New Phishing Campaign is Targeting TrustWallet With Impersonation Emails

Phishing Campaign Targeting TrustWalletVade Secure warns that a phishing campaign is targeting TrustWallet cryptocurrency wallet users with phony verification emails.

“The phishing email itself impersonates the TrustWallet brand,” the researchers write. “[T]he TrustWallet logo matches TrustWallet’s official logo and includes a support link titled ‘Support 2022.’ Additionally, Zendesk’s legitimate footer appears at the bottom of the email, giving the email an additional air of legitimacy from a known, trusted brand.... The phishing email informs the user that their wallet must be verified due to an NFT update. Failing to verify the wallets, the email warns, will result in account suspension. The user is encouraged to verify their account by June 15 by clicking on a phishing link with the CTA ‘Verify your wallet.’

After clicking the link, the user is taken to a convincingly spoofed TrustWallet page that asks them for their recovery phrase.

“The user is asked to enter their recovery phrase to unlock their wallet,” the researchers write. “Most cryptocurrency wallets use 12-word recovery phrases, but in some cases, they may use 24. The phisher has considered this and includes a button to click if the user does in fact use a 24-word recovery phrase. This technique accomplishes two things: First, it makes the phishing page seem more legitimate in the eyes of the user because it has covered both scenarios. Second, the phishing page can accept credentials from either 12- or 24-word recovery phrases, widening the scope of the phishing campaign.”

The researchers conclude that users need to be wary of messages like this, even if the email address appears legitimate.

“While inspecting the sender email address is an important step in scrutinizing an email for signs of email spoofing in phishing, it is not always enough to recognize an attack,” Vade says. “As is the case in this TrustWallet phishing attack, the email address is a legitimate, albeit malicious Zendesk email, so inspecting the domain is not helpful in recognizing the attack.”

New-school security awareness training can teach your employees to follow security best practices so they can avoid falling for social engineering attacks.

Vade Secure has the story.

Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Topics: Phishing

Subscribe To Our Blog

Ransomware Hostage Rescue Manual

Get the latest about social engineering

Subscribe to CyberheistNews