Hackers launch 'poison' to steal users' cryptocurrencies
With cryptocurrencies increasing in price and more and more people pouring money into investments, the crypto market becomes a "fertile ground" for hackers. Many crypto holders have lost a large amount of money after being tricked by hackers.
Recently, security research firm Check Point Research has warned about a new form of fraud targeting cryptocurrency holders globally, including Vietnam. Accordingly, hackers will create fake websites or extensions (browser extensions), with the same interface as websites or extensions of popular cryptocurrency wallets, such as Phantom App, MetaMask or PancakeSwap…
Not stopping there, hackers will spend money to buy ads on Google to bring their phishing sites to the top of the search list. Many people who do not double-check the website link mistakenly visit fake websites, instead of the real website of cryptocurrency wallets.
On this fake website, there will be a dialog box to ask the user to log in to the e-wallet account. Many users who did not recognize the fake websites did not hesitate to fill in the login information, then enter the OTP password confirmation code (issued through the smartphone application) to log in to the e-wallet account.
In just a short time, hackers will use these logins (including OTP codes) to access users' e-wallets and steal all the cryptocurrencies contained therein.
In case the victim visits a fake website and creates a new e-wallet, they will be issued a Recovery Phrase (account recovery phrase, which is a 12-word string of English words that users can use to log in). to e-wallets on any device). In case the victim uses this account recovery phrase to log in, they will log into the hacker's account and any funds transferred there will actually be transferred to the hacker's digital wallet.
According to research by security experts Check Point Research, within the last few days, hackers have stolen more than $500,000 worth of cryptocurrency globally thanks to this scam.
On cryptocurrency trading groups in Vietnam, many people have also reflected that they lost all their crypto in their wallets because of the same "tricks" as Check Point Research warned.
Due to the anonymity of crypto-currency interfaces, it is impossible to identify the scammers and steal money from e-wallets, so the victims have to accept the loss of their funds. without being able to identify the culprit.
"I believe we are facing a new cybercrime trend where scammers will use Google's search engine as a means of attack, instead of email phishing like before," Oded Vanunu said. , said Check Point's Director of Vulnerability Research. "According to our observations, every hacker ad on Google is carefully keyword-selected to stand out in the search results. The phishing sites are meticulously designed and identical to each other. real website".
"I urge the crypto community to carefully check the links of the websites they visit to avoid being trapped by hackers at this time," Vanunu added.
Check Point Research's findings set off alarm bells about the quality of ads on Google, as the search engine didn't thoroughly censor the content advertised on its site.
After Check Point published a report on the cryptocurrency scam, Google immediately removed the ads of the fraudulent websites.
"This behavior violated our policies, and we immediately removed the advertising content and suspended the offending ad accounts. We are always adjusting our operating mechanisms to prevent it. these violations," a Google representative said.
According to a study by GOBankingRates, a website dedicated to rating banking and financial services, 2020 was a record year for crypto-related scams, with more than 26,500 reported scams, causing victims to lose more than 419 million USD. The number of crypto-related scams tends to continue to increase sharply in 2021. According to a survey by financial consulting firm Motley Fool, in the first quarter of 2021 alone, there were 14,079 scams. related to cryptocurrencies recorded in the US alone, causing victims to lose more than 215 million USD.
You should read it
- The biggest problem with Facebook's electronic currency: Trust
- Detecting new electronic phishing malware, redirecting payment transactions to attackers
- 'People play' electricity from nuclear power plants to exploit electronic money
- US $ 1.7 billion of electronic money was beaten by hackers in 2018
- 7 best safety wallets for Bitcoin and other electronic currencies
- Chia Network launched an electronic money development contest with a total prize value of up to 2.3 billion VND
- 32 million dollars 'evaporated' in the hack of Bitpoint electronic money trading floor
- President Trump: 'I'm not a fan of Bitcoin or any other electronic money'
May be interested
- Google's free services are exploited by hackers for phishing campaignshackers are taking advantage of free users' services and tools to create phishing campaigns. based on the reputation and popularity of google, hackers easily steal login information or trick users into installing malware.
- Free Games on Steam: Hackers' New Dangerous Traphackers exploit free games on steam to steal passwords, valve warns affected users.
- Super hackers steal tens of millions of credit card datain the biggest bank card theft in the united states, 28-year-old hackers were fined $ 2.7 million and have the ability to 'peel off the calendar' for decades in prison.
- Appearing software to help hack iCloud easierrussian company phone breaker software elcomsoft can help hackers quickly steal data that you store on icloud by allowing hackers to quickly select the files they want to steal instead of having to download all the data that could be lost. many hours.
- How to turn off Java to improve securitythe us department of homeland security has just advised internet users to turn off java on their browsers. the reason given is that a lot of vulnerabilities in this tool can cause hackers to steal important information.
- How scary is the poison VX, the most terrifying neurotoxin in the world?vx is a neurotoxin that is considered to be the most powerful man ever created. it is 100 times stronger than srarin - a deadly poison in minutes in very small doses. the united nations has classified this poison as a list of weapons of mass destruction.
- Classify hackers and career opportunities for true hackersmust white hat hackers, black hat hackers, gray-hat hackers have to be all kinds of hackers in the world? let's find out the hacker classification in this article.
- Test your understanding about hackinghacker is a job that brings a lot of income and is loved by many people. to become a true hacker you need to cultivate a lot of useful knowledge. the network administrator's quiz below will help you gain the knowledge to start your career as a hacker.
- Dangerous security flaw allows hackers to monitor Wi-Fi networks and steal informationaccording to techradar, a serious security flaw has just been discovered in the ieee 802.11 wi-fi standard that can be easily exploited by hackers to infiltrate and secretly spy on users' networks.
- Hackers can spy on Samsung users with pre-installed appssergey toshin - founder of oversecure company specializing in mobile application security, has found more than a dozen vulnerabilities affecting samsung devices, allowing hackers to steal information and track users.