MetaverseNFTCoins.com
  • NFT News
  • Crypto News
  • Blockchain
  • Regulations
  • Scams
No Result
View All Result
MetaverseNFTCoins.com
No Result
View All Result

Fake Binance NFT Mystery Box bots steal victim’s crypto wallets

May 13, 2022
in NFT News
Reading Time: 3 mins read
A A
Fake Binance NFT Mystery Box bots steal victim’s crypto wallets
ShareShareShareShareShare
Source: ITAMGamesInc

A new RedLine malware distribution campaign promotes fake Binance NFT mystery box bots on YouTube to lure people into infecting themselves with the information-stealing malware from GitHub repositories.

Binance mystery boxes are sets of random non-fungible token (NFT) items that people buy, hoping they’ll receive a unique or rare item at a bargain price. Some of the NFTs found in these boxes can be used to add rare cosmetics or personas within online blockchain games.

Mystery boxes are trendy in the NFT market because they give people the joy of the unknown and the potential for a big payday if they land a rare NFT. However, marketplaces like Binance offer them in limited numbers, making some boxes hard to get before they run out of stock.

This is why interested buyers often deploy “bots” to acquire them, and it’s precisely this hot trend that the threat actors are trying to take advantage of.

YouTube and GitHub abuse

According to a new report by Netskope, threat actors are creating YouTube videos to entice potential victims into downloading and installing the malware on their computer, thinking they’re getting a free mystery box scalper bot.

Malicious YouTube videos
Malicious YouTube videos (Netskope)

BleepingComputer confirmed that the videos listed in the indicators of compromise are still available on YouTube, albeit having a low number of views. 

There likely are many more than those spotted by Netskope, and it’s also possible that previous scam videos with a higher number of views were reported and taken down by YouTube moderators.

The threat actors uploaded the videos between March and April 2022, and they all feature a link to a GitHub repository that supposedly hosts the bot but, in reality, distributes RedLine.

Video description leading to a GitHub download
Video description leading to a GitHub download (Netskope)

The name of the dropped file is “BinanceNFT.bot_v1.3.zip”, containing a similarly-named executable, which is the payload, a Visual C++ installer, and a README.txt file.

Files contained in the dropped ZIP archive
Files contained in the dropped ZIP 
(Netskope)

RedLine requires the VC redistributable installer to run since the program is developed in .NET, while the text file contains the installation instructions for the victim.

Readme file instructions
Readme file instructions (Netskope)

In this campaign, RedLine was configured to exit if the malware detected the country on the host computer to be Russia, Ukraine, Belarus, Armenia, Azerbaijan, Kazakhstan, Moldova, Uzbekistan, Tajikistan, or Kyrgystan.

In addition to the RedLine campaign seen by Netskope, BleepingComputer noticed newer YouTube campaigns promoting a free ‘Binance NFT Bot.’

Newer Binance NFT bot scams on YouTube
Newer Binance NFT bot scams on YouTube
Source: BleepingComputer

However, these campaigns are using rebrand.ly URLs that redirect to downloads hosted on MediaFire. According to VirusTotal, this campaign is also distributing password-stealing trojans.

RedLine threat continues

RedLine is a very popular and potent threat in the information-stealing malware space, being distributed by multiple threat actors and in a wide variety of ways.

It’s currently sold to independent operators under a subscription model for $100 per month and supports the stealing of login passwords and cookies from web browsers, data from chat apps, VPN credentials, and cryptocurrency wallets.

In cryptocurrency-themed campaigns, such as this one, the victims typically possess digital assets and cryptocurrency, making the financial damage even more significant.

One thing to always keep in mind is that the legitimacy of platforms like YouTube and GitHub does not automatically equate to content trustworthiness, as the upload checks and the moderation procedures on these sites are lacking.

Clicking on links provided under or on videos uploaded by small and obscure YouTube channels, downloading executable files, and running them on your system is never a good idea.

Credit: Source link

ShareSendTweetPinShare
Previous Post

Fender has filed trademarks for NFTs and “other crypto-collectibles”

Next Post

The Sixers Season Is Over, But At Least I Got This Playoff NFT

Next Post
The Sixers Season Is Over, But At Least I Got This Playoff NFT

The Sixers Season Is Over, But At Least I Got This Playoff NFT

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Weekly Updates

LimeWire to Debut Music NFTs in Partnership With UMG

LimeWire to Debut Music NFTs in Partnership With UMG

May 19, 2022
Regulation: The Gold-Standard for Crypto-Assets

Regulation: The Gold-Standard for Crypto-Assets

May 18, 2022
Terra crash sharpens Washington’s attention on crypto regulations

Terra crash sharpens Washington’s attention on crypto regulations

May 17, 2022
Federal, New York Officials Look for Public Input on Crypto Regulation

Federal, New York Officials Look for Public Input on Crypto Regulation

May 19, 2022
Crypto’s First Generative Formline NFT Project Offers the Chance to Become a Whale

Crypto’s First Generative Formline NFT Project Offers the Chance to Become a Whale

May 20, 2022
MetaverseNFTCoins.com

This is an online news portal that aims to provide the latest NFT news, crypto news, blockchain, regulations, scams, and much more stuff like that around the world. We promise to share only high quality content from the world's best crypto sources. Feel free to get in touch.

What’s New Here!

  • BTC Could Reach $28,000 Level; Dips Likely to be Limited
  • G7 says crypto regulation must be swift and comprehensive
  • Draft Law About NFTs Submitted to Russian Parliament – Regulation Bitcoin News

Subscribe Now

Loading
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - metaversenftcoins.com - All rights reserved!

No Result
View All Result
  • NFT News
  • Crypto News
  • Blockchain
  • Regulations
  • Scams

© 2021 - metaversenftcoins.com - All rights reserved!

  • bitcoinBitcoin (BTC) $ 29,455.00 0.67%
  • ethereumEthereum (ETH) $ 1,977.99 0.45%
  • tetherTether (USDT) $ 1.00 0.01%
  • usd-coinUSD Coin (USDC) $ 1.00 0.07%
  • bnbBNB (BNB) $ 313.08 3.21%
  • xrpXRP (XRP) $ 0.414833 0.55%
  • binance-usdBinance USD (BUSD) $ 1.00 0.11%
  • cardanoCardano (ADA) $ 0.527751 1.79%
  • solanaSolana (SOL) $ 50.06 0.52%
  • dogecoinDogecoin (DOGE) $ 0.084891 0.62%
  • polkadotPolkadot (DOT) $ 9.92 1.98%
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 29,436.00 0.6%
  • staked-etherLido Staked Ether (STETH) $ 1,925.71 0.61%
  • avalanche-2Avalanche (AVAX) $ 29.62 1.6%
  • tronTRON (TRX) $ 0.074033 3.88%
  • shiba-inuShiba Inu (SHIB) $ 0.000012 1%
  • daiDai (DAI) $ 1.00 0.01%
  • litecoinLitecoin (LTC) $ 69.76 1.35%
  • crypto-com-chainCronos (CRO) $ 0.189929 1.27%
  • leo-tokenLEO Token (LEO) $ 4.91 1.76%
  • matic-networkPolygon (MATIC) $ 0.648089 1.83%
  • nearNEAR Protocol (NEAR) $ 5.94 2.05%
  • ftx-tokenFTX Token (FTT) $ 30.04 0.71%
  • bitcoin-cashBitcoin Cash (BCH) $ 191.54 0.61%
  • chainlinkChainlink (LINK) $ 7.04 1.84%
  • moneroMonero (XMR) $ 178.32 1.26%
  • stellarStellar (XLM) $ 0.129926 1.99%
  • cosmosCosmos Hub (ATOM) $ 10.95 2.58%
  • okbOKB (OKB) $ 12.17 1.02%
  • flowFlow (FLOW) $ 2.83 0.82%
  • algorandAlgorand (ALGO) $ 0.429586 1.72%
  • ethereum-classicEthereum Classic (ETC) $ 20.29 0.11%
  • uniswapUniswap (UNI) $ 5.28 4.61%
  • apecoinApeCoin (APE) $ 8.01 2.5%
  • hedera-hashgraphHedera (HBAR) $ 0.100672 0.52%
  • vechainVeChain (VET) $ 0.030794 1.75%
  • elrond-erd-2Elrond (EGLD) $ 90.96 1.52%
  • theta-fuelTheta Fuel (TFUEL) $ 0.063670 0.09%
  • internet-computerInternet Computer (ICP) $ 7.98 3.31%
  • magic-internet-moneyMagic Internet Money (MIM) $ 0.997499 0.06%
  • filecoinFilecoin (FIL) $ 8.12 2.82%
  • axie-infinityAxie Infinity (AXS) $ 20.84 0.22%
  • decentralandDecentraland (MANA) $ 1.09 1.43%
  • the-sandboxThe Sandbox (SAND) $ 1.32 3.91%
  • tezosTezos (XTZ) $ 1.81 4.94%
  • compound-ethercETH (CETH) $ 39.69 0.62%
  • kucoin-sharesKuCoin Token (KCS) $ 15.99 4.82%
  • chain-2Chain (XCN) $ 0.091111 0.82%
  • fraxFrax (FRAX) $ 1.00 0.01%
  • pancakeswap-tokenPancakeSwap (CAKE) $ 4.59 3.12%