Odaily星球日报讯 网络安全专家近日发现一起针对加密货币行业内外用户的双重恶意软件攻击。网络情报公司 Silent Push 在最新报告中揭露了名为 PoisonSeed 的恶意活动,该活动先伪造 Mailchimp 和 SendGrid 等批量邮件服务提供商的登录页面窃取用户凭证。攻击者发送虚假邮件,谎称用户账户受限,诱骗其登录高仿网站,输入凭证后,攻击者迅速自动导出邮件订阅列表。随后,攻击者利用窃取的订阅列表,冒充 Coinbase 向受害者联系人发送钓鱼邮件,称交易所“正过渡至自托管钱包”,并附带 12 词助记词,诱骗用户导入钱包,实则让黑客掌控资产。(Decrypt)
Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.