Netskope details the Underground crypto-draining operation
3 companies named across 5 categories, one of 294 articles referencing Netskope. Previous coverage: AI training portals, cloud sandboxes, and security advisories - Week of September 28, 2026 (Sep 2026).
Companies mentioned
Best suited for
- Seniority
- Director
- Job function
- Cybersecurity / Information Security
- Persona
- Security Operations Leader
- Buyer role
- Technical Implementer / Administrator
- Buyer journey
- Need to Buy
- Adoption curve
- Early Adopters
- Technology maturity
- Operational Expansion
- Industry
- Information Technology / Cybersecurity / Security Operations / Threat Intelligence & Digital Risk Protection
Our classification, not the publisher's statement. Best suited for, not only for.
Netskope Threat Labs examined a crypto-stealing campaign that used a Windows loader, browser injection, and rotating gates to drain exchange accounts and alter confirmation emails. The report matters to enterprise security teams because it combines endpoint compromise, web injection, and anti-analysis measures in a single operation.
Infection chain
The operation started with archive files that contained a setup program, a modified DLL, and an encrypted data file. Running the setup program launched an Underground loader that decrypted a later stage, injected it into dllhost.exe, and then spawned Chrome or Edge under the victim’s browser profile.
That process let the stealer operate inside already authenticated browser sessions without writing its stage to disk. Netskope said the loader also checked for analysis tools, packet sniffers, monitoring utilities, and virtual machine artifacts before continuing.
Gate protocol and browser injection
Each infected machine contacted a gate through /api/machine/commands using a per-machine UUID. The gate used Cloudflare in front of an nginx/FastCGI origin, returned 404 responses at the root, and served content only from /api/machine/* paths.
The /api/machine/injections endpoint returned a large JSON configuration with browser-injection scripts, clipboard-clipper rules, and file-finder logic. Netskope tracked seven gate domains that changed over time, with some registered long before use and others appearing in telemetry shortly after registration.
Account drain and clipboard clipper
The injected script targeted Binance sessions with an in-page overlay that imitated a security-verification prompt in about 25 languages. Behind that overlay, it disabled the withdrawal allow list, converted assets to USDC and then BTC, and sent funds to an 11-address Bitcoin reserve pool.
The same configuration also monitored webmail services including Gmail, Outlook, Yahoo, and Proton for withdrawal confirmations. Netskope said the payload rewrote the message content in the victim’s browser so the notice appeared routine.
On-chain activity and builder telemetry
Netskope estimated the campaign’s on-chain proceeds at about $100,000, based on inbound transactions to destination addresses at spot prices and stopping at the first hop. The report counted at least 350 to 430 paying victims after filtering contracts and services, while noting that the true total is higher because exchange wallet transfers were not included.
The Underground builder also reported stage activity to a telemetry panel tied to an IP address that recorded logs from October 2023 through January 2026. Netskope said it did not attribute the operation to a named actor and used Underground as its label for the builder.
Defensive guidance
Netskope said its Threat Protection detects the campaign through behavioral URI matching, malicious-site classification, and loader scanning. The company advised treating a blocked gate as an active infection because affected hosts can keep polling for new infrastructure even after web blocking is in place.
The report also recommends checking for dllhost.exe injection, browser processes launched by dllhost.exe, files written to and removed from C:\ProgramData\Underground\, and Chrome or Edge requests to /api/machine/* paths. It also says exchange withdrawals should be verified through a separate channel because the payload can rewrite confirmation emails in webmail.
This Blog Summary is a fact-based summary of the vendor blog and shows how the campaign combined a Windows loader, browser-based theft, and rotating infrastructure to target exchange accounts. For enterprise decision-makers, the report highlights endpoint cleanup, behavioral detection, and out-of-band verification as the main controls discussed in the blog.
Blog post, originally published by Vini Egerland at netskope.com.