crypto.news and Cryptopolitan both cite $11.8 million in losses from a Singapore joint SPF/CSA advisory, but describe different victims and mechanisms.
crypto.news and Cryptopolitan both cite $11.8 million in losses from a Singapore joint SPF/CSA advisory, but describe different victims and mechanisms.
A fake cryptocurrency job offer that infected a company-issued device has led to US$11.8 million in losses after attackers gained access to corporate systems and bypassed transaction controls, Singapore authorities have said.
Singapore’s police and Cyber Security Agency have issued a joint advisory on cryptocurrency scams disguised as job offers, after victims lost about $11.8 million.
What would settle it: The full text of the SPF/CSA joint advisory
Once installed, the malware harvested the victim’s session token, SPF and CSA said. Attackers then used the stolen token to bypass multi-factor authentication and gain access to the victim’s Bitbucket account, which was connected to the employer’s code repository.
The job scams usually start on social media when victims answer an advertisement promising an online job or an investment return. The victim is then walked through opening a crypto account and buying tokens by someone posing as a helpful guide.
What would settle it: The full text of the SPF/CSA joint advisory
Credentials collected during the compromise allowed the attackers to bypass transaction limits and approval checks used to control cryptocurrency transfers. SPF and CSA said the attackers subsequently carried out crypto transactions that resulted in losses totaling US$11.8 million.
Unsurprisingly, the payout never lands, and in many cases, the target is also talked into handing over login details or a seed phrase, which lets the fraudster empty the account outright.
What would settle it: The full text of the SPF/CSA joint advisory
Treat the $11.8 million figure and the existence of a joint SPF/CSA advisory on fake-job crypto scams as established; the underlying description of who was victimized and how the money was actually taken differs between the two reports and cannot both be correct as written, so avoid drawing conclusions about the specific attack method until the advisory itself is checked.
Treat the $11.8 million figure and the existence of a joint SPF/CSA advisory on fake-job crypto scams as established; the underlying description of who was victimized and how the money was actually taken differs between the two reports and cannot both be correct as written, so avoid drawing conclusions about the specific attack method until the advisory itself is checked.
Original source: AltcoinGordon