Fake websites are posing as crypto exchanges to drain victim wallets

Bitcoin
(Image credit: Shutterstock)

Cybercriminals are reportedly using fake versions of popular websites such as Coinbase, Gemini, Kraken, and MetaMask in an attempt to drain the bitcoin wallets of victims dry. 

According to Netskope, criminal groups are using search engine optimization (SEO) techniques, that involve an extensive network of bots posting links to phishing pages on other websites (mainly blogs) to boost their rankings in search engines such as Google.

In some instances, the researchers claim these fake websites are ranking better than the legitimate sites being copied.

How does the campaign work?

When the victim clicks on a malicious link, they will be greeted by relatively realistic-looking imitation websites hosted on either Google Sites or Microsoft Azure, which will often include a detailed FAQ.

Using the popular Crypto wallet MetaMask as an example, Netskope researchers said users would be directed to either “Download now” or “Login”, where the site will try and dupe users out of their crypto wallet or their username and password. 

How can I avoid getting compromised?

Netskope had some advice for those who don't want to end up as the latest phishing attack victims.

This includes never entering credentials after clicking on a link, and instead, always navigating directly to the site you are trying to log in to. 

For organizations, Netskope also recommends using a secure web gateway to detect and block phishing.

This unfortunately isn't the first time that crypto exchanges have been used as part of a ploy by cybercriminals, in fact, these seem to be getting more inventive.

A group of cybercriminals recenty created a deep fake of Binance chief communications officer (CCO) Patrick Hillmann to extort money out of firms, attempting to convince them they were in the running for a listing on the crypto exchange.

  • Want to avoid your organization becoming compromised? Check out our guide to the best endpoint protection
TOPICS

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
Bitcoin
Fake Ledger data breach emails used to trick victims into giving up recovery phrases
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Marvel Rivals
Marvel Rivals' next update will add two new hero skins for Iron Man and Spider-Man mains this week
Nvidia Isaac GROOT N1
“The age of generalist robotics is here" - Nvidia's latest GROOT AI model just took us another step closer to fully humanoid robots
Lego Pokemon
Pokemon and Lego announce the most electrifying collaboration of all time and I’m going to be first in line
Apple Watch app health
Apple Watch blood pressure monitoring tech revealed in patent
Using Zipped files and folders in Windows 11
Hidden clues suggest Microsoft is moving another part of Windows 11’s Control Panel to the Settings app – and this time it’s mouse options