BTC $83,892.25 -0.25%
ETH $2,682.90 -0.56%
BNB $772.21 -0.38%
XRP $1.54 -2.79%
SOL $120.40 +0.70%
TRX $0.3363 -0.19%
DOGE $0.0969 -0.63%
ADA $0.2541 -0.39%
BCH $333.99 -0.46%
LINK $14.21 +1.52%
HYPE $91.89 -0.84%
AAVE $154.22 +3.43%
SUI $1.15 +3.06%
XLM $0.2171 -1.92%
ZEC $1,537.75 -4.15%
AAPL $340.22 +1.46%
AMZN $249.42 -0.27%
GOOGL $343.13 -0.69%
MSFT $517.41 +2.04%
META $747.64 -1.11%
NVDA $224.22 -0.94%
TSLA $371.56 -0.07%
SNDK $1,776.15 -1.17%
INTC $122.96 -2.29%
SPCX $148.55 +0.49%
MU $1,082.43 -1.97%
AMD $629.41 -0.82%
BTC $83,892.25 -0.25%
ETH $2,682.90 -0.56%
BNB $772.21 -0.38%
XRP $1.54 -2.79%
SOL $120.40 +0.70%
TRX $0.3363 -0.19%
DOGE $0.0969 -0.63%
ADA $0.2541 -0.39%
BCH $333.99 -0.46%
LINK $14.21 +1.52%
HYPE $91.89 -0.84%
AAVE $154.22 +3.43%
SUI $1.15 +3.06%
XLM $0.2171 -1.92%
ZEC $1,537.75 -4.15%
AAPL $340.22 +1.46%
AMZN $249.42 -0.27%
GOOGL $343.13 -0.69%
MSFT $517.41 +2.04%
META $747.64 -1.11%
NVDA $224.22 -0.94%
TSLA $371.56 -0.07%
SNDK $1,776.15 -1.17%
INTC $122.96 -2.29%
SPCX $148.55 +0.49%
MU $1,082.43 -1.97%
AMD $629.41 -0.82%

steal

All
Article
Flash

first_img HBO Max account was hijacked, and 108 malicious ads were placed to steal cryptocurrency assets

Cybersecurity company Hudson Rock disclosed that the Reddit verified account of the streaming service HBO Max was hijacked earlier this month and deployed 108 malicious ads within approximately 48 hours. These ads used a non-existent HBO Max native macOS application as bait, luring users to open Terminal or PowerShell and paste malicious commands, a technique known as ClickFix.Researchers named this operation PasteSwitch, and its delivery system adapts based on the visitor's device and the advertised software. Observed Mac payloads include MacSync and Atomic macOS (AMOS) information-stealing trojans, targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware also utilized Binance Smart Chain contracts as variable C2 address delivery points and was associated with a cryptocurrency clipboard hijacker that replaces clipboard wallet addresses.According to Malwarebytes, Reddit administrators have suspended the related ads and initiated a security investigation following reports. The report did not specify how the account was compromised or the number of victims, nor was there evidence found that the HBO Max streaming service itself was breached. The ClickFix technique has previously been used multiple times in attacks targeting cryptocurrency users, including approximately 2,000 compromised WordPress sites and malicious activities disguised as CAPTCHA.

first_img Socket exposes 77 malicious wallet extensions for Firefox, 40 confirmed to steal mnemonic phrases

According to a report by Decrypt, security company Socket released research results linking 77 Firefox extensions to what it calls a "wallet theft factory," with 40 confirmed to have malicious behavior.These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, tricking users into importing wallets through fake wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla's signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online at the time of Socket's report.About half of the extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the inputted mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content.Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran sports score applications sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released as score applications for sports like football and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the "wallet theft factory," but cautioned that it has not confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys into these extensions should consider it a "permanent leak" and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.

The IRS warns of new cryptocurrency phishing attacks: counterfeit letters use QR codes to steal wallet private keys

According to CoinDesk, the Internal Revenue Service (IRS) has issued a warning that a sophisticated email phishing campaign targeting U.S. cryptocurrency holders is spreading. Attackers are impersonating official tax letters to lure users into scanning malicious QR codes to steal cryptocurrency wallet credentials and private keys.It is reported that attackers are sending paper letters impersonating the IRS, creating a sense of urgency under the guise of "tax compliance" and "account verification," and including QR codes in the letters. Once users scan the code, they may be directed to a counterfeit website, leading to the leakage of wallet login information, recovery phrases, or private keys, resulting in the theft of digital assets.The IRS reminds taxpayers that official agencies will not request users to provide cryptocurrency wallet private keys, recovery phrases, or perform similar "wallet verification" operations through unofficial channels. Cryptocurrency holders should be vigilant against any suspicious emails and letters that request scanning QR codes, connecting wallets, or submitting sensitive information.As the number of cryptocurrency asset holders grows, social engineering attacks targeting digital wallets continue to increase, and regulatory and security agencies are strengthening warnings against related fraudulent activities.

ZachXBT: American female scammer impersonates customer service to steal over 5 million dollars in cryptocurrency assets

On-chain detective ZachXBT posted that U.S. threat actor Tiffany Milanovich participated in the theft of approximately $5 million in crypto assets by impersonating hardware wallet and centralized exchange customer service.Her methods included disguising as Bitcoin IRA email support, during one attack transferring about $1.2 million in BTC and ETH from the victim's Trezor wallet, and in another case stealing about $500,000 in BTC from a Coinbase account. Tiffany induced victims to hand over access to their funds under the guise of "customer service calls," later boasting about the stolen money on social media and Telegram groups, mocking victims with recordings, and collaborating with other threat actors to launder money using phishing panels and instant exchange services, with some of the stolen funds still dormant on-chain.The threat actor codenamed "Tiffany" is suspected of participating in multiple crypto asset thefts, gambling the stolen funds at crypto casinos. The platform Shuffle has frozen related accounts based on evidence submitted by ZachXBT; Tiffany previously shared a search and seizure warrant from Connecticut, dated before some of the incidents involved.ZachXBT has obtained chat logs, recordings, and on-chain evidence, anticipating that this individual may face further legal consequences. This threat actor is also linked to the John Daghita (Lick) case, who is suspected of stealing over $46 million in crypto assets from a U.S. government-seized wallet.
app_icon
ChainCatcher Building the Web3 world with innovations.