Beware Of Efimer Trojans Targeting Organizations With Phishing Emails
JAKARTA - Kaspersky Security Network reports a fast-growing malicious campaign through a trojan called Efimer.
It was first discovered that in October 2024, until July 2025 Kaspersky had found more than 5,000 users, both individuals and organizations, were recorded as victims.
The global cybersecurity company also said that Brazil was the most affected country with around 1,500 victims, followed by India, Spain, Russia, Italy, and Germany.
Trojan Efimer is designed to steal and change the victim's crypto wallet address. The version initially appeared and was spread through the compromised WordPress website. However, since June 2025, the attack method has developed via phishing email.
Where the attackers disguised themselves as law firms and sent electronic mail containing threats of lawsuits for violating domain name patents. This tactic is used to trick recipients into downloading malware.
For private users, attackers use Torrent files pretending to be popular films to lure victims, while for companies, they rely on fake emails containing legal threats.
Kaspersky recommends corporate and individual users: