Scan to download
BTC $64,205.62 +1.07%
ETH $1,674.94 +0.51%
BNB $608.33 +0.71%
XRP $1.13 +1.18%
SOL $68.16 +2.32%
TRX $0.3181 +1.01%
DOGE $0.0876 +0.14%
ADA $0.1714 +0.66%
BCH $207.46 +1.33%
LINK $7.97 +1.52%
HYPE $59.81 -2.30%
AAVE $66.34 +2.31%
SUI $0.7644 +1.94%
XLM $0.1867 -1.61%
ZEC $409.52 -1.38%
BTC $64,205.62 +1.07%
ETH $1,674.94 +0.51%
BNB $608.33 +0.71%
XRP $1.13 +1.18%
SOL $68.16 +2.32%
TRX $0.3181 +1.01%
DOGE $0.0876 +0.14%
ADA $0.1714 +0.66%
BCH $207.46 +1.33%
LINK $7.97 +1.52%
HYPE $59.81 -2.30%
AAVE $66.34 +2.31%
SUI $0.7644 +1.94%
XLM $0.1867 -1.61%
ZEC $409.52 -1.38%

Slow Fog: Attackers exploit XSS vulnerability on Cointelegraph website for phishing

2024-11-28 09:35:52
Collection

ChainCatcher news, Slow Mist founder Yuxian disclosed an XSS attack targeting the crypto industry on the X platform. The attacker exploited an XSS vulnerability on the crypto media website Cointelegraph to lure target users into opening a link to the official Cointelegraph website (with XSS malicious script), resulting in:

  • Malicious script loading and execution;
  • The address bar being set to a suspicious address (which at first glance looks like an official unpublished draft);
  • A fake Sign in with X pop-up appearing;
  • After clicking Sign in with X, the third-party application authorization for X opens, with a large blank section in the permissions list. If you inadvertently click to authorize without paying attention, your X-related permissions will be taken over by the attacker.

This type of phishing with a slight exploit is particularly difficult for the general public to defend against, so extra caution is needed.

app_icon
ChainCatcher Building the Web3 world with innovations.