In cybersquatting and phishing, threat actors have created a site that “imitates” the legitimate service Privnote.com, with the goal of stealing bitcoin. The creators of the legitimate Privnote.com expressed concern that someone had created a fake version of their site to trick users into using it. Not long ago, KrebsOnSecurity learned that the owners of Privnote.com were concerned that someone had created a “clone” of their site that was deceiving several regular users of the service, as reported by investigative security Brian Krebs. The legitimate site Privnote.com offers the ability to send encrypted notes that can be shared with other users. Now, a site called Privnotes.com has been created that imitates the authentic Privnote.com. The Privnotes clone site added ads to Google Search so that its results would surpass the "organic" results.

This means that whenever a user types “privnote (s)” into the search, Google will first display the “fake” Privnotes.com ad. The developers of Privnote.com discovered that the clone site not only does not implement encryption but also steals bitcoins by changing the pasted addresses.

With the help of security expert Allison Nixon, Krebs discovered that Privnotes.com was created to steal cryptocurrency payment requests sent through their platform. When the contents of a paste include a Bitcoin address, the creator of the fake site changes the Bitcoin address to one under his control, with the goal of stealing bitcoins. Additionally, to avoid detection, the first four characters of the changed Bitcoin address are the same as the address originally pasted. Also, to make this behavior difficult for an end user to detect, the Bitcoin address is only changed if the accessed from a different IP address than the creator’s.

However, when tested by BleepingComputer using a VPN and individual incognito sessions (to avoid tracking via cookies), it appeared that the site had for now reversed the malicious behavior. The Bitcoin addresses remained the same in BleepingComputer’s tests. For example, the BleepingComputer team sent a message containing the Bitcoin address “3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy”. On a different computer, the same Bitcoin address was received by the recipient at a different IP address. While both sites offer a “secure connection” using SSL/TLS, Bleeping Computer noted the obvious differences between certificates : The fake Privnotes.com uses a free Let’s Encrypt certificate. Using a Let’s Encrypt certificate does not necessarily mean that a site is malicious. However, Let’s Encrypt is an attractive option for scammers creating phishing sites. This sophisticated scam is a wake-up call for both end users and site creators whenever they share sensitive information online. In this case, users may not have realized that the Privenotes site is fake.
