Good day everyone,
I hope you are all having a good day, welcome to CryptoGod-1's blog on all things crypto related. In this post I will delve into the recent news that scammers managed to make more than $59m from victims as part of their “crypto drainer” malware scams on Google Ads and X.
Crypto Drainers
According to security researchers Scam Sniffer, a new series of “crypto drainer” malware attacks have been operational for around the past nine months or so which made use of a service known as “MS Drainer” to siphon about $59 million worth of crypto from numerous victims. This was done by luring the victims to phishing pages via Google and X (formerly Twitter) ads.
A crypto drainer is a form of malware which misleads the user into approving a transaction which then automatically drains their cryptocurrency wallets of all tokens. Scam Sniffer noted how one particular version of crypto drainer, known as "MS Drainer," was behind the new spate of attacks. The victims would click on a Google or X ad which was linked to the DeFi keywords Zapper, Lido, Stargate, Defillama, Orbiter Finance and Radiant. From there they would be taken to the counterfeit phishing pages of those sites and their crypto wallets would be infected with the malware once the users approved a transaction.
These malicious ads were first detected in March and make use of a sophisticated system to ensure users get duped. It was SlowMist security platform who assisted Scam Sniffer in the investigation, and the scammers use techniques which ensure they bypass ad audits by targeting specific regions and making use of “redirect deception” to take users to phishing sites. This means the ad will not always redirect users to a malicious domain. Instead the redirect happens randomly meaning sometimes it is on the first click, and other times it happens after multiple clicks. This enabled scammers to post fake ads as part of their phishing scam.
These scams open paths to a wide variety of cyber threats which include watering hole attacks, drive-by downloads, and phishing. Basically this means that hackers can easily deliver malicious payloads on a user’s browser when they visit a malicious domain. With the high level of threats out there, the malware can even be sent directly to a users browser cache to exfiltrate sensitive information, such as passwords and credentials.
Scan Sniffer noted that there have been around 10,000 phishing sites since March which make use of these drainers, with about 63,210 victims over the past nine months from MS Drainer alone. This has resulted in $59million being stolen from the victims in digital currency. They also noted that around 60% of phishing ads on X take users to malware designed to steal their virtual currency. The peak of the drainer scams happened in November but has declined since. Without over $1 Billion lost in 2022 thanks to various crypto scams, the scammers are becoming more advanced and intelligent every day. Ensuring users remain vigilant is the only way for users to protect themselves from these malicious attempts. There are some tips for helping to ensure users can stay protected, such as using adblockers and multi-factor authentication for cryptocurrency wallets.
Scam Sniffer also managed to locate the MS drainer for sale on a dark web forum. The developers charge a 20% fee for the use of the drainer, and the MS Drainer’s administrators sell the source code direct to all-comers. The flat fee price, according to the report, was set at $1,499.99, with additional “modules” being offered at varying prices. The security firm advised users to remain cautious when interacting with online advertising, while also noting the ad industry needs to up its game.
“As can be seen, advertising has become an important means for phishing scammers to reach their victims. By targeting specific audiences through Google search terms and the following base of X, they can select specific targets and launch continuous phishing campaigns at a very low cost.”
Have a great day,
Peace. CryptoGod-1.
Referral Links and Follow Me: