The proxy service for the Tor browser stole Bitcoin users

Security specialists from the company Proofpoint conducted an investigation, during which they found that the proxy service, through which you can access the Tor network from a regular browser, replaces the addresses of the bitcoin-purses and behaves similarly to the extortion programs LockeR, Sigma, and GlobeImposter.

The service looks through the web pages downloaded through the portal, looking for lines that look like addresses of bitcoins and purses, then replaces those lines with purses of intruders, experts from Proofpoint explained.

During the analysis of the service, it was found that it works by several rules of substituting bitcoin-purses, which clearly indicates a manual setting for each particular site.

So far, there have been two bitcoins-purses belonging to scammers working through In total, purses contain about two Bitcoins (about 22 thousand dollars). After the scheme was declassified, the program operators removed links to all proxy servers and advised users to pay only through the Tor browser.

