Cyber Attacks

New MetaMask phishing campaign uses KYC lures to steal passphrases

0

A new phishing campaign is targeting Microsoft 365 users while spoofing the popular MetaMask cryptocurrency wallet provider and attempting to steal recovery phrases.

MetaMask recovery phrases, or seeds, are a series of 12 words that users can use to import an existing crypto wallet on other devices. Those who have access to this recovery phrase can import the wallet on any device they wish to and steal the NFTs and cryptocurrency stored within it, making them a popular target for threat actors.

According to email security firm Armoblox, the new campaign targets users of Microsoft Office 365, distributing messages that seems legitimate identity verification requests.

The phishing email, appears to be from MetaMask support, spoofs a Know Your Customer (KYC) verification request and features convincing branding and no typos or other obvious scam giveaways.

KYC requests are part of standard anti-money laundering legal obligations financial companies must abide by, so receiving a request would be usual.

The real MetaMask does not require its users to provide KYC details, so dealing with verification requests can be a frustrating experience, possibly causing recipients to be less cautious.

The phishing actors even give the recipients a deadline of up to a whole month to take action to verify themselves, which again makes the user believe that it is legitimate as phishing attempts usually involve urgency.

If the victims click the embedded button, they are taken to a fake landing page that looks like the actual MetaMask website.

The phishing site also warns the visitors to ensure that their passphrase is always adequately protected.

The actual MetaMask domain is “metamask.io,” whereas the phishing page uses “metamask.io-integrated-status.com,” which again looks like a genuine one.

When the victims enter their passphrase on the phishing site, the threat actors receive it, and usually it does not take long for the adversaries to take action and steal the victim’s available funds and NFTs.

The users must be cautious when they receive such emails. In case you receive emails that make serious claims about the status of your accounts, ignore the embedded buttons or URLs and instead visit the platform directly from a new tab, login to your account, and check for any alerts requiring your attention.

Always make sure to verify the domain in which you are going to enter credentials is the correct one. And always enable multi-factor authentication (MFA) on all online accounts where the security measure is offered as an option.

Image Credits : Piunikaweb

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Chinese hackers target script kiddies with info-stealer trojan

Previous article

Mitel zero-day exploited by hackers to deploy ransomware

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *