Tech giant Google, X ads include crypto 'Drainer' malware used for crypto theft.
Hackers have devised a new scheme to steal cryptocurrency, draining nearly $58.98 million from 63,210 victims over the past nine months. This scam, dubbed "MS Drainer," utilizes fake versions of popular crypto sites and malicious ads to deceive users. Let's break down the key details of this cyber heist:
- Scam Scope: $58.98 million stolen from 63,210 victims
- Modus Operandi: Fake crypto sites and Google/X ads
- Target Platforms: Zapper, Lido, Stargate, DefiLlama, Orbiter Finance, Radiant
MS Drainer operates by employing "wallet drainers," blockchain technologies that enable attackers to siphon cryptocurrency from unsuspecting victims without their knowledge. Scammers typically achieve this by manipulating the token approval process.
The scheme first surfaced in March 2023, with security teams from SlowMist and ZachXBT contributing to its investigation. Further evidence emerged in June through the "Ordinal Bubbles" phishing scam linked to MS Drainer.
Researchers discovered nine different Google ads promoting the scam, with 60% directly linked to the drainer program. A staggering 10,072 fake websites utilizing MS Drainer were also uncovered.
Interestingly, the MS Drainer developer employed an atypical marketing strategy. Unlike most wallet drainers that take a percentage of stolen funds, MS Drainer was advertised on forums for a flat fee of $1,499.99. Additional "modules" offering advanced features were available for purchase at varying prices.