A relatively new phishing service called “ Inferno Drainer ” has allegedly stolen over $5.9 million worth of crypto from 4,888 victims. According to a report by Web3Anti-Scam firm “ Scam Sniffer ,” the phishing service has created at least 689 fake websites since late March of this year.

Most of the phishing websites created with the service appeared online after May 14, 2023.
See also: New PhaaS “Greatness” simplifies Microsoft 365 phishing attacks
The malicious websites target 229 popular brands, including Pepe, Bob, MetaMask, OpenSea, Collab.Land, LayerZero, and others.
Scam Sniffer researchers discovered the Inferno Drainer phishing service for crypto theft after they identified a member who promoted the service on Telegram by posting a screenshot proving the theft of $103,000.
“ By searching for the transaction hash hidden in the screenshot, we found this transaction in ScamSniffer’s database and correlated it with some known malicious addresses in database our malicious address ,” Scam Sniffer explains
The Inferno Drainer service promotes multi-chain fraud, Aave token and Art Blocks theft, MetaMask token approval exploits, and more.
See also: Spain: Gang of criminals involved in phishing and bank fraud dismantled
The creators of the “drainer” toolkit provide a modern admin panel with customization options and also offer a trial for interested buyers.
Operators pay Inferno Drainer 20% of their revenue. They can pay up to 30% for services that involve creating phishing sites. However, BleepingComputer reports that due to high demand, the service only offers phishing sites to “good customers,” or customers who have proven their ability to generate a lot of money.
Inferno Drainer
Scam Sniffer investigated the operation of the Inferno Drainer phishing service and found that it had been active since February 2023. However, it increased its activities since mid-April 2023.

One of the biggest victims identified by analysts lost $400,000 worth of crypto.
See also: Gmail: Billions of users at risk of phishing attack
Scam Sniffer says that the threat are distributing the funds they collect to five crypto addresses that currently hold between 250 and 400 ETH.
Crypto holders should be vigilant with all transactions, treat incoming messages with skepticism, verify the sender’s identity, use multi-factor authentication to protect their accounts, and keep their software up to date. Another option is to store cryptocurrencies in a cold wallet. A cold wallet is a wallet that stores crypto offline and is therefore inaccessible to malicious users. This type of wallet provides multiple ways of protection, such as a coded pin and encryption.
Source: www.bleepingcomputer.com
