Cisco and the Ukrainian cyber police revealed a phishing scheme for $ 50 million # Daily news of cryptocurrency 15/02/18

in #news6 years ago

The company Cisco and the Department of Cyber Police of the National Police of Ukraine uncovered a major fraudulent scheme, during which more than $ 50 million was stolen over the past three years, according to a report from the intelligence team Talos of Cisco.

Talos first began to study the phishing threat on February 24, 2017, when the phishing scheme, located in Ukraine, COINHOARDER, concentrated on the service of purses blockchain.info. Malicious phishing links spread through Google Ads and processed about 200,000 search queries.

Hosted ads on Google outwardly represented an almost original blockchain.info purse, also used very similar to the official website name and address, for example, blockchein.info. The phishing sites themselves, except for the domain name, completely coincided in appearance with the original. At the same time, the Talos team writes that the phishing sites of COINHOARDER became more convincing over time, which the attackers sought to use fraudulent SSL certificates in conjunction with "taipsquatting" (registration of domain names similar to the original), brand interception and homographic attack. "

The investigation showed that the scammers were aimed at regions with unstable local currencies, for residents whose English language is not native. Victims of fraud, for example, from Nigeria and Ghana, did not notice any small differences with the original service site for cryptotics.

A joint investigation by Cisco and Ukrainian cyberpolicy has made it possible to identify the bitcoin fraudsters purse. Talos writes that "about $ 10 million" was stolen only during observations of transactions from September to December 2017.

After detecting such a large-scale phishing scheme, Cisco began marking similar domains as suspicious and sending DNS queries for the search and blocking of other sites registered by this user. The Talos report ends with a set of IP addresses, where the participants of the phishing scheme were exposed, as well as recommendations to Internet users on protection from such threats.

Meanwhile, the crypto phishing scam is getting more and more widespread on Twitter, where fake pages and jokes appear on behalf of such crypto stars as Charlie Lee or Vitalik Buterin.

A source: bitnovosti.com