The Efimer Trojan spreads through torrent files and targets cryptocurrency wallets by disguising itself as a media player named xmpeg_player.exe. Cybercriminals exploit poorly secured WordPress sites to distribute this malware, while in corporate settings, they use phishing emails related to copyright infringement to deliver the Trojan. Once activated, it searches for cryptocurrency seed phrases and replaces transfer addresses with those of the attackers. Victims have been reported in Russia, India, Spain, Italy, and Germany. Kaspersky Lab has also reported on another malware, SparkKitty, aimed at stealing cryptocurrency from users in Southeast Asia and China.