Researchers from Cisco's OpenDNS security team have uncovered a complex phishing scheme aimed at harvesting user credentials from various Bitcoin-related services, which, upon closer inspection, led to a known rogue hosting company.
The first to stumble upon this campaign were security researchers from CYREN, who spotted it during the first week of June.
The scammers behind the phishing campaign relied on perfectly cloned Web pages for various Bitcoin wallet services, with a particular focus on Blockchain.info, one of the most important sites in the Bitcoin ecosystem.
The phishers ran a Google AdWords campaign to lure victims into their malicious websites, registered using typosquatting domains, such as bioklchain.info instead of blockhain.info.
What caught the attention of the OpenDNS was that some of these websites were hosted on IP addresses that had a history.
Searching OpenDNS's massive Whois database, the team discovered that the same IP had hosted a multitude of malicious sites in the past, such as pharma spam and other phishing domains, for services such as banking portals, iCloud accounts, and more.
Additionally, most of these phishing domains were registered with just six email addresses. OpenDNS says the oldest of these domains was registered on May 26, 2016 .
The IP belonged to a company called Novogara, registered in the Seychelles. The company’s previous name was QUASINETWORKS. Before that, it was called Ecatel and was initially operating in the Netherlands until December 2015.
In the Web hosting industry, Novogara is what is called a "bulletproof hosting provider," which refers to companies that do everything they can to protect their customers, even if they know their customers are engaging in illegal activities.
These types of companies use safe harbor provisions in legislation around the world that allow them to defer legal liability for their customers. They also charge more than regular hosting providers, mainly because they turn a blind eye to what their customers do.
In the past, Novogara has been linked to child pornography, spam, and DDoS traffic sites. The company's toxic traffic became so bad in 2008that its fellow companies stopped doing business with Novogara (then Ecatel). In 2012, the Anonymous collective launched multiple DDoS against the network for hosting child pornography.
However, if it's not Novogara, then it's someone else. Such companies exist everywhere, from the US to Romania and from Russia to China.


