Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach

Bybit
Blockonomics


Trezor users have been targeted by an unusually convincing phishing campaign after attackers compromised a third-party email provider used by the hardware wallet manufacturer. 

The company confirmed late Wednesday that a fraudulent email titled “Critical Security Alert: STM32 Entropy Vulnerability” had been distributed to users.

“Our third-party e-mail provider has been breached,” Trezor said. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”

Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach

bybit

XRP, Stellar (XLM), Dogecoin (DOGE) and Near Protocol (NEAR) Price Analysis for September 10: Will Market Reclaim Momentum?

Trezor added that it had taken down the affected domain and was investigating how the attackers managed to gain access to infrastructure that is linked to the legitimate domain.

The company has not publicly disclosed how many customers received the phishing message. 

Not a typical phishing email 

This incident is particularly terrifying because it does not involve misspelled or obviously fraudulent addresses.

In fact, the malicious messages were delivered via infrastructure authorized to send email on Trezor’s behalf. This makes it way harder for both users and automated spam filters to identify them. 

A screenshot circulating following the attack shows the email identifying its sender as “Trezor Security” with the address help@trezor.io.

card

More importantly, Gmail displayed “mailed-by: mailing.trezor.io” and “signed-by: trezor.io.”

The fraudulent messages passed SPF, DKIM, and DMARC checks. This helps explain why recipients could see “signed-by: trezor.io” in Gmail and why the messages were less likely to be relegated to spam.

Fake vulnerability warning 

The attackers attempted to create urgency by claiming that Trezor devices had a critical entropy vulnerability (compromised randomness). They were trying to capitalize on the panic stemming from the nightmare that devastated Coldcard wallet owners earlier this year. 

Unfortunate email recipients were then pushed to go through what looked like a security verification process. 

One Trezor forum user said an “offline” HTML file was capable of transmitting entered information to Telegram.

Other companies reportedly affected 

There have been other suspicious emails targeting customers of BitBox and cryptocurrency portfolio service CoinTracking.

Some community investigators have pointed to email marketing provider Brevo as the common infrastructure behind the incidents.

Trezor itself has not identified the email provider that has been compromised. 

A similar incident  

As reported by U.Today, the company disclosed a separate incident in August . The incident, which involved shipping provider ShipMonk, exposed customer information and could increase the risk of targeted phishing.

There is currently no confirmed evidence that the ShipMonk exposure and Wednesday’s email-provider compromise were caused by the same attackers.



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*