logo
logo
Sign in

Coinbase infosec spotted phishy process spawned by Firefox

avatar
Geekz Snow
Coinbase infosec spotted phishy process spawned by Firefox

Elaborate zero-day browser break-out betrayed by unusual behavior

Coinbase chief information security officer Philip Martin this week published an incident report covering the recent attack on the cryptocurrency exchange, revealing a phishing campaign of surprising sophistication.

At some point prior to that, the attackers – a group known to Coinbase as CRYPTO-3 or sometimes HYDSEVEN – compromised or created two email accounts at Cambridge.

Two days before the initial emails went out, they registered a domain to deliver their exploit, Martin said.

After corresponding with the initial set of targets – about 200 – through a series of messages over several weeks, the hackers winnowed their list of prospective victims down to five specific marks.

"Stage one of this attack first identified the operating system and browser, and displayed a convincing error to macOS users who were not currently using Firefox, instructing them to install the latest version from Mozilla," Martin wrote.

collect
0
avatar
Geekz Snow
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more