16/01/2023 Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

A sponsored advertising link on Google hid malware that siphoned thousands of dollars worth of crypto and NFTs from an influencer’s wallet.

Google Ads-delivered malware drains NFT influencer’s entire crypto wallet

An NFT influencer claims to have lost “a life-changing amount” of their net worth in nonfungible tokens (NFTs) and crypto after accidentally downloading malicious software found via a Google Ad search result.

The pseudo-anonymous influencer known on Twitter as “NFT God” posted a series of tweets on Jan. 14 describing how his “entire digital livelihood” came under attack including acompromise of his crypto walletand multiple online accounts.

NFT God, known also as “Alex,” said he used Google's search engine to download OBS, an open-source video streaming software. But instead of clicking on the official website, he clicked the sponsored advertisement for what he thought was the same thing.

It wasn’t until hours later — after a series of phishing tweets posted by attackers on two Twitter accounts that Alex operates — that he realized malware was downloaded from the sponsored advertisement alongside the software he wanted.

Following a message from an acquaintance, Alex noticed his crypto wallet was also compromised. The next day, attackers breached his Substack account and sent phishing emails to his 16,000 subscribers.

Blockchain data shows that at least 19 Ether worth nearly $27,000 at the time, a Mutant Ape Yacht Club (MAYC) NFT with a current floor price of 16 ETH ($25,000), and multiple other NFTs were siphoned from Alex’s wallet.

The attacker moved most of the ETH through multiple wallets before sending it to the decentralized exchange (DEX) FixedFloat, where it was swapped for unknown cryptocurrencies.

Alex believes the “critical mistake” that allowed the wallet hack was setting up his hardware wallet as ahot wallet by entering its seed phrase“ in a way that no longer kept it cold,” or offline, which allowed the hackers to gain control of his crypto and NFTs.

Unfortunately, NFT God’s experience isn’t the first time the crypto community has dealt with crypto-stealing malware in Google Ads.

A Jan. 12 report from cybersecurity firm Cyble warned of an information-stealing malware called “Rhadamanthys Stealer” spreading through Google Ads on “highly convincing phishing webpage[s].”

In October, Binance CEO Changpeng “CZ” Zhao warned that Google search results were promoting crypto phishing and scamming websites.

Cointelegraph contacted Google for comment but did not receive a response. In its help center, however, Google said it “actively works with trusted advertisers and partners to help prevent malware in ads.”

It also describes its use of “proprietary technology and malware detection tools” to regularly scan Google Ads.

Cointelegraph was unable to replicate the results of Alex’s search nor verify if the malicious website was still active.

Arts

google-ads-delivered-malware-drains-nft-influencers-entire-crypto-wallet

Interesting NFTs
David vs the Virus
"An ode to the year everything changed" - Frank Wilder The story of the underdog is a reoccurring theme throughout history, and perhaps the most famous example is that of David vs Goliath. A tale about perseverance, in which David takes on and defeats the giant warrior using only his smarts and a stone. Famously depicted by Michelangelo's David statue. Fast forward to the present day in 2020 and we as humanity are faced with our own Goliath. An uncontrollable pandemic spread around the globe. Now with the entire planet being affected by this we understand the gravity of the situation at hand, whether it be a virus we’re fighting or other forces at play, there is indeed an energy out to shift the balance of the Universe… Regardless of our differences, in this moment must unite as one. With diligence, trust and belief we as a whole can come together to triumph against "the enemy". Stay vigilant my friends. Original score created by the one and only Phoenix Wilder.
CryptoFinney 446 of 481
name CryptoFinney img QmdpUhYbJBz1mcBWUSUijMcbDZYSrVtn2WtNuHfrzxS38G/finney_2_1_1_4_4_4_8_4_0_5_1_2_4_a.png backimg QmdpUhYbJBz1mcBWUSUijMcbDZYSrVtn2WtNuHfrzxS38G/finney_2_1_1_4_4_4_8_4_0_5_1_2_4_b.png cardimg QmRwteLfCXy8MbNfhKomtbhn1LqEQoT1agMpXEBX6tkP5J metal Gold skin Dark eyes Blue torso Red T-Shirt legs Black Trousers feet Runners rarity Ethereum Cap, 80's Sunglasses, Green Mask, Brown Jacket, Pink Watch artist Jon Trafford release CryptoFinney Genesis url writer.io Mint number - 446of481
Bored Ape Yacht Club #2087
The Bored Ape Yacht Club is a collection of 10,000 unique Bored Ape NFTs— unique digital collectibles living on the Ethereum blockchain. Your Bored Ape doubles as your Yacht Club membership card, and grants access to members-only benefits, the first of which is access to THE BATHROOM, a collaborative graffiti board. Future areas and perks can be unlocked by the community through roadmap activation.
Traffic
Traffic explores a crossroads between the metaverse & reality through organized chaos. The complexity of this aural / visual landscape demanded over 200 hours of design time between Slimesunday & 3LAU. Every detail of this piece was built from scratch, from the reflective puddled pavement to the stabbing synthesis of the song. We think we'll be spending a lot more time in the metaverse in the future, don't you?
#2921
By OthersideDeployer