{"id":28898,"date":"2021-02-13T04:11:47","date_gmt":"2021-02-12T17:11:47","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/cryptoscam-in-discord-fake-news-services\/28898\/"},"modified":"2021-02-13T04:12:27","modified_gmt":"2021-02-12T17:12:27","slug":"cryptoscam-in-discord-fake-news-services","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/cryptoscam-in-discord-fake-news-services\/28898\/","title":{"rendered":"Discord cryptoscam: Attack of the clones"},"content":{"rendered":"<p>Since we <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord\/38661\/\" target=\"_blank\" rel=\"noopener nofollow\">described how scammers are tricking Discord users<\/a> into registering on fake cryptocurrency exchanges, they have harnessed new and even more effective techniques. What\u2019s the catch, and can you protect yourself?<\/p>\n<h2>Origins<\/h2>\n<p>In the earlier grift, members of Discord cryptocurrency communities received private messages from trading platforms supposedly giving away cryptocurrency. Potential victims received a link to register on the website of a cryptocurrency exchange, which was fake but looked real. Then, to get the free coins, they just had to verify their account, and to do that, they had to make a deposit.<\/p>\n<h2>New tricks<\/h2>\n<p>We recently discovered four new pseudo exchanges: Bitcmoney, Itmaxbit, Crypto24cap, and Bit24cap. The campaign built around them operates according to a similar but more sophisticated scenario.<\/p>\n<p>Most of the innovations seek to lower the victim\u2019s guard. Even the layout of the Discord messages became more discreet, with emojis and caps used a bit more judiciously.<\/p>\n<div id=\"attachment_38766\" style=\"width: 827px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041155\/cryptoscam-in-discord-fake-news-services-screenshot-1.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-38766\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041155\/cryptoscam-in-discord-fake-news-services-screenshot-1.png\" alt=\"Message from a fake cryptoexchange about free Bitcoin\" width=\"817\" height=\"828\" class=\"size-full wp-image-28899\"><\/a><p id=\"caption-attachment-38766\" class=\"wp-caption-text\">Message from a fake cryptoexchange about free Bitcoin<\/p><\/div>\n<p>Another technique designed to enhance the sense of legitimacy is including a code for users to confirm their registration. Bona fide sites often use such methods to protect against bots.<\/p>\n<div id=\"attachment_38767\" style=\"width: 884px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041204\/cryptoscam-in-discord-fake-news-services-screenshot-2.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-38767\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041204\/cryptoscam-in-discord-fake-news-services-screenshot-2.png\" alt=\"E-mail with registration confirmation code\" width=\"874\" height=\"965\" class=\"size-full wp-image-28901\"><\/a><p id=\"caption-attachment-38767\" class=\"wp-caption-text\">E-mail with registration confirmation code<\/p><\/div>\n<p>Those help, but the main innovation is the use of fake cryptocurrency news portals. Their function is twofold. First, links to the fake exchanges from other sites help <a href=\"https:\/\/developers.google.com\/search\/help\/site-position-in-search-faq\" target=\"_blank\" rel=\"nofollow noopener\">boost the fakes\u2019 search results<\/a>. Second, their very existence adds plausibility; trust in the media remains quite high, and the articles and posts underscore the portals\u2019 perceived reliability.<\/p>\n<p>For example, one fake report describes Crypto24cap as \u201cone of the largest cryptocurrency exchanges\u201d and \u201ca reputable platform suitable for both newbies and more advanced users.\u201d Another proclaims that 10 exchange members won cryptocurrency in a giveaway organized by the site.<\/p>\n<p>One sham article, seemingly published four months ago, talks about a Crypto24cap hack from May 2019, but the fake exchange\u2019s domain <a href=\"https:\/\/uk.godaddy.com\/whois\/results.aspx?domain=crypto24cap.com\" target=\"_blank\" rel=\"nofollow noopener\">wasn\u2019t registered until January 26, 2021<\/a>.<\/p>\n<div id=\"attachment_38768\" style=\"width: 1170px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041212\/cryptoscam-in-discord-fake-news-services-screenshot-3.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-38768\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041212\/cryptoscam-in-discord-fake-news-services-screenshot-3.png\" alt=\"What the fake cryptocurrency exchange Crypto24cap looks like\" width=\"1160\" height=\"760\" class=\"size-full wp-image-28903\"><\/a><p id=\"caption-attachment-38768\" class=\"wp-caption-text\">What the fake cryptocurrency exchange Crypto24cap looks like<\/p><\/div>\n<p>Checking the domains through WHOIS services reveals that the news services were created quite recently. Although not a smoking gun, the backdated publication of articles is very suspicious. What\u2019s more, the sites duplicate each other\u2019s content in many cases.<\/p>\n<p>Hence, simply by using publicly available tools and consulting different sources of information, cryptocurrency investors can save themselves a lot of money and hassle. That said, finding what you want to find online is easy. Skimming search result excerpts, you can easily come away with the impression that fake news sites like those we describe above are real \u2014 in other words, that the free money you\u2019ve been offered is real. Look instead for circumstantial evidence of a scam and you\u2019ll find it in the negative reviews and duplicated and backdated content.<\/p>\n<p>Aside from those described above, other changes, from the updated website design to the money-stealing mechanism, distinguish the new from the <a href=\"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord\/38661\/\" target=\"_blank\" rel=\"noopener nofollow\">original campaign<\/a>. For example, whereas previously, the pretext for siphoning cryptocurrency was account verification, now the withdrawal transaction appears to freeze for some time, after which the service asks for a deposit from the target wallet, supposedly to link the wallet to the account.<\/p>\n<div id=\"attachment_38769\" style=\"width: 605px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041225\/cryptoscam-in-discord-fake-news-services-screenshot-4.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-38769\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2021\/02\/13041225\/cryptoscam-in-discord-fake-news-services-screenshot-4.png\" alt=\"The fake exchange asks for a deposit of 0.02 BTC or 0.66 ETH to link the target wallet to the \" winner account width=\"595\" height=\"492\" class=\"size-full wp-image-28905\"><\/a><p id=\"caption-attachment-38769\" class=\"wp-caption-text\">The fake exchange asks for a deposit of 0.02 BTC or 0.66 ETH to link the target wallet to the \u201cwinner\u2019s\u201d account<\/p><\/div>\n<h2>How to stay safe<\/h2>\n<ul>\n<li>Be wary of promises of anything free or heavily discounted, and be especially suspicious of schemes requiring a payment to receive payment.<\/li>\n<li>Thoroughly research cryptocurrency exchanges before doing business with them. Size and popularity are useful measures. Look them on sites such as <a href=\"https:\/\/www.coingecko.com\/en\/exchanges\" target=\"_blank\" rel=\"nofollow noopener\">CoinGecko<\/a>, <a href=\"https:\/\/www.cryptocompare.com\" target=\"_blank\" rel=\"nofollow noopener\">CryptoCompare<\/a>, or <a href=\"https:\/\/coinmarketcap.com\/rankings\/exchanges\/\" target=\"_blank\" rel=\"nofollow noopener\">CoinMarketCap<\/a>, bearing in mind that even such sites, though reputable, are not the source of absolute truth: they may have bias, some show ads, and all are susceptible to hacking.<\/li>\n<li>Check the URL in the address bar, and use different passwords for each service to protect yourself from phishers and data leaks. And, to simplify managing your unique and complex passwords, use a <a href=\"https:\/\/www.kaspersky.com.au\/password-manager?icid=au_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">password manager<\/a>.<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/discord-privacy-security\/38546\/\" target=\"_blank\" rel=\"noopener nofollow\">Configure your privacy settings<\/a> to help you resist the onslaught of spammers and scammers in Discord.<\/li>\n<li>Protect your devices with a reliable security solution. For example, <a href=\"https:\/\/www.kaspersky.com.au\/plus?icid=au_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kplus___\" target=\"_blank\" rel=\"noopener\">Kaspersky Plus<\/a> gives you all the warnings you need about phishing and malware.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-banking\">\n","protected":false},"excerpt":{"rendered":"<p>Scammers are using fake news sites to lend legitimacy to their Bitcoin and Ethereum offers on Discord.<\/p>\n","protected":false},"author":2513,"featured_media":28907,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2646],"tags":[374,2620,3395,2672,726],"class_list":{"0":"post-28898","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-bitcoin","9":"tag-cryptocurrencies","10":"tag-discord","11":"tag-ethereum","12":"tag-scam"},"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/cryptoscam-in-discord-fake-news-services\/28898\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/cryptoscam-in-discord-fake-news-services\/22519\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/cryptoscam-in-discord-fake-news-services\/18011\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/cryptoscam-in-discord-fake-news-services\/24234\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/cryptoscam-in-discord-fake-news-services\/22301\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/cryptoscam-in-discord-fake-news-services\/21057\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/cryptoscam-in-discord-fake-news-services\/24752\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/cryptoscam-in-discord-fake-news-services\/23956\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/cryptoscam-in-discord-fake-news-services\/30112\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/cryptoscam-in-discord-fake-news-services\/9342\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/cryptoscam-in-discord-fake-news-services\/38764\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/cryptoscam-in-discord-fake-news-services\/16414\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/cryptoscam-in-discord-fake-news-services\/14492\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/cryptoscam-in-discord-fake-news-services\/26248\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/cryptoscam-in-discord-fake-news-services\/30055\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/cryptoscam-in-discord-fake-news-services\/26708\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/cryptoscam-in-discord-fake-news-services\/23558\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/cryptoscam-in-discord-fake-news-services\/28706\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/scam\/","name":"scam"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/28898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2513"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=28898"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/28898\/revisions"}],"predecessor-version":[{"id":28906,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/28898\/revisions\/28906"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/28907"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=28898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=28898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=28898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}