Tag Archive for: Crypto

Apple Users' Privacy & Security Under Threat!



Fake Binance NFT Mystery Box bots steal victim’s crypto wallets


GB Master Kung Mystery Box
Source: ITAMGamesInc

A new RedLine malware distribution campaign promotes fake Binance NFT mystery box bots on YouTube to lure people into infecting themselves with the information-stealing malware from GitHub repositories.

Binance mystery boxes are sets of random non-fungible token (NFT) items that people buy, hoping they’ll receive a unique or rare item at a bargain price. Some of the NFTs found in these boxes can be used to add rare cosmetics or personas within online blockchain games.

Mystery boxes are trendy in the NFT market because they give people the joy of the unknown and the potential for a big payday if they land a rare NFT. However, marketplaces like Binance offer them in limited numbers, making some boxes hard to get before they run out of stock.

This is why interested buyers often deploy “bots” to acquire them, and it’s precisely this hot trend that the threat actors are trying to take advantage of.

YouTube and GitHub abuse

According to a new report by Netskope, threat actors are creating YouTube videos to entice potential victims into downloading and installing the malware on their computer, thinking they’re getting a free mystery box scalper bot.

Malicious YouTube videos
Malicious YouTube videos (Netskope)

BleepingComputer confirmed that the videos listed in the indicators of compromise are still available on YouTube, albeit having a low number of views. 

There likely are many more than those spotted by Netskope, and it’s also possible that previous scam videos with a higher number of views were reported and taken down by YouTube moderators.

The threat actors uploaded the videos between March and April 2022, and they all feature a link to a GitHub repository that supposedly hosts the bot but, in reality, distributes RedLine.

Video description leading to a GitHub download
Video description leading to a GitHub download (Netskope)

The name of the dropped file is “BinanceNFT.bot_v1.3.zip”, containing a similarly-named executable, which is the payload, a Visual C++ installer, and a README.txt file.

Files contained in the dropped ZIP archive
Files contained in the dropped ZIP 
(Netskope)

RedLine requires the VC redistributable installer to run since the program is developed in .NET, while the text file contains the installation instructions for the victim.

Readme file instructions
Readme file…

Source…

Fake crypto giveaways steal millions using Elon Musk Ark Invest video


Fake crypto giveaways reuse YouTube videos of Musk, Dorsey to make millions

Fake cryptocurrency giveaways are stealing millions of dollars simply by replaying old Elon Musk and Jack Dorsey Ark Invest videos on YouTube.

The scheme is the old “double your investment” ruse that promises to pay back twice the cryptocurrency amount the victim sends the scammer.

The fraudsters made more than $1.3 million after re-streaming an edited version of an old live panel discussion on cryptocurrency with Elon Musk, Jack Dorsey, and Cathie Wood at Ark Invest’s “The ₿ Word” conference.

In the past, scammers used other videos related to Elon Musk, including SpaceX launches or Tesla videos, to successfully promote fake giveaways and steal millions of dollars while doing so.

Simple operation

At a quick search, BleepingComputer found that close to 10 YouTube channels have published the discussion, albeit in a smaller format edited to include additional elements that promoted the scam, including the link to the fraudulent crypto giveaway website.

Our findings are just a glimpse of the entire scheme, which we observed unfold since March. However, there are reports of it going as far back as January and bringing scammers $400,000 in just seven hours

Security researchers at cybersecurity firm McAfee were also monitoring the scam and published a report on Thursday in which they identified 11 fraudulent websites.

Fraudulent websites hosting crypto scam
source: McAfee

McAfee updated the post the next day saying that the number of these websites had increased to 26 in just 24 hours.

“The YouTube streams advertised several sites which shared a similar theme. They claim to send cryptocurrency worth double the value which they’ve received. For example, if you send 1BTC you will receive 2BTC in return” – McAfee

However, these websites appear every day and scammers generate new wallets to receive funds from gullible cryptocurrency users. Here’s some that BleepingComputer and…

Source…