Skip to main content

Netskope details the Underground crypto-draining operation

3 companies named across 5 categories, one of 294 articles referencing Netskope. Previous coverage: AI training portals, cloud sandboxes, and security advisories - Week of September 28, 2026 (Sep 2026).

Companies mentioned

Best suited for

Seniority
Director
Job function
Cybersecurity / Information Security
Persona
Security Operations Leader
Buyer role
Technical Implementer / Administrator
Buyer journey
Need to Buy
Adoption curve
Early Adopters
Technology maturity
Operational Expansion
Industry
Information Technology / Cybersecurity / Security Operations / Threat Intelligence & Digital Risk Protection

Our classification, not the publisher's statement. Best suited for, not only for.

Netskope Threat Labs examined a crypto-stealing campaign that used a Windows loader, browser injection, and rotating gates to drain exchange accounts and alter confirmation emails. The report matters to enterprise security teams because it combines endpoint compromise, web injection, and anti-analysis measures in a single operation.

Infection chain

The operation started with archive files that contained a setup program, a modified DLL, and an encrypted data file. Running the setup program launched an Underground loader that decrypted a later stage, injected it into dllhost.exe, and then spawned Chrome or Edge under the victim’s browser profile.

That process let the stealer operate inside already authenticated browser sessions without writing its stage to disk. Netskope said the loader also checked for analysis tools, packet sniffers, monitoring utilities, and virtual machine artifacts before continuing.

Gate protocol and browser injection

Each infected machine contacted a gate through /api/machine/commands using a per-machine UUID. The gate used Cloudflare in front of an nginx/FastCGI origin, returned 404 responses at the root, and served content only from /api/machine/* paths.

The /api/machine/injections endpoint returned a large JSON configuration with browser-injection scripts, clipboard-clipper rules, and file-finder logic. Netskope tracked seven gate domains that changed over time, with some registered long before use and others appearing in telemetry shortly after registration.

Account drain and clipboard clipper

The injected script targeted Binance sessions with an in-page overlay that imitated a security-verification prompt in about 25 languages. Behind that overlay, it disabled the withdrawal allow list, converted assets to USDC and then BTC, and sent funds to an 11-address Bitcoin reserve pool.

The same configuration also monitored webmail services including Gmail, Outlook, Yahoo, and Proton for withdrawal confirmations. Netskope said the payload rewrote the message content in the victim’s browser so the notice appeared routine.

On-chain activity and builder telemetry

Netskope estimated the campaign’s on-chain proceeds at about $100,000, based on inbound transactions to destination addresses at spot prices and stopping at the first hop. The report counted at least 350 to 430 paying victims after filtering contracts and services, while noting that the true total is higher because exchange wallet transfers were not included.

The Underground builder also reported stage activity to a telemetry panel tied to an IP address that recorded logs from October 2023 through January 2026. Netskope said it did not attribute the operation to a named actor and used Underground as its label for the builder.

Defensive guidance

Netskope said its Threat Protection detects the campaign through behavioral URI matching, malicious-site classification, and loader scanning. The company advised treating a blocked gate as an active infection because affected hosts can keep polling for new infrastructure even after web blocking is in place.

The report also recommends checking for dllhost.exe injection, browser processes launched by dllhost.exe, files written to and removed from C:\ProgramData\Underground\, and Chrome or Edge requests to /api/machine/* paths. It also says exchange withdrawals should be verified through a separate channel because the payload can rewrite confirmation emails in webmail.

This Blog Summary is a fact-based summary of the vendor blog and shows how the campaign combined a Windows loader, browser-based theft, and rotating infrastructure to target exchange accounts. For enterprise decision-makers, the report highlights endpoint cleanup, behavioral detection, and out-of-band verification as the main controls discussed in the blog.

Blog post, originally published by Vini Egerland at netskope.com.

Structured data (JSON-LD)

The schema.org markup this page publishes for search engines and AI agents, exactly as they read it.

[
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#website",
    "@type": "WebSite",
    "name": "Decision Insights",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://decisioninsights.ai/search/?q={search_term_string}&submit=1"
      }
    },
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    },
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#organization",
    "@type": "Organization",
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer support",
      "email": "[email protected]"
    },
    "description": "Decision Insights is a Registry of technology companies, open source projects, and industry terms, built for people and for AI agents that need sourced, structured information.",
    "logo": {
      "@type": "ImageObject",
      "url": "https://wiretap-cdn-assets.nyc3.cdn.digitaloceanspaces.com/decision-insights/[email protected]"
    },
    "name": "Decision Insights",
    "parentOrganization": {
      "@type": "Organization",
      "name": "Wiretap Labs",
      "sameAs": [
        "https://www.linkedin.com/company/wiretap-labs",
        "https://www.crunchbase.com/organization/wiretap-labs"
      ],
      "url": "https://wiretaplabs.com"
    },
    "publishingPrinciples": "https://decisioninsights.ai/standards/",
    "sameAs": [
      "https://www.linkedin.com/company/decisioninsights"
    ],
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai",
        "name": "Decision Insights",
        "position": 1
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/records/",
        "name": "Records",
        "position": 2
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/netskope-details-the-underground-crypto-draining-operation/",
        "name": "Netskope details the Underground crypto-draining operation",
        "position": 3
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/netskope-details-the-underground-crypto-draining-operation/#blogposting",
    "@type": "BlogPosting",
    "about": {
      "@id": "https://decisioninsights.ai/registry/netskope/#organization",
      "@type": "Organization",
      "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
      "name": "Netskope"
    },
    "audience": [
      {
        "@type": "Audience",
        "additionalType": "Seniority",
        "audienceType": "Director"
      },
      {
        "@type": "Audience",
        "additionalType": "Job function",
        "audienceType": "Cybersecurity / Information Security"
      },
      {
        "@type": "Audience",
        "additionalType": "Persona",
        "audienceType": "Security Operations Leader"
      },
      {
        "@type": "Audience",
        "additionalType": "Buyer role",
        "audienceType": "Technical Implementer / Administrator"
      },
      {
        "@type": "Audience",
        "additionalType": "Adoption curve",
        "audienceType": "Early Adopters"
      },
      {
        "@type": "Audience",
        "additionalType": "Technology maturity",
        "audienceType": "Operational Expansion"
      },
      {
        "@type": "Audience",
        "additionalType": "Industry",
        "audienceType": "Information Technology / Cybersecurity / Security Operations / Threat Intelligence & Digital Risk Protection"
      }
    ],
    "author": {
      "@id": "https://decisioninsights.ai/author/decision-insights-signals/#person",
      "@type": "Person",
      "name": "Decision Insights Record",
      "url": "https://decisioninsights.ai/author/decision-insights-signals/"
    },
    "dateModified": "2026-10-01T05:47:23-06:00",
    "datePublished": "2026-10-01T05:47:17-06:00",
    "description": "Netskope said a crypto-stealing campaign used a Windows loader and browser injection to drain exchange accounts.",
    "headline": "Netskope details the Underground crypto-draining operation",
    "isBasedOn": {
      "@type": "CreativeWork",
      "author": {
        "@type": "Person",
        "name": "Vini Egerland"
      },
      "url": "https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation"
    },
    "keywords": [
      "Edge",
      "Enterprise",
      "Services",
      "Telemetry",
      "Threats"
    ],
    "mainEntityOfPage": {
      "@id": "https://decisioninsights.ai/netskope-details-the-underground-crypto-draining-operation/",
      "@type": "WebPage",
      "sdDatePublished": "2026-10-01",
      "sdPublisher": {
        "@id": "https://decisioninsights.ai/#organization"
      }
    },
    "mentions": [
      {
        "@id": "https://decisioninsights.ai/registry/btc/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/btc/",
        "name": "BTC"
      },
      {
        "@id": "https://decisioninsights.ai/registry/cloudflare/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/cloudflare/",
        "name": "Cloudflare"
      },
      {
        "@id": "https://decisioninsights.ai/registry/netskope/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
        "name": "Netskope"
      }
    ],
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    }
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/author/decision-insights-signals/#person",
    "@type": "Person",
    "description": "Press releases and independent analyst research, structured into concise summaries for research and monitoring. Produced under our Standards & Methodology.",
    "name": "Decision Insights Record",
    "sameAs": [
      "https://www.linkedin.com/showcase/decisioninsights/"
    ],
    "url": "https://decisioninsights.ai/author/decision-insights-signals/"
  }
]

Is this your company? Get structured data for your own pages