Security News > 2022 > October > Hackers are breaching scam sites to hijack crypto transactions

Hackers are breaching scam sites to hijack crypto transactions
2022-10-04 18:20

In a perfect example of there being no honor among thieves, a threat actor named 'Water Labbu' is hacking into cryptocurrency scam sites to inject malicious JavaScript that steals funds from the scammer's victims.

In July, the FBI warned of scam 'dApps' that impersonated cryptocurrency liquidity mining services but, in reality, stole a victim's crypto investments.

Instead of creating their own scam sites, Water Labbu hacks into these types of fake dApp sites and injects JavaScript code into site's HTML. The hackers do not engage with the victims and instead leave all the social engineering work to the scammers.

The script monitors newly connected wallets on the scam sites and retrieves the address and balances of TetherUSD and Ethereum wallets.

For Windows users, the hacked sites will show a fake Flash Player update notice overlayed on the scam site instead. The Flash installer is, in reality, a backdoor fetched directly from GitHub.

Periodically review your wallet's allowed sites to make sure you did not inadvertently add a scam site.


News URL

https://www.bleepingcomputer.com/news/security/hackers-are-breaching-scam-sites-to-hijack-crypto-transactions/