HomeSecurityTalkTalk hackers also invaded EtherDelta

TalkTalk hackers also broke into EtherDelta

US authorities have charged two suspects in the December 2017 hack of cryptocurrency exchange EtherDelta, changing the website’s DNS settings and redirecting traffic to a clone, where they recorded user credentials and then stole customers’ money. One of the two suspects is Elliott Gunton, also known as “Glubz,” a 20-year-old from the United Kingdom, known for his role in the TalkTalk hack. The other is Anthony Tyler Nashatka, also known as “psycho,” who lives in New York. Both went from buying an EtherDelta employee’s phone number on the black market to stealing money from thousands of EtherDelta users in the space of a week.

EtherDelta

Hacker obtained the personal information of Etherdelta CEO

According to court documents, it all appears to have started on December 13th, when Nashakta purchased the personal information of an EtherDelta employee. The data believed to have been obtained included the employee ’s phone number and email address .

While court documents refer to this employee as ZC, this person is believed to be Zachary Coburn, the CEO , since only his accounts would have allowed the hacker to do what he did next.

The court documents do not say whether Nashakta specifically targeted Coburn’s data because he was EtherDelta’s CEO or whether the hacker found it by mistake and then realized who he was. However, later, recognizing the value of the details he had obtained, Nashakta contacted Gunton and planned to take over EtherDelta’s ClouDD and DreamHost accounts.

Hackers forwarded calls from the CEO's phone number

Court documents reveal that Gunton somehow managed to convince a cell phone operator to add a call forwarding number to Coburn's cell phone account.

This meant that all incoming calls to Coburn's phone would be quietly forwarded to a Google Voice number so they would both receive the calls.

Gunton and Nashatka wasted no time and immediately used the call forwarding feature to bypass two-factor authentication (2FA) on Coburn's EtherDelta (admin) account.

A day later, on December 20, they began orchestrating their hack. They first began by modifying the DNS settings on the company's G Suite portal and redirecting Gmail traffic through a server in the United Kingdom that they owned, allowing them to monitor and hide certain emails.

The next step was to reset the password on Cloudflare , retrieve the reset link from Coburn's emails, and gain access to the Cloudflare account as the new owners, changing the password and locking out the company's other employees.

The final step was to change EtherDelta's DNS records within the Cloudflare account and add new ones, with the official EtherDelta website now located on their webserver. Here, the two hackers hosted a clone of the original website, as well as one that logged users' credentials.

The DNS redirection was detected a few hours later and of course was reported in all the media.

After their scheme was exposed, they naturally proceeded to steal money from users. While court documents don't state the total amount they stole, one victim reports losing more than $800,000.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS