Originally published 8/16/2022
Attackers are bypassing two-factor authentication (2FA) and employing other evasion tactics in a campaign aimed at taking over Coinbase accounts to defraud users of their cryptocurrency.
Researchers at PIXM Software say that threat actors are using Coinbase-spoofed emails to trick users into logging into their accounts, allowing them to access the accounts and steal funds.[2] The researchers say that the cybercriminals will distribute these stolen funds through a network of “burner” accounts, in an automated way, via hundreds or thousands of transactions. The cybercriminals do this to obscure the original wallet from the destination wallet.[2]
The attackers employ a range of tactics to avoid detection. One such tactic is what researchers call “short-lived domains.” These domains are only available for extremely short periods (less than two hours), which deviates from typical phishing practices.[1] Another tactic used is context awareness. Context awareness allows cybercriminals to know the IP address, CIDR Range, or geolocation from which they anticipate their target will be connecting. The attackers can then create something similar to an Access Control List (ACL) on the phishing page to restrict connections to their intended target's IP address, CIDR Range, or region.[1]
The Coinbase attacks begin with criminals targeting users with a malicious email that spoofs Coinbase, making victims believe they are receiving a legitimate message. The email uses a variety of reasons to persuade the user to log in to their account. For example, the account might be locked due to suspicious activity, or a transaction needs to be confirmed. As in a typical phishing campaign, if the user is persuaded to follow the link in the phony message, they are taken to a fake login page and prompted to enter their credentials. If the user enters their credentials, the cybercriminal receives them in real-time and uses them to log in to the legitimate Coinbase website. Because the attacker logged into the legitimate Coinbase website, the victim is sent a 2FA code from Coinbase. Thinking that they are logging into the legitimate Coinbase website, the victim enters the 2FA code they received. However, just as with login credentials, the cybercriminal receives the 2FA code and gains control of the victim’s account.[1]
Once the criminal has access to the account, they divert the victim’s funds to the aforementioned network of accounts in order to evade detection or suspicion. According to researchers, the funds are often embezzled through unregulated and illegal online cryptocurrency services, like cryptocurrency casinos, betting applications, and illegal online marketplaces.[1] At this point, the victim is told that their account is locked or restricted and is prompted to contact customer service to resolve the issue. This prompt is the second phase of the attack, where the cybercriminal poses as a Coinbase employee, trying to help the victim regain access to their account, but in reality is stalling so the fund transfer can be completed before the victim becomes suspicious. Once the transfer is complete, the cybercriminal will abruptly close the session and then shut down the phishing page, leaving the victim without their funds.[1]
This threat advisory contains no indicators of compromise, but users should ensure they interact only with legitimate communications from Coinbase and other services.
(1) Montalbano, Elizabeth. “Phishers Swim Around 2FA in Coinbase Account Heists.” Threatpost English Global, August 8, 2022. https://threatpost.com/phishers-2fa-coinbase/180356/.
(2) PIXM Software, ed. “Coinbase Attacks Bypass 2FA.” Pixm Anti-Phishing, August 8, 2022. https://pixmsecurity.com/blog/phish/coinbase-attacks-bypass-2fa/.
Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut.