The post Ledger CTO Issues Phishing Warning After Fake Podcast Scam Attempt appeared on BitcoinEthereumNews.com. How attack worked  Malware-as-a-service Charles Guillemet, chief technology officer at hardware manufacturer Ledger, recently spotlighted a sophisticated phishing attack targeting Ethereum developer Zak Cole. Guillemet has warned users against storing keys on their computers to avoid becoming the victim of such an attack.  How attack worked  The malicious actor in question posed as a legitimate contact from a popular podcast in order to gain trust.  The attacker sent an email with a link to StreamYard, a popular webinar platform. This was followed by a typical step for such attacks: the landing page showed a fake error and prompted the targeted developer to download a desktop app with rather suspicious insistence. Cole, who already lost some of his crypto holdings to scammers earlier this year, downloaded a macOS installer file to a separate test machine and (unsurprisingly) ended up finding a fake program with a script and a fake Terminal icon that was meant to run the hidden script. You Might Also Like   The malicious malware was meant to grab wallet files, messages, photos, as well as other files from the computer of the potential victim and send back whatever it stole to the servers operated by the attacker. Malware-as-a-service The most surprising development was finding out that the attacker in question was actually operating rented malware that they were able to profitably use for just $3,000 per month.  According to Cole, this shows that “malware-as-a-service” is turning into a burgeoning industry, and even low-skill actors can now get their hands on commodity malware.  Source: https://u.today/ledger-cto-issues-phishing-warning-after-fake-podcast-scam-attemptThe post Ledger CTO Issues Phishing Warning After Fake Podcast Scam Attempt appeared on BitcoinEthereumNews.com. How attack worked  Malware-as-a-service Charles Guillemet, chief technology officer at hardware manufacturer Ledger, recently spotlighted a sophisticated phishing attack targeting Ethereum developer Zak Cole. Guillemet has warned users against storing keys on their computers to avoid becoming the victim of such an attack.  How attack worked  The malicious actor in question posed as a legitimate contact from a popular podcast in order to gain trust.  The attacker sent an email with a link to StreamYard, a popular webinar platform. This was followed by a typical step for such attacks: the landing page showed a fake error and prompted the targeted developer to download a desktop app with rather suspicious insistence. Cole, who already lost some of his crypto holdings to scammers earlier this year, downloaded a macOS installer file to a separate test machine and (unsurprisingly) ended up finding a fake program with a script and a fake Terminal icon that was meant to run the hidden script. You Might Also Like   The malicious malware was meant to grab wallet files, messages, photos, as well as other files from the computer of the potential victim and send back whatever it stole to the servers operated by the attacker. Malware-as-a-service The most surprising development was finding out that the attacker in question was actually operating rented malware that they were able to profitably use for just $3,000 per month.  According to Cole, this shows that “malware-as-a-service” is turning into a burgeoning industry, and even low-skill actors can now get their hands on commodity malware.  Source: https://u.today/ledger-cto-issues-phishing-warning-after-fake-podcast-scam-attempt

Ledger CTO Issues Phishing Warning After Fake Podcast Scam Attempt

  • How attack worked 
  • Malware-as-a-service

Charles Guillemet, chief technology officer at hardware manufacturer Ledger, recently spotlighted a sophisticated phishing attack targeting Ethereum developer Zak Cole.

Guillemet has warned users against storing keys on their computers to avoid becoming the victim of such an attack. 

How attack worked 

The malicious actor in question posed as a legitimate contact from a popular podcast in order to gain trust. 

The attacker sent an email with a link to StreamYard, a popular webinar platform.

This was followed by a typical step for such attacks: the landing page showed a fake error and prompted the targeted developer to download a desktop app with rather suspicious insistence.

Cole, who already lost some of his crypto holdings to scammers earlier this year, downloaded a macOS installer file to a separate test machine and (unsurprisingly) ended up finding a fake program with a script and a fake Terminal icon that was meant to run the hidden script.

You Might Also Like

 

The malicious malware was meant to grab wallet files, messages, photos, as well as other files from the computer of the potential victim and send back whatever it stole to the servers operated by the attacker.

Malware-as-a-service

The most surprising development was finding out that the attacker in question was actually operating rented malware that they were able to profitably use for just $3,000 per month. 

According to Cole, this shows that “malware-as-a-service” is turning into a burgeoning industry, and even low-skill actors can now get their hands on commodity malware. 

Source: https://u.today/ledger-cto-issues-phishing-warning-after-fake-podcast-scam-attempt

Market Opportunity
Union Logo
Union Price(U)
$0.002531
$0.002531$0.002531
+4.54%
USD
Union (U) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.