Tech
Cryptocurrency Scammers Use ‘Wallet Drainer’ Ploy on Google and X Ads, Make $59M in Phishing Scams: Report
In a worrying trend that has continued since last year, cybercriminals have orchestrated a series of phishing scams to steal millions of dollars in cryptocurrency assets through deceptive ads on major platforms, including Google and X. Discovered by cybersecurity experts at ScamSniffer, these scammers are using a sinister tool known as a “wallet drainer” to carry out their shady plans in the phishing scams.
Released in a recent blog post, ScamSniffer reveals that the initial detection of this wallet drainer occurred within Google Search Ad Phishing, and then made its way into a series of X-Phishing Ads shared by ZachXBT. A recent examination of ads in X feeds showed that nearly 60% of phishing ads used this specific drain.
Now we are on WhatsApp. Click on joint.
Read also: Are you looking for a smartphone? To check the mobile device tracker
Between March and December, ScamSniffer diligently monitored 10,072 phishing websites, linking them to the theft of nearly $58.98 million from more than 63,000 victims over the previous nine months through an analysis of on-chain data associated with addresses of phishing.
Understanding Wallet Emptying and Its Propagation
Wallet drainers work by tricking users into authorizing malicious transactions that drain assets from their cryptocurrency wallets. Typically, this happens when users interact with misleading links embedded in deceptive advertisements, which are, in reality, phishing scams.
Recent examples of these phishing scams using wallet emptying include a group of deceptive X ads called “Ordinals Bubbles” and fake links leading to popular crypto platforms like DeFiLlama and Lido. Notably, these phishing ads have become more sophisticated, incorporating redirect tricks that imitate official, legitimate domains and ultimately direct users to phishing websites.
The blog post highlights the versatility of these wallet drainers, stating: “Phishing scammers have implemented these tactics through various channels such as phishing ads, supply chain attacks, Discord phishing, spam comments and mentions on Twitter, Airdrop phishing , SimSwap attacks, DNS attacks, email phishing, etc., continuously targeting ordinary users with phishing attacks and causing significant resource losses.”