A multi-stage bitcoin scam exposed and exploited personally identifiable information (PII) to trick users into signing up for a malicious site. Researchers identified approximately 250,000 unique files. The malicious actors behind the bitcoin scam created sites that featured fake interviews and comments from celebrities praising a cryptocurrency trading platform.
In the first stage of the celebrity-baiting scam, individuals are sent a message informing them that a celebrity has managed to increase their income thanks to a “smart” investment. The message includes a link that supposedly leads the recipient to proof of their claims, which is the second stage. The sender of the message appears to come from a trusted source, but in reality, it is not. Clicking on the URL opens a website that is supposed to be a trusted local news source, according to researchers at Singapore-based cybersecurity firm Group-IB

The malicious actors set up their operation in such a way that victims in different regions would be directed to websites that looked like legitimate websites in their region. For example, users in the United Kingdom would be directed to a page that supposedly belonged to the newspapers “The Sun” and “Mirror”. Potential victims located in Australia would be directed to a fake ABC (Australian Broadcasting Corporation) website. Users in Singapore were directed to a page that supposedly belonged to the newspaper “The Straits Times”.

Group-IB found that the URL of the malicious platform includes the victims’ personal information, which is used to fill in fields to create accounts. The content on all of the fake websites is designed to lure the target into the bitcoin scam. Specifically, it shows users fake interviews and comments from famous figures in each user’s region, who claim to have made a fortune using a specific trading , such as Crypto Cash, Bitcoin Rejoin, Bitcoin Supreme, and Banking on Blockchain.
Among the names used by the scammers are American singer Chris Brown, Australian entrepreneurs Andrew Forrest, Travers Beynon and Gina Rinehart, and Singaporean actor and TV host Bryan Wong. All links on these pages direct to the alleged service, where targets can create an account and activate it for a small fee of 0.03 BTC, or about $270.

However, it is unclear how the scammers obtained the personally identifiable information (PII), but the bitcoin scam exposed phone numbers, first and last names, and, in some cases, email.
A company spokesperson told BleepingComputer that researchers identified 248,926 unique URLs, each with a set of PII. Ilya Sachkov, CEO of Group-IB, said that scammers can use personal user data to increase the success rate of the campaign, as victims are more likely to fall for the attacks.
Ilya Sachkov also added that people often underestimate the risks of publishing their names, phone numbers or emails onlineuntil something bad or extreme happens. In fact, such a large amount of sensitive and confidential data in the wrong hands opens up a whole new world of opportunities for fraudsters. This data can be sold, or it can pave the way for a new scam.
Below is an analysis of the attack steps.

Most of the victims come from the United Kingdom (147,610) and Australia (82,263), with the rest from South Korea, Singapore, Malaysia) and Spain (less than 5,000 in each of them). The origin of the personal information remains unclear, since researchers could not find it in breach or on marketplaces that trade this type of “goods”. However, it is speculated that the malicious actors obtained the information through a different scheme or purchased it from a third party.
