News: 1645183027

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft offers defense against 'ice phishing' crypto scammers

(2022/02/18)


Microsoft has some advice on how to defend against "ice phishing" and other novel attacks that aim to empty cryptocurrency wallets, for those not already abstaining.

Ice fishing involves cutting a hole in a frozen body of water in order to catch fish. Ice phishing, as Microsoft describes it, is a clickjacking, or a user interface redress attack, that "[tricks] a user into signing a transaction that delegates approval of the user’s tokens to the attacker."

The recent [1]$120m attack on BadgerDAO , for example, relied on a malicious injected script to enable ice phishing, which involved prompting users of the [2]BadgerDAO web app to delegate the attacker to conduct transactions for them.

[3]

"In an 'ice phishing' attack, the attacker merely needs to modify the spender address to the attacker's address," said Christian Seifert, a security researcher at Microsoft, in a [4]blog post . "This can be quite effective as the user interface doesn’t show all pertinent information that can indicate that the transaction has been tampered with."

[5]

[6]

Seifert said Badger's smart contract front-end infrastructure at Cloudflare was compromised and the attacker gained control over a Cloudflare API key. That allowed the injection of a malicious script into the Badger smart contract front end.

"This script requested users to sign transactions granting ERC-20 approvals to the attacker’s account," explained Seifert.

[7]

[8]ERC-20 refers to the standard for creating smart contracts on the Ethereum blockchain. ERC-20 tokens implement an API for smart contracts which allow programmatic transactions. The token owner can transfer tokens but must delegate authority to any smart contract that would transact on the owner's behalf.

In the BadgerDAO theft, almost 200 individuals ended up handing control of their tokens to a smart thief instead of a smart contract. They did so because the app interface didn't make it obvious that the "spender" account being authorized was controlled by the attacker.

[9]

Click to enlarge

Seifert also described other forms of cybercrime tuned for "web3," which is to say decentralized finance and related blockchain jargon.

There's scanning social media for people seeking support with wallet software and responding with spoofed support messages in the hope of convincing the victim to reveal private crypto wallet keys. There's distributing new tokens for free and then causing transactions involving those tokens to fail with an error message that redirects to a phishing site or malware installer. And there's impersonating legitimate smart contract front ends or wallet software to nab private keys directly.

Really, it's all just the same old web, code, and scammers. But feel free to call it web3 if that makes it seem shiny and new.

[10]Phishing kits' use of man-in-the-middle reverse proxies is growing, warns Proofpoint

[11]Crypto.com now says someone tried to drain $34m from hundreds of accounts

[12]This malware gang plants incriminating evidence on PCs, gets victims arrested

[13]Singapore monetary authority threatens action on bank over widespread phishing scam

Microsoft at least has an idea about how to mitigate cryptocurrency-focused attacks. The company has created and [14]open-sourced an [15]agent on Forta, a smart contract threat-detection platform. The software looks for suspicious token approvals – the precursor of ice phishing – and suspicious transfers. Maybe this will help.

Seifert also offers web3 users advice on protecting themselves from threats like the BadgerDAO attack. Mostly it's common sense stuff like "Review the smart contract you are interacting with." This seems likely to be about as successful as "Review the code in your npm dependencies."

[16]

But Seifert also calls out a real problem with the entire web3 ecosystem, the lack of consumer protection.

"[T]hese recommendations put a lot of burden on the users; we encourage web3 projects and wallet providers to increase usability to help users perform these actions," he said.

In the meantime, we recommend either [17]Rekt or " [18]web3 is going just great " for those interested in keeping up with the crypto thefts and scams fueling the web3 dumpster fire. ®

Get our [19]Tech Resources



[1] https://www.theregister.com/2021/12/02/badgerdao_coin_theft/

[2] http://app.badger.com/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yg-QuGUeOC72q44g4g-9LAAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.microsoft.com/security/blog/2022/02/16/ice-phishing-on-the-blockchain/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg-QuGUeOC72q44g4g-9LAAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yg-QuGUeOC72q44g4g-9LAAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg-QuGUeOC72q44g4g-9LAAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://ethereum.org/en/developers/docs/standards/tokens/erc-20/

[9] https://regmedia.co.uk/2022/02/17/microsoft_blog_image.png

[10] https://www.theregister.com/2022/02/03/proofpoint_mitm_reverse_proxies/

[11] https://www.theregister.com/2022/01/20/cryptocom_cryptocurrency_theft/

[12] https://www.theregister.com/2022/02/10/modifiedelephant_evidence_malware/

[13] https://www.theregister.com/2022/01/18/singapore_monetary_authority_threatens_action/

[14] https://github.com/microsoft/forta_phishing_agents

[15] https://connect.forta.network/agent/0x302139894ae9906024a1f78b5f2669c11cc259c6306f76c8830633759527cde1

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yg-QuGUeOC72q44g4g-9LAAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://rekt.news/

[18] https://web3isgoinggreat.com/

[19] https://whitepapers.theregister.com/



wolfetone

There are a number of us who use Office 365 this week that have seen first hand how Microsoft tends to defend its users from these scammers.

By listing the domain names of the user's company as being infected with Malware. Then going through all of the emails for that user and their company, removing them from their mailboxes and throwing them in to quarantine en mass.

At which point, they then say "Oops, sorry" after a full 2 days of these shenanigans without so much as an explanation as to why, to only then (from last night) remove emails that have been received this week and then redeliver them to the same mailbox, as if the emails have just been sent.

Colour me surprised that no one seems to have covered this monumental faux pas, that's affected a fair number of customers?

I have a sure fire way to avoid these Web3 Scammers...

lglethal

Don't get involved in the stupid, f%&king Web3 scamming bollocks to start with! Walla, you are protected from being scammed out of your crypto - because you dont have any! No Ice phishing for you!

Protect yourself, your family, and the Environment - just say NO!!!!

Re: I have a sure fire way to avoid these Web3 Scammers...

ShadowSystems

Damn my inability to upvote you another trillion times.

*Hands you a super sized tankard*

Please accept a couple dozen pints on me as a gesture of how much I agree with your post instead.

Cheers! =-)

It's going great

trevorde

https://web3isgoinggreat.com/

Re: It's going great

Howard Sway

Thanks for the link - all the stories are just mind-meltingly hilarious. Had to stop at "Baby Musk Coin" before I got to "Samsung launches environmental sustainability-themed metaverse scavenger hunt where people plant virtual trees and earn NFTs"

Re: It's going great

vtcodger

It's the drinking water I tell you. It has to be the drinking water. The CIA and the Illuminati are putting something in it that deprives people of what little sense they normally have.. Worldwide apparently.

And I think the animals are starting to act funny too.

It has to be the drinking water.

Re: It's going great

Arthur the cat

It has to be the drinking water.

Nah. Chemtrails(*), innit?

(*) For purposes of balance: other barking mad conspiracy theories may also apply.

If only you knew she loved you, you could face the uncertainty of
whether you love her.