Authored by: Neil Tyagi
Rip-off artists know no bounds—and that additionally applies to stealing your cryptocurrency. Crypto scams are like every other monetary rip-off, besides the scammers are after your crypto property fairly than your money.
Crypto scammers use many techniques in different monetary crimes, similar to pump-and-dump scams that lure traders to buy an asset with faux claims about its worth or outright makes an attempt to steal digital property.
This time scammers had been attempting to get an investor to ship a digital asset as a type of cost for a fraudulent transaction.
It begins with a Tweet used as bait to lure harmless cryptocurrency traders into buying a non-existent token, associated to a reputed firm, SpaceX.
The theme used right here by scammers is the sale of the official cryptocurrency of SpaceX. Within the above picture we will additionally see the attain of the tweet is excessive. (224.4K views)
Safety with McAfee+:
McAfee+ offers all-in-one on-line safety on your id, privateness, and safety. With McAfee+, you’ll really feel safer on-line since you’ll have the instruments, steerage, and assist to take the steps to be safer on-line. McAfee protects in opposition to a lot of these rip-off websites with Internet Advisor safety that detects malicious web sites.
The hyperlink current on this tweet redirects to house[-]launch[.]web, which is already marked as malicious by McAfee.
A WHOIS search on the location reveals it’s hosted on Cloudflare. Cloudflare has more and more turn into the primary selection for scammers to host malicious web sites and defend their property.
A WHOIS lookup on the area reveals redacted private info. No surprises there
When we click on on the hyperlink, it takes us to a login web page and asks for HouseX login credentials. This web page was designed as a phishing web page for folks who have actual SpaceX login credentials.
For individuals who don’t have SpaceX credentials, they will use the signup hyperlink.
After we log in, it redirects to a touchdown web page the place one can buy the supposedly unique cryptocurrency launched by SpaceX
As you possibly can see, it impersonates because the official SpaceX portal for getting their token. It additionally has all the weather associated to SpaceX and its branding.
In the above picture, we will see that scammers are using the social engineering trick of FOMO (Worry Of Lacking Out) as they’ve created a timer showing that the faux tokens are solely obtainable for buy for the subsequent 10 hours. This additionally makes positive that the rip-off would finish earlier than all of the on-line safety distributors flag the location.
Scammers also permit customers to buy faux tokens from about 22 cryptocurrencies, the distinguished being Bitcoin, Ethereum, and USDT.
Scammers even supply a bonus of faux SpaceX tokens if customers are able to buy a minimal quantity
Right here we will discover the BTC pockets tackle of the scammers and see the transactions associated to those wallets.
The crypto pockets addresses of scammers for the next currencies are.
- BTC bc1qhhec8pkhj2cxtk6u0dace8terq22hspxkr5pee
- USDT 398a9BF5fe5fc6CaBB4a8Be8B428138BC7356EC1
- ETH 16a243E3392Ffd9A872F3fD90dE79Fe7266452F9
Taking a look at transactions associated to those addresses, we discover folks have turn into victims of this rip-off by sending funds to those wallets. The Bitcoin pockets above has gathered round 2,780 US dollars. You may as well see three of the final transactions made to the account.
Equally, for Ethereum, the scammers have gathered round 1,450 US {dollars}
We noticed two fashionable cryptocurrencies, however scammers are utilizing about 22 completely different crypto wallets.
Crypto phishing scams continuously evolve, and new techniques emerge repeatedly. Customers ought to take the initiative to coach themselves concerning the newest phishing methods and scams concentrating on the cryptocurrency neighborhood. Additionally, keep knowledgeable by researching and studying about latest phishing incidents and safety finest practices.
IOC (Indicator of Compromise)
Area | Crypto Kind | Pockets tackle |
house[-]launch[.]web | BTC | bc1qhhec8pkhj2cxtk6u0dace8terq22hspxkr5pee |
house[-]launch[.]web | USDT | 398a9BF5fe5fc6CaBB4a8Be8B428138BC7356EC1 |
house[-]launch[.]web | ETH | 16a243E3392Ffd9A872F3fD90dE79Fe7266452F9 |
house[-]launch[.]web | XRP | rnmj4xsaaEaGvFbrsg3wCR6Hp2ZvgjMizF |
house[-]launch[.]web | DASH | XxD3tJ7RA81mZffKFiycASMiDsUdqjLFD1 |
house[-]launch[.]web | BCH | qr45csehwfm5uu9xu4mqpptsvde46t8ztqkzjlww68 |
house[-]launch[.]web | USDC | 0x398a9BF5fe5fc6CaBB4a8Be8B428138BC7356EC1 |