- Cofense warns of a running phishing -campaign
- Threat actors mimic binance and promise their victims $ trump -coins
- The victims are lured to download Connectwise Rat
Cyber criminals take advantage of “Trump Coin -Dille to steal people’s information and possibly other cryptocurrencies, Cofense has warned.
Earlier this year, US President Donald Trump launched a “Memecoin” (a cryptocurrency coin for fun) called $ Trump. After launching, the price of the token rose by over 300% overnight.
Within two days, the 19th most valuable cryptocurrency was globally, with a total trade value approaching $ 13 billion based on a value of $ 64 per year. Token for the 200 million tokens issued in the afternoon of January 19.
Connection rat
These kinds of events are golden opportunities for cyber criminals. As reported by Cofense, the threat actors made a fake Binance site that – though not perfect – does a good job of pretending to be the popular cryptocurrency exchange. The attackers then sent out phishing -e emails and told their victims that they could redeem recently created $ Trump coins, but only if they move quickly and download “Binance Desktop”.
Instead of actually getting Exchange’s Desktop client, the victims would install Connectwise Rat -a sometime -Legitim Remote Desktop Manager (RDM) utilized by cyber criminals to act as malware. As soon as the fake software is installed, the attackers would move in and try to take over the device.
This is something unusual, Cofense said, as the threat actor in most connection cases would interact with the victim after some time had passed. In any case, the rat is then used to exfilter passwords stored in Microsoft Edge and other programs and applications supported by Trojan.
Phishing campaigns often utilize current events as they help create a sense of urgent character. Fast-selling tickets for events such as the Olympics or World Cup, Black Friday deals or cryptocurrency-tokens, which rises rapidly in prices, can trigger FOMO with consumers, making them ideal foundations for a scam campaign.