• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
inferno malware masqueraded as coinbase, drained $87 million from 137,000

Inferno Malware Masqueraded as Coinbase, Drained $87 Million from 137,000 Victims

You are here: Home / General Cyber Security News / Inferno Malware Masqueraded as Coinbase, Drained $87 Million from 137,000 Victims
January 16, 2024

The operators behind the now-defunct Inferno Drainer produced much more than 16,000 unique destructive domains more than a span of a single year among 2022 and 2023.

The plan “leveraged high-excellent phishing internet pages to entice unsuspecting users into connecting their cryptocurrency wallets with the attackers’ infrastructure that spoofed Web3 protocols to trick victims into authorizing transactions,” Singapore-headquartered Team-IB stated in a report shared with The Hacker News.

Cybersecurity

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Inferno Drainer, which was lively from November 2022 to November 2023, is approximated to have reaped in excess of $87 million in illicit revenue by scamming more than 137,000 victims.

The malware is section of a broader established of identical offerings that are offered to affiliates under the fraud-as-a-services (or drainer-as-a-service) design in trade for a 20% slash of their earnings.

What is much more, consumers of Inferno Drainer could either upload the malware to their personal phishing web-sites, or make use of the developer’s provider for developing and hosting phishing internet sites, possibly at no more price or charging 30% of the stolen property in some circumstances.

According to Team-IB, the activity spoofed upwards of 100 cryptocurrency brand names by using specially crafted web pages that had been hosted on above 16,000 unique domains.

Further more investigation of 500 of these domains has revealed that the JavaScript-primarily based drainer was hosted initially on a GitHub repository (kuzdaz.github[.]io/seaport/seaport.js) ahead of incorporating them straight on the sites. The consumer “kuzdaz” at present does not exist.

In a equivalent trend, an additional set of 350 web sites bundled a JavaScript file, “coinbase-wallet-sdk.js,” on a diverse GitHub repository, “kasrlorcian.github[.]io.”

These web sites had been then propagated on web sites like Discord and X (previously Twitter), attractive opportunity victims into clicking them below the guise of supplying cost-free tokens (aka airdrops) and connecting their wallets, at which issue their belongings are drained after the transactions are accepted.

Cybersecurity

In working with the names seaport.js, coinbase.js and wallet-connect.js, the notion was to masquerade as well-liked Web3 protocols like Seaport, WalletConnect, and Coinbase to full the unauthorized transactions. The earliest web site that contains a person of these scripts dates back to Could 15, 2023.

“Another regular element of phishing web sites belonging to Inferno Drainer was that buyers are not able to open up web page source code by working with hotkeys or suitable-clicking on the mouse,” Team-IB analyst Viacheslav Shevchenko reported. “This implies that the criminals tried to hide their scripts and unlawful exercise from their victims.”

It is worth noting that Google-owned Mandiant’s X account was compromised previously this thirty day period to distribute links to a phishing website page hosting a cryptocurrency drainer tracked as CLINKSINK.

“Inferno Drainer may possibly have ceased its activity, but its prominence all through 2023 highlights the severe threats to cryptocurrency holders as drainers continue on to build more,” Andrey Kolmakov, head of Team-IB’s High-Tech Criminal offense Investigation Section, mentioned.

Uncovered this post appealing? Follow us on Twitter  and LinkedIn to examine far more exclusive material we post.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «hackers weaponize windows flaw to deploy crypto siphoning phemedrone stealer Hackers Weaponize Windows Flaw to Deploy Crypto-Siphoning Phemedrone Stealer
Next Post: Case Study: The Cookie Privacy Monster in Big Global Retail case study: the cookie privacy monster in big global retail»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.