Skip to content
  Monday 12 May 2025
  • Home
  • Attack
  • Malware
  • Cloud
  • Data
  • Technology
  • World of tech
Trending
May 8, 2024Day 2 Highlights at RSA Conference 2024 February 4, 2024Satya Nadella’s first decade as Microsoft CEO was defined by cloud. What’s next? March 22, 2024Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects June 25, 2024Tesla recalls Cybertruck to fix faulty windshield wipers, loose trim June 27, 2024Why Activist Investor Jana Is Pressing Rapid7 to Sell Itself August 1, 2024Qualcomm beats estimates and phone chip sales are up 12% April 3, 2024TSMC’s evacuated workers return to some factories after Taiwan’s strongest earthquake in 25 years April 30, 2024Binance’s billionaire founder to find out if prison time is coming — here’s what lawyers are expecting May 19, 2024Microsoft set to unveil its vision for AI PCs at Build developer conference December 31, 2024Silicon Valley’s turn of fortune: Intel has worst year ever, while Broadcom enjoys record gain
  • Home
  • Attack
  • Malware
  • Cloud
  • Data
  • Technology
  • World of tech
  Attack  Crypto Scammers are Masquerading as NFT Developers
Attack

Crypto Scammers are Masquerading as NFT Developers

adminadmin—August 7, 20230
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail


Aug 07, 2023THNCyber Crime / Cryptocurrency

Crypto Scammers

The U.S. Federal Bureau of Investigation (FBI) is warning about cyber crooks masquerading as legitimate non-fungible token (NFT) developers to steal cryptocurrency and other digital assets from unsuspecting users.

In these fraudulent schemes, criminals either obtain direct access to NFT developer social media accounts or create look-alike accounts to promote “exclusive” new NFT releases, often employing misleading advertising campaigns that create a sense of urgency to pull them off.

“Links provided in these announcements are phishing links directing victims to a spoofed website that appears to be a legitimate extension of a particular NFT project,” the FBI said in an advisory last week.

The replica websites urge potential targets to connect their cryptocurrency wallets and purchase the NFT, only for the threat actors to siphon the funds and NFTs to wallets under their control.

Cybersecurity
More stories

Learn to Boost Cybersecurity with AI-Powered Vulnerability Management

September 2, 2024

Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks

April 17, 2025

Chinese Hackers Exploited FortiGate Flaw to Breach Dutch Military Network

February 7, 2024

Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability

December 3, 2024

“Contents stolen from victims’ wallets are often processed through a series of cryptocurrency mixers and exchanges to obfuscate the path and final destination of the stolen NFTs,” the agency said.

To mitigate the risks posed by such scams, it’s recommended that users carry out due diligence and review social media accounts and websites to verify their legitimacy.

The development comes nearly five months after the FBI warned of a spike in bogus cryptocurrency investment schemes called pig butchering (or shā zhū pán), leading to losses of $2 billion in 2022.

This includes a category called CryptoRom in which criminals use fictitious identities on dating apps and social media platforms to develop romantic relationships and build trust with victims, before introducing the idea of trading cryptocurrencies.

The operators are known to engage in initial conversation within the app with which they made initial contact with the target. Soon after, the chat is moved to a private messaging app such as Telegram or WhatsApp, where they encourage them to use fraudulent crypto websites or apps and make substantial investments.

Cybersecurity

“Criminals coach victims through the investment process, show them fake profits, and encourage victims to invest more,” the FBI said. “When victims attempt to withdraw their money, they are told they need to pay a fee or taxes. Victims are unable to get their money back, even if they pay the imposed fees or taxes.”

The romance-centered social engineering attacks have also gotten a facelift in recent months, with Sophos identifying apps on the Apple App Store and Google Play Store that make use of generative AI features to lend more credibility to conversations with the victims on messaging apps like WhatsApp.

“These applications are able to get past review by Apple and Google by modifying remote content associated with the apps after they are approved and published to the stores,” the cybersecurity company said.

“By simply changing a pointer in remote code, the app can be switched from a benign interface to a fraudulent one without further review by Apple or Google, unless a complaint is filed.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

admin

X, formerly Twitter, commandeers ‘@music’ handle from user with half a million followers
Shares of China’s second largest chip foundry Hua Hong jump 13% in Shanghai debut
Related posts
  • Related posts
  • More from author
Attack

Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams

May 12, 20250
Attack

Why Exposed Credentials Remain Unfixed—and How to Change That

May 12, 20250
Attack

Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures

May 12, 20250
Load more

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Malware

Google Reaches $1.4 Billion Privacy Settlement With Texas

May 12, 20250
Attack

Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams

May 12, 20250
Attack

Why Exposed Credentials Remain Unfixed—and How to Change That

May 12, 20250
Attack

Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures

May 12, 20250
Malware

Russian FSB Hackers Deploy New Lostkeys Malware

May 11, 20250
Attack

Germany Shuts Down eXch Over $1.9B Laundering, Seizes €34M in Crypto and 8TB of Data

May 10, 20250
Load more

Recent Posts

  • Google Reaches $1.4 Billion Privacy Settlement With Texas
  • Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams
  • Why Exposed Credentials Remain Unfixed—and How to Change That
  • Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures
  • Russian FSB Hackers Deploy New Lostkeys Malware

    © 2022
    • Home
    • Attack
    • Cloud
    • Data
    • Malware
    • Technology
    • World of tech
    • Privacy
    • Contact