A remote access trojan campaign stole over $235,000 in cryptocurrency from hundreds of victims within a 48-hour window, according to a report published on September 20, 2026. The malware used credential harvesting and session manipulation techniques to bypass authentication and drain wallets at scale. No specific malware variant, threat actor, or law enforcement investigation has been identified so far. The irreversibility of cryptocurrency transactions makes fund recovery nearly impossible, and the window for authorities to act appears to have already closed.
Source: Read the original article

