By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    What is a rootkit and how to remove it
    8 months ago
    The Mask – Unveiling the World’s Most Sophisticated APT Campaign
    8 months ago
    Regin APT Attacks Among the Most Sophisticated Ever Analyzed
    8 months ago
    Latest News
    Safeguards against firmware signed with stolen MSI keys
    16 hours ago
    WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
    16 hours ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
    6 days ago
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    7 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    For 0-day vulnerabilities in Windows, temporary patches
    7 months ago
    Windows 11 22H2 (build 22621.317) outs in the Release Preview Channel
    8 months ago
    How to avoid problems installing Windows 11 22H2
    8 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    3 months ago
    Now you can speed up any video in your browser
    3 months ago
    How to restore access to a file after EFS or view it on another computer?
    4 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    4 months ago
  • How To
    How ToShow More
    What is two-factor authentication | Kaspersky official blog
    2 days ago
    Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
    4 days ago
    NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
    4 days ago
    How Oxy uses hooks for maximum extensibility
    How Oxy uses hooks for maximum extensibility
    5 days ago
    The personal threat landscape: securing yourself smartly
    5 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to remove Taskbar time and date on Windows 11 (preview)
    2 months ago
    How to add multiple Android and iPhone to Phone Link on Windows 11
    1 month ago
    How to check USB4 devices specs from Settings on Windows 11
    2 days ago
    Latest News
    How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
    2 days ago
    How to enable Taskbar End Task option to close apps on Windows 11
    2 days ago
    How to check USB4 devices specs from Settings on Windows 11
    2 days ago
    How to enable new header UI for File Explorer on Windows 11
    7 days ago
  • Glossary
  • My Bookmarks
Reading: Scam e-mails from “cloud-mining platform”
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Threats

Scam e-mails from “cloud-mining platform”

Vitus White
Last updated: 26 March
Vitus White 2 months ago
Share
7 Min Read

Despite some instability over the past six months, the cryptocurrency market is still seen by many as a get-rich-quick scheme. Accordingly, the stream of scammers feeding off this topic won’t be running dry any time soon. To lure victims into their traps, they continue to come up with new ploys, each more innovative than the last. Today we look at a novel scheme that invites victims to withdraw funds supposedly mined by their accounts on some kind of “automated cloud-mining platform.”

Contents
While you were gone, your account got minedHow to stay safe

While you were gone, your account got mined

It all starts with an e-mail with an attached PDF informing the recipient that nearly a year has passed since they last logged in to their “Bitcoin Cloud Mining” account, which they supposedly created once upon a time. In the interim, the scammers write, 0.7495 BTC (worth around US$15,000) has accumulated in the account. But here’s the rub: since the account has been dormant for almost a year, it will be blocked very soon — after which the mined cryptocurrency will be distributed among other platform users. Time is of the essence, though it’s not clear precisely how much of it the user actually has: the e-mail states “2 days 23:58:38” in a large font, while the small print reads “within 24 hours”. Either way, not everything is lost: the user still has time to log in and withdraw the funds.

In the attached PDF, scammers promise a large payout if the victim logs in right away; otherwise the account will be blocked

After clicking the button in the file, the user is taken to the mentioned “Bitcoin Mining” website (the word “Cloud” has been dropped out of the name by this point). There, two pieces of good news await. First, it turns out that the platform remembers the user by their IP address, so there’s no need to recall the username and password. Second, the payout has now gone up to 1.3426 BTC – a little more than US$30,000 at the time of posting.

Fake Bitcoin mining platform

Fake Bitcoin mining platform claims to remember the user’s IP address

Now for the bad news: even less time now remains than was specified in the e-mail. The account will be blocked in precisely 18 hours, 39 minutes, 54 seconds — so get those skates on!

Fake website urging the victim to hurry up

Scammers rush the victim: no time to lose!

The username and password are already auto-filled in the form; all that remains is to click the login button.

Form for entering credentials to log in to the fake mining platform

There’s no need to remember the username and password, they are auto-filled

The fake site is surprisingly detailed, with lots of different sections to explore. For example, there’s a monthly history of accruals, a history of rewards for individual mining operations, a colorful page showing the current balance, and even a news section. Besides, occasional notifications pop up in a corner of the window stating that some other user just got a large payout.

The scam site is surprisingly well designed

There’s a “settings section” for changing the password, subscribing to various services, enabling auto-withdrawal of funds (not specified where to), and even allowing other users of the platform to send you money (on the notification settings tab, for some reason).

Settings section on the fake site

The scam site even has a settings section

Settings section on the fake site

The focal point for the victim, of course, is the “Get payout” button. Clicking this button initiates what seems to be a chat between the user and a certain Sophia, who appears to be the Head of Payout Operations. Another form has to be filled out, this time with personal data, including card number (presumably the site creators collect this information to sell on).

During the chat with the “Head of Payout Operations”, the user is asked to enter their personal data, including card number

Of course, the scammers’ goal is to squeeze real money out of the victim. So pretty soon they get down to brass tacks. The victim is offered to convert the cryptocurrency into dollars by paying a small commission of 0.25%. In monetary terms, the fee turns out to be even less than that — just $64.03.

Fake site asks for a conversion fee

A small commission is charged to convert bitcoin into regular money

The “fee” must be paid in cryptocurrency, so the user is transferred to a page explaining how to purchase it.

Helping the victim purchase bitcoin

Customer care: the scam site kindly explains how to buy bitcoin

After clicking the “Pay” button, a page appears with the wallet address for sending the “fee”.

Send the payment here

Sure, after paying the “fee”, the victim receives not a penny of the promised payout, but has handed their payment and personal information to the attackers, who can then use it in other schemes or sell it on the dark web.

How to stay safe

Now for a few tips on how to protect yourself from this and other scams:

  • Don’t be fooled by sudden generous gifts: large no-strings-attached payouts. If someone dangles large winnings in front of your nose, it will probably end in tears.
  • Learn to recognize online scams. There are several telltale signs, which we covered earlier.
  • Never enter card details on suspicious sites.
  • Don’t send cryptocurrency to strangers — you won’t be able to appeal the transaction and get your money back.
  • Install a reliable security solution with built-in protection against phishing and online fraud. This will warn you in advance if you’re about to land on a dangerous site.

Source: kaspersky.com

Translate this article

TAGGED: Phishing, PoC, SASE, Security, Threats
Vitus White March 26, 2023 March 26, 2023
Share this Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Safeguards against firmware signed with stolen MSI keys
Threats 19 hours ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats 19 hours ago
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
News 2 days ago
How to enable Taskbar End Task option to close apps on Windows 11
News 2 days ago
How to check USB4 devices specs from Settings on Windows 11
News 2 days ago

Recent Posts

  • Safeguards against firmware signed with stolen MSI keys
  • WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
  • How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
  • How to enable Taskbar End Task option to close apps on Windows 11
  • How to check USB4 devices specs from Settings on Windows 11

You Might Also Like

Threats

Safeguards against firmware signed with stolen MSI keys

19 hours ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats

WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin

19 hours ago
News

How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11

2 days ago
How To

What is two-factor authentication | Kaspersky official blog

2 days ago
Show More

Related stories

How to Use Cloudflare to Secure Your WordPress Site
How To Starting Chrome from the command line
How to fix error 0x80070057 in Chrome?
Windows 10 How To Disable Slide to Shutdown
Windows search not working (FIX)
How to watch movies and TV series for free on Kinopoisk?
Previous Next

10 New Stories

What is two-factor authentication | Kaspersky official blog
Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
How Oxy uses hooks for maximum extensibility
The personal threat landscape: securing yourself smartly
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Previous Next
Hot News
Safeguards against firmware signed with stolen MSI keys
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
How to enable Taskbar End Task option to close apps on Windows 11
How to check USB4 devices specs from Settings on Windows 11
10alert.com10alert.com
Follow US

© 10 Alert Network. All Rights Reserved.

  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?