Telegram is the crypto hackers’ newest playground — and they have automated the process

Advertisement
Telegram is the crypto hackers’ newest playground — and they have automated the process
Telegram rayapp3雷竞技官网APP商业内幕
  • Cryptocurrency scammers are using bots on Telegramto con investors into giving up their one-time-passwords (OTPs).
  • The hackers use the OTPs to lock the original users out of their account and then steal their holdings.
  • The bots are available for sale on Telegram too for around $300 per month.
Advertisement
First they got into emails, then onto WhatsApp, and now Telegram is the latest playing field for cryptocurrency scammers. Bots on the messaging platform are being tasked with getting investors to reveal their two factor authentication, which is then being used by hackers to log into the account, lock out the original users and then clean the house.

Rather than having to socially engineer elaborate conversations over phone or messages, the OTP bots automate the entire process so that it can be done at scale. This means more attacks — and more victims.

The growing threat of Telegram bots


These bots normally parade around pretending to be a help channel, according to a report by digital threat detection firmQ6 Cyber. It highlights that, not only are bots a growing threat, but that the damage they inflict is difficult to quantify.

And, they’re for sale even if you’re not a coder. An investigation byIntel471revealed that a user only needs to pay a monthly fee of $300 in order to obtain the authentication code required to operate one of these bots. For another $20 to $100, they could have access to live phishing panels, which come ready with a list of possible targets — like users that confirmed members ofCoinbase.

While SMS- and phone-call-based OTP services are better than nothing, criminals have found ways to socially engineer their way around the safeguards.

Excerpt from a report by Intel471 dated September 2021

Crime-as-a-service


Advertisement

In July, last year, Indian crypto exchange ZebPay sent an alert out to its users warning them of a fake support group on Telegram trying to steal OTPs from users.


The automated process of stealing information for users has given birth to a new underground industry — crime as a service. For an engineer, he doesn’t need to get his hands dirty — just provide the bot. And, for a thief, they longer necessarily need to have the technical know-how to steal things online.

The creative ways in which hackers are trying to steal digital currencies is on the rise, even with the prices of tokens being in the doldrums since the start of the year.

SEE ALSO:
Russia-Ukraine conflict continues to play havoc on crypto prices
Tata Motors, Wipro, TCS, Nestle and other hot stocks on February 17
{{}}