Interview with a Crypto Scam Investment Spammer

[ad_1]

Social networks are constantly fighting against inauthentic bot accounts that send direct messages to users promoting fraudulent cryptocurrency investment platforms. The following is an interview with a Russian hacker responsible for a series of aggressive crypto spam campaigns that recently caused several large Mastodon communities to temporarily suspend new registrations. According to the hacker, their spam software was used for private purposes until recent weeks when it was released as open source code.

Renaud Chaput is a freelance programmer working on modernizing and scaling Mastodon project infrastructure, including joinmastodon.org, mastodon.online, and mastodon.social. Chaput said that on May 4, 2023, someone unleashed a torrent of spam targeting users of these Mastodon communities via private mentions, a kind of direct messaging on the platform.

The messages stated that the recipients had obtained investment credit on a cryptocurrency trading platform called moonxtrade[.]com. Chaput said spammers used more than 1,500 internet addresses across 400 providers to register new accounts, which then followed popular accounts on Mastodon and sent private mentions to followers of those accounts.

Since then, the same spammers have used this method to advertise over 100 different crypto investing-themed domains. Chaput said that at some point last week, the volume of bot accounts registered for the crypto spam campaign began to overwhelm the servers that handle new registrations on Mastodon.social.

We suddenly went from three recordings per minute to 900 per minute, Chaput said. There was nothing in the Mastodon software to detect this activity, and the protocol is not designed to handle this.

One of the crypto investment scam messages promoted in spam campaigns on Mastodon this month.

Seeking to temporarily rein in the spam wave, Chaput said he briefly disabled new account registrations on mastodon.social and mastondon.online. Shortly after, those same servers suffered a sustained Distributed Denial of Service (DDoS) attack.

Chaput said whoever was behind the DDoS was definitely not using point-and-click DDoS tools, like a startup or stress service.

It was three hours non-stop, 200,000 to 400,000 requests per second, Chaput said of DDoS. At first they were targeting one path, and when we blocked it they started randomizing things. For three hours, the attack evolved several times.

Chaput says the spam waves have died down since they modernized mastodon.social with a CAPTCHA, those wavy combinations of letters and numbers designed to thwart automated account creation tools. But he worries that other instances of Mastodon aren’t as well-staffed and could be easy prey for these spammers.

We don’t know if it’s the work of one person, or if it’s [related to] software or services sold to others, Chaput told KrebsOnSecurity. We were really impressed with the scale of the use of hundreds of domains and thousands of Microsoft email addresses.

Chaput said a review of their logs indicates that many newly registered Mastodon spam accounts were registered using the same 0auth credentials, and that a common domain for those credentials was quot[.]p.w.

A DIRECT QUOTATION

The domain quot[.]pw has been registered and abandoned by multiple parties since 2014, but the most recent registration data available via DomainTools.com shows that it was registered in March 2020 by someone in Krasnodar, Russia with the address email [email protected].

This email address is also connected to accounts on several Russian cybercrime forums, including __edman__, which used to sell logs of large amounts of data stolen from numerous bot-infected computers, as well as giving access to hacked Internet of Things (IoT) devices. .

In September 2018, a user by the name Zipper (phonetically in Russian) registered on the Russian hacking forum Lolzteam using the address [email protected]. In May 2020, Zipper told another Lolzteam member that quot[.]pw was their domain. This user advertised a service called Quot Project which said he could be hired to write programming scripts in Python and C++.

I’m making Telegram bots and other junk cheaply, reads a February 2020 sales thread from Zipper.

Quotpw/Ahick/Edgard/ advertising its coding services in this Google-translated forum post.

Clicking the Open Chat in Telegram button on the Zippers Lolzteam profile page launched a Telegram instant message chat window where Quotpw user replied almost immediately. When asked if they knew their domain was being used to run a spam botnet that bombarded Mastodon instances with crypto scam spam, Quotpw confirmed that the spam was powered by their software.

It was designed for a limited circle of people, Quotpw said, noting that they recently released the bot software as open source on GitHub.

Quotpw went on to say that the spam botnet was powered by far more than the hundreds of IP addresses tracked by Chaput, and that these systems were primarily residential proxies. A home proxy generally refers to a computer or mobile device running some type of software that allows the system to be used as an intermediary for Internet traffic from other people.

Very often, this proxy software is installed surreptitiously, for example via a free VPN service or a mobile application. Home proxies can also refer to homes protected by compromised home routers running default credentials or outdated firmware.

Quotpw claims to have earned over $2,000 by sending around 100,000 private mentions to users in different Mastodon communities over the past few weeks. Quotpw said his conversion rate for the same bot-fed direct messaging spam on Twitter is generally much higher and more profitable, although he admitted that recent tweaks to Twitter’s anti-bot CAPTCHA have hurt his earnings on Twitter.

My partners (Im programmer) wasted time and money while ArkoseLabs (funcaptcha) introduced new precautions on Twitter, Quotpw wrote in a Telegram response. On Twitter, no more spam and crypto scam.

When asked if they felt at all conflicted about spamming people with invites to cryptocurrency scams, Quotpw said that in their hometown they paid more for such work only in white jobs referring to legitimate programming jobs that do not involve malware, botnets, spam and scams.

Consider salaries in Russia, Quotpw said. All spam is for profit and earn illegal money for spammers.

THE CONNECTION WITH VIENNA

Shortly after [email protected] recorded quot[.]pw, the WHOIS registration records for the domain have been changed again, to [email protected], and to a phone number in Austria: +43.6607003748.

Constella Intelligence, a company that tracks hacked data, discovers that the address [email protected] has been associated with accounts on the mobile application site aptoide.com (user: CoolappsforAndroid) and vimeworld.ru which have were created from different Internet addresses. in Vienna, Austria.

A Skype search of this Austrian phone number shows it belongs to a Sergey Proshutinskiy who lists his location in Vienna, Austria. The very first result that pops up when one Googles this unusual name is a LinkedIn profile of Sergey Proshutinskiy from Vienna, Austria.

Proshutinskiys’ LinkedIn profile says he is a class of 2024 student at TGM, which is a Christian missionary school in Austria. His CV also states that he is a data science intern at Mondi Group, an Austrian manufacturer of sustainable packaging and paper.

Mr. Proshutinskiy did not respond to requests for comment.

Quotpw denied being Sergey and said Sergey was a friend who registered the domain as a birthday present and favor last year.

Initially, I bought it for 300 rubles, explained Quotpw. The extension cost 1300 rubles (expensive). I waited for it to expire and forgot to buy it. After that, a friend (Sergey) bought [the] domain and transferred access rights to me.

He’s not even an information security specialist, Quotpw said of Sergey. My friends do not belong to this field. None of my friends are engaged in scams or other black [hat] activities.

It might seem unlikely that someone would bother spamming Mastodon users for several weeks using an impressive amount of resources, all for just $2,000 in profit. But it is likely that whoever is actually running the various crypto scam platforms advertised by Quotpws spam messages is paying handsomely for all the investments generated by their spam.

According to the FBI, financial losses from cryptocurrency investment scams eclipsed losses for all other types of cybercrime in 2022, dropping from $907 million in 2021 to $2.57 billion last year.

*** This is a syndicated Krebs on Security Security Bloggers Network blog written by BrianKrebs. Read the original post at: https://krebsonsecurity.com/2023/05/interview-with-a-crypto-scam-investment-spammer/

Sources

1/ https://Google.com/

2/ https://securityboulevard.com/2023/05/interview-with-a-crypto-scam-investment-spammer/amp/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts