HomeSecurityPhishing attacks against Celsius Network Creditors intensify

Phishing attacks against Celsius Network Creditors intensify

Scammers are impersonating the bankruptcy claim agent for crypto lender Celsius in phishing attacks attempting to steal money from cryptocurrency wallets.

See also: Company announcement about Free Download Manager site that spread Linux malware

Phishing attacks against Celsius Network Creditors intensify

In July 2022, crypto lender Celsius filed for bankruptcy and froze withdrawals from users’ accounts. Customers have filed claims against the company, hoping to recover some of their funds.

In recent days, people have been reporting receiving email scams pretending to be from Stretto, the Claims Agent for Celsius' insolvency proceedings.

A recipient shared the phishing email with BleepingComputer, which claims to offer creditors a 7-day window to access their frozen funds.

See also: International Criminal Court: It fell victim to a cyberattack

The email claims to be from “Stretto Corporate Restructing,” using the email address no-reply@stretto.com, as shown below.

Phishing attacks against Celsius Network Creditors intensify

The phishing email includes a link to the website case-stretto[.]com, which redirects the recipient to the phishing site pretends-stretto[.]com below. The claims-stretto[.]com domain was registered today and is hosted on a web hosting provider in the Seychelles.

The legal Stretto website for Celsius claims is located at https://cases.stretto.com/celsius/claims/.

Phishing attacks against Celsius Network Creditors intensify

On the page, visitors are asked to enter their email address to retrieve their application, and when the submit button is pressed, a WalletConnect window opens to connect your installed cryptocurrency wallet to the website.

Phishing attacks against Celsius Network Creditors intensify

By linking a wallet, the site will now have access to all the information stored within, including cryptocurrencies, balances, activity , and the ability to suggest transactions.

Phishing attacks against Celsius Network Creditors intensify

With this connection in place, hackers can attempt to empty all assets and NFTs stored in the wallet by presenting the transaction as a deposit.

Passes SPF checks

This offensive campaign stands out because the emails pass Sender Policy Framework (SPF) checks, which determine whether an email comes from a valid email server for the sending domain.

SPF performs this check by comparing the IP address of the mail server sending the email with a list of IP addresses found in the SPF DNS record for the domain used in the mail header 'Return-Path'.

In this case, the return path of the phishing email is 'bounces+xxx-xx=xxx.com@em6462.stretto.com', with em6462.stretto.com having an SPF record v=spf1 ip4:149.72.171.199 -all. This SPF record means that any emails from 149.72.171.199 should be considered valid and not marked as spam.

As these phishing emails originate from the IP address 149.72.171.199, which belongs to email marketing company SendGrid, they pass the SPF check and are allowed for delivery.

Below is the image (some information has been removed), where the email is successfully delivered to Gmail after successful SPF checks.

Phishing attacks against Celsius Network Creditors intensify

One of the recipients of these phishing emails told BleepingComputer that they did not have an account with Celsius and had never applied as a lender, which makes it strange that they received this email.

The attackers are likely using older contact lists that were previously stolen through hacked cryptocurrency marketing accounts.

BleepingComputer reached out to Stretto to confirm whether their SendGrid account was compromised to send these emails, but did not receive a response.

If you receive an email claiming to be about Celsius' claims, ignore it and check for new updates about the case on the legitimate website https://cases.stretto.com/celsius/.

Unfortunately, if you have already visited one of these scam sites and lost funds or NFTs after connecting your wallet, there is likely no way to recover your assets.

Celsius has previously reported similar phishing attacks used to steal creditors' funds.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS