file containing three executables: a legitimate Windows file, a malicious version of a DLL file and an XOR-encoded back door.
A DLL is a library that contains code and data that can be used by more than one program at the same time. On the other hand, XOR is an encryption method used to encrypt data and is hard to crack by the brute-force method
The threat actor was then able to remotely access the infected system through the use of the back door.
Microsoft said DEV-0139 may have also run other campaigns using similar techniques.
More For You
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
What to know:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
Circle faces first major 'threat' for institutional dollars from Tether’s USAT

While Circle's USDC has operated without a "credible domestic competitor," Tether's USAT has the potential to shake up the landscape, analysts said.
What to know:
- Analysts said USAT, the U.S.-focused stablecoin by Tether, could become the first credible domestic competitor to Circle's USDC token.
- USAT is "a threat to USDC" and could gain an edge through institutional partners and global USDT connectivity, Crypto is Macro Now's Noelle Acheson said.
- ClearStreet's Owen Lau called USAT “a manageable risk” for Circle, and noted potential "cannibalization" risk between Tether's two tokens.











