市值: $2.8531T -1.56%
成交额(24h): $79.1889B 54.08%
  • 市值: $2.8531T -1.56%
  • 成交额(24h): $79.1889B 54.08%
  • 恐惧与贪婪指数:
  • 市值: $2.8531T -1.56%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$83049.881944 USD

-1.68%

ethereum
ethereum

$2647.419272 USD

-2.15%

tether
tether

$0.999568 USD

-0.02%

bnb
bnb

$762.972281 USD

-1.56%

xrp
xrp

$1.479864 USD

-2.79%

usd-coin
usd-coin

$0.999936 USD

0.00%

solana
solana

$118.546682 USD

-2.33%

tron
tron

$0.333632 USD

0.14%

zcash
zcash

$1545.886176 USD

-7.02%

hyperliquid
hyperliquid

$89.159807 USD

-4.02%

dogecoin
dogecoin

$0.092943 USD

-4.16%

chainlink
chainlink

$13.773145 USD

-3.82%

monero
monero

$533.211349 USD

-4.05%

cardano
cardano

$0.244903 USD

-4.37%

unus-sed-leo
unus-sed-leo

$9.074595 USD

0.09%

加密货币新闻

加密货币诈骗者转变策略,瞄准社交媒体进行直接攻击

2024/04/22 20:57

寻求加密货币的攻击者已将重点转向用户而不是平台,利用 Twitter 等社交媒体来宣传加密货币诈骗和恶意软件。 2024 年第一季度,检测到超过 1,500 个冒充 zkSync 和 Inscribe 等公司的虚假账户。包括美国证券交易委员会 (Securities & Exchange Commission) 和 Mandiant 在内的主要社交账户也因宣传欺诈性加密货币优惠而受到损害。

加密货币诈骗者转变策略,瞄准社交媒体进行直接攻击

Cryptocurrency Scammers Shift Tactics, Targeting Users Directly

加密货币诈骗者转变策略,直接针对用户

Attackers Targeting Social Media Accounts for Cryptocurrency Scams

攻击者瞄准社交媒体帐户进行加密货币诈骗

Sophisticated threat actors are increasingly targeting cryptocurrency users on social media, according to a recent study by cybersecurity firm Cyjax. The criminals are employing a mix of fake impersonator accounts and malware to promote fraudulent cryptocurrency offers and steal victims' funds.

根据网络安全公司 Cyjax 最近的一项研究,复杂的威胁行为者越来越多地针对社交媒体上的加密货币用户。犯罪分子混合使用假冒帐户和恶意软件来推销欺诈性加密货币并窃取受害者的资金。

In the first quarter of 2024, Cyjax detected 1,517 fake accounts on Twitter promoting cryptocurrency scams, with companies including zkSync, Inscribe, and Optimism being targeted for impersonation. More alarmingly, major social media accounts for the Securities & Exchange Commission and Mandiant were compromised and used to promote bogus cryptocurrency investment schemes.

2024 年第一季度,Cyjax 在 Twitter 上检测到 1,517 个虚假账户宣传加密货币诈骗,其中 zkSync、Inscribe 和 Optimism 等公司成为假冒目标。更令人担忧的是,美国证券交易委员会和 Mandiant 的主要社交媒体账户遭到入侵,并被用来宣传虚假的加密货币投资计划。

Subtle Typosquatting and Link Redirection

微妙的误植和链接重定向

One notable incident involved a fake account impersonating the well-known cryptocurrency trader "Ansem" on Twitter. The account used a subtle typosquatting technique to respond to tweets from the legitimate Ansem account, who had announced a presale of a new token called $BULL. The malicious account's link redirected victims to a "wallet drainer" website, designed to steal cryptocurrency assets. As a result, over $2.6 million was stolen, with one victim losing a staggering $1.2 million.

一个值得注意的事件涉及 Twitter 上冒充知名加密货币交易商“Ansem”的虚假账户。该帐户使用了一种微妙的误植技术来响应来自合法 Ansem 帐户的推文,该帐户宣布预售一种名为 $BULL 的新代币。恶意帐户的链接将受害者重定向到“钱包耗尽”网站,该网站旨在窃取加密货币资产。结果,超过 260 万美元被盗,其中一名受害者损失了惊人的 120 万美元。

Enhanced Romance Scams and Phishing Attacks

增强的浪漫诈骗和网络钓鱼攻击

Cyjax also reports a surge in "pig butchering" scams, a sophisticated type of romance scam that involves building trust with victims over time before urging them to invest in fraudulent cryptocurrency schemes. These scams have resulted in millions of dollars in losses for unsuspecting victims.

Cyjax 还报告称,“杀猪”骗局激增,这是一种复杂的浪漫骗局,涉及随着时间的推移与受害者建立信任,然后敦促他们投资欺诈性加密货币计划。这些骗局给毫无戒心的受害者造成了数百万美元的损失。

Phishing attacks have also become more prevalent, with attackers exploiting vulnerabilities in email service providers to impersonate web3 companies. In one such attack, a hacker stole over $600,000 by impersonating a legitimate web3 company and sending phishing emails to victims.

网络钓鱼攻击也变得更加普遍,攻击者利用电子邮件服务提供商的漏洞来冒充 web3 公司。在一次此类攻击中,一名黑客通过冒充合法的 web3 公司并向受害者发送网络钓鱼电子邮件窃取了超过 600,000 美元。

Drainer Malware on the Rise

Drainer 恶意软件呈上升趋势

Cyjax notes a concerning trend in the use of drainer malware by cryptocurrency phishing threat actors. This type of malware does not require the attacker to directly convince the victim to send funds. Instead, it only requires the victim to connect their cryptocurrency wallet to the malicious code, which then drains the victim's funds. In one instance, a victim lost 111.6 million ALI tokens, valued at approximately $4.3 million, due to this type of malware.

Cyjax 注意到加密货币网络钓鱼威胁行为者使用 Drainer 恶意软件的一个令人担忧的趋势。此类恶意软件不需要攻击者直接说服受害者发送资金。相反,它只需要受害者将其加密货币钱包连接到恶意代码,然后恶意代码就会耗尽受害者的资金。在一个实例中,受害者由于此类恶意软件而损失了 1.116 亿个 ALI 代币,价值约 430 万美元。

Prevention and Awareness

预防和意识

Cyjax emphasizes that user-oriented attacks have been a persistent threat to cryptocurrency users since the inception of digital currencies. However, recent market fluctuations and the ease with which scams can be carried out on platforms like Twitter have made these threats particularly prevalent in the first quarter of 2024.

Cyjax 强调,自数字货币诞生以来,面向用户的攻击一直是对加密货币用户的持续威胁。然而,最近的市场波动以及 Twitter 等平台上诈骗的便捷性使得这些威胁在 2024 年第一季度尤为普遍。

To protect themselves, cryptocurrency users are urged to be wary of unsolicited offers or investment advice on social media. They should also be cautious when connecting their wallets to websites or services, particularly if they are prompted to do so through a link in an email or social media message.

为了保护自己,加密货币用户应警惕社交媒体上未经请求的报价或投资建议。他们在将钱包连接到网站或服务时也应该谨慎,特别是当通过电子邮件或社交媒体消息中的链接提示他们这样做时。

Social media platforms have a responsibility to combat the proliferation of fraudulent accounts and malicious content. They should implement robust security measures and cooperate with law enforcement agencies to identify and shut down illicit activity.

社交媒体平台有责任打击欺诈账户和恶意内容的扩散。他们应实施强有力的安全措施,并与执法机构合作,查明并制止非法活动。

By staying informed and exercising caution, cryptocurrency users can mitigate the risks of falling victim to these sophisticated scams.

通过保持知情并保持谨慎,加密货币用户可以降低成为这些复杂骗局受害者的风险。

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年09月29日 发表的其他文章