Cyber Hacking News

Hackers steal $3 million by impersonating crypto news journalists

0

A hacking group named ‘Pink Drainer’ has been impersonating journalists in phishing attacks to compromise Discord and Twitter accounts and steal cryptocurrency.

According to ScamSniffer analysts, Pink Drainer compromised the accounts of 1,932 victims to steal around $2,997,307 worth of digital assets on the Mainnet and Arbitrum.

The on-chain monitoring bots of Scamsniffer captured the threat actor when they stole $327,000 worth of NFTs from a single person.

Some of the hacker’s recent targets include the CTO of OpenAI Mira Murati, Steve Aoki, Evmos, Pika Protocol, Orbiter Finance, LiFi, Flare Network, Cherry Network, and Starknet.

Pink Drainer hijacks accounts through social engineering techniques, in which the threat actors spend few days impersonating journalists from popular media outlets like Cointelegraph and Decrypt to conduct interviews with the victims.

After attaining their victim’s trust, the threat actors askthe targets to conduct a KYC (know your customer) validation to prove their identity, leading them to websites used to steal Discord authentication tokens.

These sites impersonate malicious bots such as a Carl verification bot, where they are told to add bookmarks containing malicious JavaScript code using a “Drag Me” button on the malicious page.

This code steals Discord tokens, allowing the threat actors to hijack the accounts without knowing the user credentials or having a way to intercept the two-factor authentication code.

The attackers set themselves as administrators and removed all other administrators to steal digital assets and sensitive information.

If the account belongs to a renowned project or person having many followers, the attackers use their access to it to promote fake giveaways, fake mints, cryptocurrency scams, and phishing pages.

Pink Drainer is still active and so high-profile digital asset holders must stay vigilant. If a journalist approaches you, contact the media outlet via the details provided on their official website, and verify that the message originates from them.

Cryptocurrency investors must not automatically trust promotions posted by legitimate accounts. Instead, confirm the authenticity of giveaways and token drops by checking the platform’s website and other social media channels.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Over 60,000 Android apps installed adware for past six months

Previous article

Swiss Government hit by series of cyber-attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *