Malware spreads false wallet mnemonics through hacking into email lists
ChainCatcher news, according to Decrypt, cybersecurity experts recently discovered a dual malware attack targeting users inside and outside the cryptocurrency industry.Cyber intelligence company Silent Push revealed in its latest report a malicious activity named PoisonSeed, which first forges login pages of bulk email service providers like Mailchimp and SendGrid to steal user credentials. Attackers send fake emails claiming that user accounts are restricted, luring them to log into a counterfeit website. After entering their credentials, the attackers quickly and automatically export the email subscription list.Subsequently, the attackers use the stolen subscription list to impersonate Coinbase and send phishing emails to the victims' contacts, claiming that the exchange "is transitioning to self-custody wallets," and includes a 12-word recovery phrase, tricking users into importing the wallet, effectively allowing hackers to take control of the assets.