|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
仮想通貨を求める攻撃者は、プラットフォームではなくユーザーをターゲットにすることに重点を移し、Twitter などのソーシャル メディアを使用して仮想通貨詐欺やマルウェアを促進しています。 2024 年第 1 四半期には、zkSync や Inscribe などの企業になりすました 1,500 を超える偽アカウントが検出されました。証券取引委員会やマンディアントなどの主要なソーシャルアカウントも、不正な暗号通貨のオファーを促進するために侵害されています。

Cryptocurrency Scammers Shift Tactics, Targeting Users Directly
暗号通貨詐欺師は戦術を変え、ユーザーを直接標的にする
Attackers Targeting Social Media Accounts for Cryptocurrency Scams
仮想通貨詐欺でソーシャルメディアアカウントを狙う攻撃者
Sophisticated threat actors are increasingly targeting cryptocurrency users on social media, according to a recent study by cybersecurity firm Cyjax. The criminals are employing a mix of fake impersonator accounts and malware to promote fraudulent cryptocurrency offers and steal victims' funds.
サイバーセキュリティ企業Cyjaxによる最近の調査によると、高度な攻撃者がソーシャルメディア上の仮想通貨ユーザーをターゲットにするケースが増えているという。犯罪者は、偽のなりすましアカウントとマルウェアを組み合わせて、不正な暗号通貨のオファーを促進し、被害者の資金を盗んでいます。
In the first quarter of 2024, Cyjax detected 1,517 fake accounts on Twitter promoting cryptocurrency scams, with companies including zkSync, Inscribe, and Optimism being targeted for impersonation. More alarmingly, major social media accounts for the Securities & Exchange Commission and Mandiant were compromised and used to promote bogus cryptocurrency investment schemes.
2024 年の第 1 四半期に、Cyjax は、仮想通貨詐欺を宣伝する 1,517 個の偽アカウントを Twitter 上で検出し、zkSync、Inscribe、Optimism などの企業がなりすましの標的となっています。さらに憂慮すべきことに、証券取引委員会とマンディアントの主要なソーシャル メディア アカウントが侵害され、偽の仮想通貨投資スキームを宣伝するために使用されました。
Subtle Typosquatting and Link Redirection
微妙なタイポスクワッティングとリンクのリダイレクト
One notable incident involved a fake account impersonating the well-known cryptocurrency trader "Ansem" on Twitter. The account used a subtle typosquatting technique to respond to tweets from the legitimate Ansem account, who had announced a presale of a new token called $BULL. The malicious account's link redirected victims to a "wallet drainer" website, designed to steal cryptocurrency assets. As a result, over $2.6 million was stolen, with one victim losing a staggering $1.2 million.
注目すべき事件の 1 つは、Twitter 上で有名な仮想通貨トレーダー「アンセム」になりすました偽アカウントに関するものでした。このアカウントは、$BULL と呼ばれる新しいトークンの先行販売を発表した正規の Ansem アカウントからのツイートに応答するために、巧妙なタイポスクワッティング手法を使用しました。悪意のあるアカウントのリンクは、仮想通貨資産を盗むことを目的とした「ウォレットドレイナー」Web サイトに被害者をリダイレクトしました。その結果、260万ドル以上が盗まれ、被害者の1人はなんと120万ドルを失いました。
Enhanced Romance Scams and Phishing Attacks
強化されたロマンス詐欺とフィッシング攻撃
Cyjax also reports a surge in "pig butchering" scams, a sophisticated type of romance scam that involves building trust with victims over time before urging them to invest in fraudulent cryptocurrency schemes. These scams have resulted in millions of dollars in losses for unsuspecting victims.
Cyjaxはまた、「豚解体」詐欺の急増も報告している。これは、時間をかけて被害者との信頼を築き、その後、詐欺的な仮想通貨スキームへの投資を促す、洗練されたタイプのロマンス詐欺である。これらの詐欺は、疑いを持たない被害者に数百万ドルの損失をもたらしました。
Phishing attacks have also become more prevalent, with attackers exploiting vulnerabilities in email service providers to impersonate web3 companies. In one such attack, a hacker stole over $600,000 by impersonating a legitimate web3 company and sending phishing emails to victims.
フィッシング攻撃も蔓延しており、攻撃者は電子メール サービス プロバイダーの脆弱性を悪用して Web3 企業になりすましています。このような攻撃の 1 つでは、ハッカーが正規の Web3 企業になりすましてフィッシングメールを被害者に送信することで、60 万ドル以上を盗みました。
Drainer Malware on the Rise
ドレイナーマルウェアが増加中
Cyjax notes a concerning trend in the use of drainer malware by cryptocurrency phishing threat actors. This type of malware does not require the attacker to directly convince the victim to send funds. Instead, it only requires the victim to connect their cryptocurrency wallet to the malicious code, which then drains the victim's funds. In one instance, a victim lost 111.6 million ALI tokens, valued at approximately $4.3 million, due to this type of malware.
Cyjax は、仮想通貨フィッシングの脅威アクターによるドレイナー マルウェアの使用に関する懸念すべき傾向を指摘しています。このタイプのマルウェアでは、攻撃者が被害者に資金を送金するよう直接説得する必要はありません。代わりに、被害者は自分の暗号通貨ウォレットを悪意のあるコードに接続するだけで、被害者の資金が流出します。ある例では、このタイプのマルウェアにより、被害者は約 430 万ドル相当の 1 億 1,160 万の ALI トークンを失いました。
Prevention and Awareness
予防と啓発
Cyjax emphasizes that user-oriented attacks have been a persistent threat to cryptocurrency users since the inception of digital currencies. However, recent market fluctuations and the ease with which scams can be carried out on platforms like Twitter have made these threats particularly prevalent in the first quarter of 2024.
Cyjax は、デジタル通貨の誕生以来、ユーザー指向の攻撃が暗号通貨ユーザーに対する継続的な脅威であったことを強調しています。ただし、最近の市場の変動と、Twitter などのプラットフォームで詐欺が簡単に実行できることにより、2024 年の第 1 四半期にはこれらの脅威が特に蔓延しました。
To protect themselves, cryptocurrency users are urged to be wary of unsolicited offers or investment advice on social media. They should also be cautious when connecting their wallets to websites or services, particularly if they are prompted to do so through a link in an email or social media message.
自分自身を守るために、仮想通貨ユーザーはソーシャルメディア上の一方的なオファーや投資アドバイスに注意するよう求められています。また、ウォレットを Web サイトやサービスに接続するとき、特に電子メールやソーシャル メディア メッセージ内のリンクを通じて接続するよう促された場合には、注意する必要があります。
Social media platforms have a responsibility to combat the proliferation of fraudulent accounts and malicious content. They should implement robust security measures and cooperate with law enforcement agencies to identify and shut down illicit activity.
ソーシャル メディア プラットフォームには、詐欺アカウントや悪意のあるコンテンツの蔓延と戦う責任があります。強力なセキュリティ対策を実施し、法執行機関と協力して違法行為を特定し阻止する必要があります。
By staying informed and exercising caution, cryptocurrency users can mitigate the risks of falling victim to these sophisticated scams.
常に情報を入手し、注意を払うことで、暗号通貨ユーザーはこれらの巧妙な詐欺の被害に遭うリスクを軽減できます。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































