HT TECH wants to start sending you push notifications. Click allow to subscribe

Coinbase, Gemini to MetaMask- Crypto Scammers Use Fake Websites to Dupe Customers

Illicit scheme involves exploiting SEO and using live chats, researchers say.

By: BLOOMBERG
Updated on: Sep 10 2022, 21:11 IST
Crypto Scammers Use Fake Websites in Latest Bid to Dupe Customers (REUTERS)

Scammers in recent weeks have employed up fake cryptocurrency web pages to attempt to steal money from users, the latest tactic to emerge in what’s already been a costly year for crypto-related hacks.

The sham websites – which masquerade as pages for popular services such as Coinbase, Gemini, Kraken and MetaMask – aim to dupe visitors into providing information that helps hackers break into their cryptocurrency wallets, according to researchers from the security firm Netskope Inc. Fraudsters deployed search-engine optimization tactics to promote the websites, which used URL addresses that closely resembled the legitimate sites and propelled the fake pages to the first page of Google’s search results, the researchers said.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Google searches for phrases such as “kraken wallet” or “coinbase not working,” in the event the Coinbase site appears to be down, return results with the phishing links on the first page, according to a Bloomberg analysis. A fraudulent version of the Kraken wallet appeared in a Google search in a more prominent position than Kraken’s Twitter feed and Play store app.

Also read: Looking for a smartphone? To check mobile finder click here.

In another case, a Google search for the “metamask ios” app yielded results that included one website that five popular antivirus services flagged as malicious, according to the Bloomberg analysis.

“A lot of people are making fake versions of real websites and directing users to those pages so they can take their money,” Erin Plante, senior director of investigations at the blockchain-analysis firm Chainalysis Inc., adding that such techniques have been used in other types of cyberattacks. “A lot of this is age-old hacking. ”

The findings come amid a flurry of security incidents in cryptocurrency. Financial losses from cryptocurrency-related hacks totaled $1.9 billion in the first seven months of this year, according to Chainalysis. Hackers stole $1.2 billion over the same period in 2021, the company said.

Users that clicked on the fake websites were met with messages asking them to participate in a live Q&A with a scammer who pretended to be a customer service representative from a legitimate company, Gustavo Palazolo, a security researcher at Netskope, said in an interview. During one interaction, the bogus customer service representative asked Palazolo for his phone number in an apparent attempt to locate his cryptocurrency wallet, the researcher said.

“We detect a lot of phishing pages but when I saw the live chat function, that was something that’s more serious than the usual threat,” he said. “They got back to me within a minute after I sent a message.”

The attackers duped Google’s search algorithm into including the scam pages on the first page of the search results by frequently posting malicious URLs in comment sections on little-read blogs throughout the web, Palazolo said. Repeatedly posting links increases the chances that Google will incorporate the URL into its results, he said, adding that the scammers also used Google Sites, a web creation tool, to create their malicious pages, giving the sites an air of credibility.

The number of victims duped as part of the fraud effort wasn’t immediately clear.

Coinbase urged customers to remain on alert for such scams, publishing a security bulletin in July that offered tips on how to detect such fraud efforts. In a statement, a Kraken spokesperson said the company proactively identifies counterfeit websites and apps and works to take them down. The site also has a support page meant to help crypto users avoid fraud.

Neither Gemini nor MetaMask responded to requests for comment.

Numerous bogus websites flagged by Netskope disappeared from search results after Bloomberg flagged the malicious sites to Google.

“For most queries related to the mentioned topics, search results rank authoritative and reliable sources as the top results,” a Google spokesperson said in an email. “On Google Sites, we explicitly prohibit phishing and we invest heavily in detecting, deterring, and removing abuse from our platforms.”

In a separate ruse earlier this year, fraudsters impersonated journalists, crypto apps and a variety of nonfungible token projects on Twitter to steal users’ username and password credentials.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 10 Sep, 18:33 IST

Sale

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
3% OFF
Samsung Galaxy Z Fold5
  • Icy Blue
  • 12 GB RAM
  • 256 GB Storage
₹154,999₹159,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Strix G17 G712LU EV078T Laptop
  • Blue
  • 16 GB RAM
  • 1 TB SSD
₹81,990₹113,990
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
NEXT ARTICLE BEGINS