Google and Twitter (now X) ads are promoting websites containing a crypto drainer called “MS Drainer.” This malware has already stolen $59 million from over 63,000 victims in the last nine months.

According to blockchain threat analysts at ScamSniffer, over ten thousand phishing sites distributed the crypto drainer from March 2023 to the present. Increased activity was observed in May, June, and November.
MS Drainer is a full phishing suite designed to steal funds from users' cryptocurrency wallets without their consent.
Users are directed to a phishing website that appears legitimate and trustworthy and are tricked into approving malicious contracts, which allow the crypto drainer to automatically perform unauthorized transactions and transfer the victim's funds to the attacker's wallet address.
See also: Crypto scammers abuse Twitter feature to impersonate well-known accounts
The source code for MS Drainer is being sold to cybercriminals for $1,500 by a user named “ Pakulichev ” or “ PhishLab .” There is an additional 20% fee on the money obtained through the crypto drainer. PhishLab also sells extra modules that add more features to the malware (costing between $500 and $1,000).
One of the victims is said to have lost $24 million worth of cryptocurrencies, while other notable cases involve victims who lost between $440,000 and $1.2 million.
Fraudulent ads on Google and X promote crypto drainer MS Drainer
On Google, MS Drainer is promoted through malicious ads that appear when someone searches for keywords related to platforms such as Zapper, Lido, Stargate, Defillama, Orbiter Finance, and Radiant.
Many of these ads exploit the Google Ads tracking template loophole to make the phishing URL appear to belong to the official domain. However, if someone clicks on it, they are redirected to a phishing site.
On X (formerly Twitter), there are a lot of ads for MS Drainer. In fact, many of them are posted by legitimate “verified” accounts that bear the blue check mark.
See also: Founder of Bitzlato crypto exchange admits service was used for money laundering
Security researcher MalwareHunterTeam, who has been tracking similar ads, told BleepingComputer that holders account may have been infected with malware, and attackers may be posting the malicious ads from the hacked accounts. He contacted an account X that was advertising this crypto drainer and was told that there was no trace of the ads on their advertising accounts.

In X, cybercriminals used several themes for their ads, including one called “Ordinals Bubbles,” which promoted a purported limited-edition NFT (non-fungible token) collection featuring various characters encased in bubbles.
The ads also promoted NFT airdrops and new tokens on websites containing the drainer.
The malicious ads are said to use geofencing, which means that only users from predefined regions are targeted and the rest are redirected to legitimate/harmless websites.
Crypto scams have always been quite successful on X. Now, with ads appearing from trusted (but hacked) accounts, things are going to get even worse.
See also: North Korean hackers have stolen $3 billion worth of crypto since 2017
Users should be very careful when seeing ads related to crypto.
What mistakes do crypto users make and lose their funds?
One of the most common mistakes crypto users make is using weak passwords. This allows attackers to easily hack into their accounts and gain access to their cryptocurrencies.
Another common mistake is storing cryptocurrencies in online wallets or exchange platforms that are vulnerable to attacks. This can lead to massive loss of cryptocurrencies.
Not using two-factor authentication is also a common mistake that users. This leaves their accounts vulnerable to phishing attacks and other hacking methods.
Furthermore, opening strange links, like those ads we mentioned above, is dangerous. Visit official sites, and avoid ads.
Finally, many users overlook the need to update and refresh their security software. This can leave their devices vulnerable to new types of attacks that can destroy their cryptocurrencies.
source: www.bleepingcomputer.com
