Phantom X Profile picture
Security Researcher | Explorer of the Digital Ether | Kimchi Says Hello 🧐. Focused on #Cybercrime #Phishing #APT #ThreatIntel #InfoSec
Sep 4, 2022 20 tweets 10 min read
🚨 North Korean APT group responsible for crypto and NFT phishing campaign spanning over 190 domains

Targeting dozens of $ETH and $SOL projects.

Uses collections on NFT marketplaces to lure victims to malicious minting sites.

🧵1/

#Phishing #NFT #NorthKorea #cybercrime Campaign activity began in April and is on-going.

The following domains have been registered in the past three days:

golddao[.]site
seveneyes[.]online
tapfantasy[.]in
genmarket[.]app
moonbirdvictorian[.]app
disneyprincessnft[.]com

Full list of domains at the end.

2/ DPRK phishing site golddao.siteDPRK phishing site seveneyes.onlineDPRK phishing site tapfantasy.inDPRK phishing site genmarket.app
Jun 26, 2022 8 tweets 9 min read
Possible nexus noted between an actor conducting Naver phishing and now Crypto.

Email gameproducters@outlook[.]com reported by @prevailion has also registered boredsnakesclub[.]com a typo squat of the legitimate BoredSnakesClub website. 1/

prevailion.com/what-wicked-we…

#Phishing Previous reporting on gameproducters@outlook[.]com listed them as registering dozens of Naver-themed phishing domains, examples below. 2/

navercomf[.]link
navercnid[.]link
naverdcom[.]click
navercomd[.]link
navernidc[.]link
naveracom[.]link
naverecom[.]click

#Phishing #Naver