
According to a new investigation by Abnormal Security, some cybercriminals have been impersonating the well-known Bitcoin trading platform, BTC ERA, in order to infect its users with malware.
The security firm found that hackers were sending emails purporting to come from BTC Era and encouraging Bitcoin users to donate money for a supposed investment.
The automated email addresses the recipient by name and says that a Bitcoin transaction has been approved, requiring a minimum deposit of $250 to initiate. The message includes a hidden URL with text that says “create account.” Once this link is clicked, multiple redirects occur, and the user is eventually taken to theverifycheck.com. Once the user reaches the page, a pop-up appears asking for permission to display notifications from the site.
If the user clicks to allow notifications, they are giving permission for an Adware to run on their device. Users don't realize it, but the site allows their activities to be tracked and ads and spam messages to be displayed.

Abnormal Security added that the scammers used email marketing provider Constant Contact, which allowed them to deliver the malicious emails to multiple recipients at once. The company said this “requires less effort than spoofing emails and is more effective at deceiving many unsuspecting users.”
Ken Liao, a key executive at Abnormal Security, commented: “We have seen that over the past few months the weekly volume of attacks impersonating Bitcoin platforms has remained relatively stable. However, we saw an increased percentage of these impersonations from late March to early May.”
He added: “We would advise organisations and employees to thoroughly check email senders and addresses to ensure they are from legitimate sources. Don’t just trust the name that appears. Furthermore, we recommend that everyone always check the website URL before connecting.”
“Attackers often hide malicious links or host them on separate sites that you can reach with secure links. This allows them to bypass the link scanning offered by traditional security email. If the URL looks suspicious, do not enter credentials and always verify with your company’s IT department.”
