Saturday, April 27, 2024
HomeOther'sTechnologyCrypto hackers using fake Amazon digital token as bait to lure victims

Crypto hackers using fake Amazon digital token as bait to lure victims

Amid the crypto buzz, cyber-criminals are leveraging Amazon’s name to promote a fraudulent scheme called ‘Amazon to create its own digital token’ — leading victims to give away their credentials in the first phase of the fraud campaign, cyber-security researchers have warned.

The researchers from cyber-security firm Akamai said that they have been able to track continuous cyberattack campaigns that took advantage of the crypto fever, including fraudsters who introduced a variety of phishing schemes built on fake rumors, such as “Amazon to create its own digital token”.

“This particular scam played directly into victims’ fear of missing out on a limited-time offer to invest in a new (albeit fake) cryptocurrency ‘opportunity’,” they said.

ALSO READ: Over 50% internet-connected devices in hospitals vulnerable to cybercrime: Report

A closer look at victims who visited the fake token landing pages showed that 98 percent of the victims were mobile users, with 56 percent using Android and 42 percent using iPhone devices.

“Looking into the geographic breakdown for campaign victims shows that 29 percent were located within North America, 35 percent in South America, and 27 percent in Asia,” the report said.

Akamai reported its findings to Amazon.

Once the targets were engaged, victims were led to a well-designed and functional fake website, where they, in turn, paid for the fake cryptocurrency.

ALSO READ: Meta, Google grilled over misinformation and cyberbullying, Twitter next

The scam required the targets to use cryptocurrency — in this instance, Bitcoin — as the method of payment for the fake tokens.

The ultimate goal of the scam was to lead victims into believing the fake cryptocurrency was real and pay for it with their own cryptocurrency (bitcoin).

“To drive victim engagement and trust, attackers created a fully functional website that required registration, account confirmation using email, and a user account profile,” said the researchers.

Additionally, the website included social engineering techniques that presented a fake progress bar, indicating tokens were about to sell out, adding pressure to the victim’s purchasing decision.

Chainalysis estimates that fraudsters received approximately $14 billion in deposits in 2021.

 

 

(This story has been sourced from a third-party syndicated feed, agencies. Raavi Media accepts no responsibility or liability for the dependability, trustworthiness, reliability, and data of the text.  Raavi Media management/ythisnews.com reserves the sole right to alter, delete or remove (without notice) the content at its absolute discretion for any reason whatsoever.)