Search This Blog

Powered by Blogger.

Blog Archive

Labels

Showing posts with label Cypto. Show all posts

Phishing Campaign Uses Flipper Zero to Steal Crypto and Sensitive Data Worldwide


What is the Flipper Zero campaign?

Experts have found a new phishing campaign that targets cybersecurity professionals and hacking enthusiasts. The campaign steals cryptocurrency and the personal information of victims. 

Flipper Zero is behind the attack, it's a portable multi-tool for pentesters, cybersecurity experts, and hackers. The tool is used to find any type of access control system, radio protocols or RFID, NFC, Bluetooth, etc. 

The tool began as a big-hit Kickstarter project but met with various obstacles. Result? Demand weighed more than supply- giving a big opportunity to cybercriminals. Today, experts are noticing various fake online stores that sell Flipper Zero and fake Twitter profiles promoting the stores. One such account uses typosquatting to fool people by cleverly replacing a letter in the spelling because the "L" in Flipper is an uppercase "i." Such accounts are currently very active, providing immediate responses to customer queries. 

Stealing crypto and data via Flipper Zero

People who fall under this trap will in the end get redirected to the phishing checkout page, where they are asked to submit a lot of sensitive data- email id, name, and residential address. Additionally, there's only one way to pay on these pages- cryptocurrency (bitcoin or ether). 

But the experts are saying that the wallets displayed on fake shops are empty, which can only mean two things, either the scammers keep changing their addresses to avoid getting doxed or no one actually fell for the trick. 

The company is struggling to battle this campaign, as it has now reached Instagram as well. The company tweeted: “Dear @Instagram and @InstagramComms, there are hundreds of fake and scam accounts imitating our official Flipper Zero Instagram account. These fraudulent accounts try to fool people and steal money. We can't report them because we are rejected to have a verified blue check mark.” 

What next for Flipper Zero?

The Flipper Zero Kickstarter campaign was last active in 2020, and it was a big hit. Initially, the campaign goal was $60,000 but it received a massive amount of over $4.8 million in pledges. The first users shared their feats on social media, and it received much appreciation from the audience, which pushed the production even more. But the production hit the brakes when PayPal held $1.3 million for months. 

In September 2020, the Flipper Zero team said that PayPal decided to hold the amount without giving any reason and later suspended the company's account, compromising the entire project. In November 2020, Flipper Zero with the help of a legal team managed to get back around three-quarters of the fund ($980,000), but PayPal kept around $350,000 to "mitigate possible claims."