New Phishing Campaign is Targeting TrustWallet With Impersonation Emails

Stu Sjouwerman | Jul 6, 2022

Phishing Campaign Targeting TrustWalletVade Secure warns that a phishing campaign is targeting TrustWallet cryptocurrency wallet users with phony verification emails.

“The phishing email itself impersonates the TrustWallet brand,” the researchers write. “[T]he TrustWallet logo matches TrustWallet’s official logo and includes a support link titled ‘Support 2022.’ Additionally, Zendesk’s legitimate footer appears at the bottom of the email, giving the email an additional air of legitimacy from a known, trusted brand.... The phishing email informs the user that their wallet must be verified due to an NFT update. Failing to verify the wallets, the email warns, will result in account suspension. The user is encouraged to verify their account by June 15 by clicking on a phishing link with the CTA ‘Verify your wallet.’

After clicking the link, the user is taken to a convincingly spoofed TrustWallet page that asks them for their recovery phrase.

“The user is asked to enter their recovery phrase to unlock their wallet,” the researchers write. “Most cryptocurrency wallets use 12-word recovery phrases, but in some cases, they may use 24. The phisher has considered this and includes a button to click if the user does in fact use a 24-word recovery phrase. This technique accomplishes two things: First, it makes the phishing page seem more legitimate in the eyes of the user because it has covered both scenarios. Second, the phishing page can accept credentials from either 12- or 24-word recovery phrases, widening the scope of the phishing campaign.”

The researchers conclude that users need to be wary of messages like this, even if the email address appears legitimate.

“While inspecting the sender email address is an important step in scrutinizing an email for signs of email spoofing in phishing, it is not always enough to recognize an attack,” Vade says. “As is the case in this TrustWallet phishing attack, the email address is a legitimate, albeit malicious Zendesk email, so inspecting the domain is not helpful in recognizing the attack.”

New-school security awareness training can teach your employees to follow security best practices so they can avoid falling for social engineering attacks.

Vade Secure has the story.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.