{"id":81,"date":"2022-12-08T21:38:09","date_gmt":"2022-12-08T21:38:09","guid":{"rendered":"https:\/\/freshphish.info\/?p=81"},"modified":"2022-12-08T21:38:57","modified_gmt":"2022-12-08T21:38:57","slug":"crypto-wallet-phish","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=81","title":{"rendered":"Crypto Wallet Phish"},"content":{"rendered":"\n<p>I found this phish a few days ago. I&#8217;m quite sure something similar has been around for a long time but it&#8217;s the first one of this type I&#8217;ve seen. It claims to be from the Exodus Cryptowallet company, saying they updated their terms of service and because of the &#8220;Know Your Customer&#8221; regulations, the target needs to log in to Exodus and acknowledge the change in terms of service.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"282\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image001-1024x282.png\" alt=\"\" class=\"wp-image-82\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image001-1024x282.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image001-300x83.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image001-768x212.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image001.png 1307w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Here&#8217;s the original email. Note the spoofed sender email address and the link to a compromised web site.<\/figcaption><\/figure>\n\n\n\n<p>If the link is clicked, the victim is brought to a page hosted in the .br (Brazil) country TLD asking for several words from the backup phrase of their Exodus wallet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"551\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image002-1024x551.png\" alt=\"\" class=\"wp-image-83\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image002-1024x551.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image002-300x161.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image002-768x413.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/image002.png 1400w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Once the malicious actor has access to the appropriate words from the backup phrase, they would have access to the victim&#8217;s cryptocurrency wallet. Knowing how much some people have in cryptocurrency, this could end up being a windfall.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I found this phish a few days ago. I&#8217;m quite sure something similar has been around for a long time<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=81\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Crypto Wallet Phish<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[32,33,30,31,34,4],"class_list":["post-81","post","type-post","status-publish","format-standard","hentry","category-phish","tag-crypto-currency","tag-crypto-wallet","tag-cryptocurrency","tag-cryptowallet","tag-exodus","tag-phish"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/81","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=81"}],"version-history":[{"count":1,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/81\/revisions"}],"predecessor-version":[{"id":84,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/81\/revisions\/84"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=81"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=81"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=81"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}