Telegram is the crypto hackers’ newest playground — and they have automated the process
- Cryptocurrency scammers are using bots on
Telegramto con investors into giving up their one-time-passwords (OTPs).
- The hackers use the OTPs to lock the original users out of their account and then steal their holdings.
- The bots are available for sale on Telegram too for around $300 per month.
AdvertisementFirst they got into emails, then onto WhatsApp, and now Telegram is the latest playing field for cryptocurrency scammers. Bots on the messaging platform are being tasked with getting investors to reveal their two factor authentication, which is then being used by hackers to log into the account, lock out the original users and then clean the house.
Rather than having to socially engineer elaborate conversations over phone or messages, the OTP bots automate the entire process so that it can be done at scale. This means more attacks — and more victims.
The growing threat of Telegram bots
These bots normally parade around pretending to be a help channel, according to a report by digital threat detection firm Q6 Cyber. It highlights that, not only are bots a growing threat, but that the damage they inflict is difficult to quantify.
And, they’re for sale even if you’re not a coder. An investigation by Intel471 revealed that a user only needs to pay a monthly fee of $300 in order to obtain the authentication code required to operate one of these bots. For another $20 to $100, they could have access to live phishing panels, which come ready with a list of possible targets — like users that confirmed members of Coinbase.
While SMS- and phone-call-based OTP services are better than nothing, criminals have found ways to socially engineer their way around the safeguards.
In July, last year, Indian crypto exchange ZebPay sent an alert out to its users warning them of a fake support group on Telegram trying to steal OTPs from users.
Scam Alert!There is a scam attempt going on the telegram in name of ZebPay Support.ZebPay will never ask you ask… https://t.co/w6DEM27Tbl— ZebPay (@zebpay) 1595937488000
The automated process of stealing information for users has given birth to a new underground industry — crime as a service. For an engineer, he doesn’t need to get his hands dirty — just provide the bot. And, for a thief, they longer necessarily need to have the technical know-how to steal things online.
The creative ways in which hackers are trying to steal digital currencies is on the rise, even with the prices of tokens being in the doldrums since the start of the year.
Russia-Ukraine conflict continues to play havoc on crypto prices
Tata Motors, Wipro, TCS, Nestle and other hot stocks on February 17
Popular on BI
- Flights could get bumpier as climate change makes air turbulence much more frequent
- A Swiggy user from Hyderabad spends Rs 6 lakh ordering idlis in a year
- Repo rate hike will slow down real estate, reverse post-Covid trends, says industry body to RBI
- Small stocks lag behind in FY23; take bigger hit than bluechip firms
- Tamil Nadu says 'nahi to dahi' over Hindi name on curd packets