Categories: CryptoNewsSecurity

Internet Criminals Drop Angler In Favor of Neutrino EK To Spread CryptXXX

The evolution of Bitcoin ransomware is spectacular to behold, yet it’s also very annoying to deal with at the same time. CryptXXX has been making a lot of media headlines throughout the years, and it looks like the developer shave added a new twist. Instead of being spread through the Angler exploit kit, the payload is now bundled with Neutrino.

CryptXXX Version 3.100 is here

As if the evolution from CryptXXX version 2.0 to version 3.0 was not worrying enough, another version has been hitting the Internet. Switching up the distribution method will increase the chances of infecting computer users all over the world. That being said, the Neutrino Exploit Kit is a rather peculiar choice.

Up until this point, the ransomware used to spread itself through the Angler exploit kit. That is not entirely surprising, considering how this toolset if the fan favorite among internet criminals. Moreover, Angler bundles some hard to patch vulnerabilities which hackers can make use of. So far, Angler has been far more successful than any other version.

But if it is up to Neutrino, that situation will come to change. Apparently, it is rather common for target campaigns to switch between Angler and Neutrino. That being said, spreading CryptXXX through Neutrino is a definite first. It looks as if the developers of CryptXXX want to stake their claim in the malware world by continuing to revamp their pet project.

Related Post

It remains unclear as to why hacker collective using the Angler exploit kit have made the switch, though. Security experts have not noticed any Angler samples containing the CryptXXX payload for several days now. Then again, internet criminality is a business model like any other, and hackers will have to keep switching up tactics to achieve their goals.

What makes the Neutrino Exploit Kit so appealing is the targeting of java runtime environments. Angler, on the other hand, goes after Java and Flash Player, as well as Silverlight. A most peculiar evolution of CryptXXX, that much is certain. Who knows what will be the next for the malware?

Source: Threatpost

Images credit 1,2

If you liked this article follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin and altcoin price analysis and the latest cryptocurrency news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Ethereum Names Its Post-Glamsterdam 2026 Upgrade: Hegota

Ethereum developers have officially named the network’s post-Glamsterdam 2026 upgrade Hegota. The name merges two…

3 days ago

TRON Integrates With Kalshi, Bringing TRX and USDT to the World’s Largest Prediction Market

TRON is pushing deeper into real-world financial infrastructure. TRON has announced that Kalshi, the world’s…

3 days ago

Former Pump.fun Developer Sentenced to Six Years After $2M SOL Heist

The “crypto Robin Hood” story has reached its legal end. A London court has sentenced…

3 days ago

NEAR Goes Live on Solana as Cross-Chain Trading and AI Ambitions Accelerate

$NEAR is now live on Solana. And the implications go far beyond a simple token…

4 days ago

Bitcoin Rips to $90K, Then Slips as Leverage and Supply Collide

Bitcoin moved fast. Then it pulled back just as quickly. A sudden surge pushed BTC…

4 days ago

Hyperliquid Proposes 37M HYPE Burn as Validators Prepare to Vote

Hyperliquid is facing one of its most consequential governance moments yet. A proposal now before…

5 days ago