BTC $79,251.59 -0.66%
ETH $2,490.40 +0.03%
BNB $740.76 -1.19%
XRP $1.40 -0.81%
SOL $104.22 -1.11%
TRX $0.3345 -0.08%
DOGE $0.0903 +0.98%
ADA $0.2197 +0.35%
BCH $260.92 +1.87%
LINK $12.81 +3.70%
HYPE $85.53 -1.95%
AAVE $132.38 -0.17%
SUI $0.8265 +3.70%
XLM $0.1932 +5.45%
ZEC $1,161.15 -4.55%
BTC $79,251.59 -0.66%
ETH $2,490.40 +0.03%
BNB $740.76 -1.19%
XRP $1.40 -0.81%
SOL $104.22 -1.11%
TRX $0.3345 -0.08%
DOGE $0.0903 +0.98%
ADA $0.2197 +0.35%
BCH $260.92 +1.87%
LINK $12.81 +3.70%
HYPE $85.53 -1.95%
AAVE $132.38 -0.17%
SUI $0.8265 +3.70%
XLM $0.1932 +5.45%
ZEC $1,161.15 -4.55%

Slow Fog: Attackers exploit XSS vulnerability on Cointelegraph website for phishing

2024-11-28 09:35:52

ChainCatcher news, Slow Mist founder Yuxian disclosed an XSS attack targeting the crypto industry on the X platform. The attacker exploited an XSS vulnerability on the crypto media website Cointelegraph to lure target users into opening a link to the official Cointelegraph website (with XSS malicious script), resulting in:

  • Malicious script loading and execution;
  • The address bar being set to a suspicious address (which at first glance looks like an official unpublished draft);
  • A fake Sign in with X pop-up appearing;
  • After clicking Sign in with X, the third-party application authorization for X opens, with a large blank section in the permissions list. If you inadvertently click to authorize without paying attention, your X-related permissions will be taken over by the attacker.

This type of phishing with a slight exploit is particularly difficult for the general public to defend against, so extra caution is needed.

app_icon
ChainCatcher Building the Web3 world with innovations.