Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Phishing Campaigns Abusing Web3 Platforms Increased by 482% in 2022

Altszn.com by Altszn.com
January 16, 2023
in Web3
0
Phishing Campaigns Abusing Web3 Platforms Increased by 482% in 2022
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


Web3 platforms have surged in popularity over the years and continue to catch headlines with billion-dollar investments as well as significant downturns. According to McKinsey, despite early funding issues, adoption of Web3 applications has occurred at an exponential pace, which has led to many industry professionals questioning how safe and stable these platforms are.

Web3 platforms are designed to make content hosting more available to individuals, evade censorship, guarantee access to the published content and avoid technical problems like server management, making these platforms attractive for threat actors seeking to host malicious content.

Upon analyzing credential phishing campaigns that reached inboxes during the first three quarters of 2022, Cofense discovered a significant rise in the abuse of Web3 platforms for phishing. As a result, phishing campaigns that abuse Web3 platforms have increased by 482 percent in 2022 with credential phishing making up the majority of the abuse.

How Web3 is Leveraged by Threat Actors

Web3 platforms require the creation of a network of many different servers working together to host content. Not every web browser supports direct access to these platforms. In order to make Web3 services more usable, some organizations run servers that produce “gateway URLs,” which allow browsers to open Web3 content as if it were being hosted on a traditional server.

Gateway services aid in the adoption of Web3 technologies by making them more accessible. However, these services are utilized by threat actors to send links to phishing pages they host on Web3 platforms. The services can choose to disable a gateway URL that points to malicious or illegal content, but the effort becomes a cat-and-mouse game as threat actors can simply keep re-publishing their content with new gateway URLs.

Why Web3 is an Attractive Target

Web3 platforms have no organized moderators to manage hosted content. While some measures are put in place to limit malicious content, it is impossible to prevent it from being hosted within the platforms or to remove it once it has been hosted. Web3 platforms are readily available to any users with relevant software and content is collaboratively hosted by the platforms’ users.

The most common tactics used by threat actors while exploiting Web3 platforms using malicious URLs can be divided into two stages. Stage 1 includes URLs embedded in the email. Only 21 percent of Web3 URLs are used in stage 1 since they are easier for organizations to identify and block. Stage 2 involves any URLs that are opened after the users have opened the embedded link in the email.

Since content published on Web3 platforms is considered permanent, this removes the need for threat actors to create or steal accounts, compromise websites, or register new domains to host a credential phishing page. Threat actors can continuously publish new phishing pages to stay ahead of countermeasures.

Although Web3 platforms are an attractive host to threat actors, these platforms cannot perform data exfiltration. Instead, threat actors must maintain more traditional compromised or malicious servers as endpoints to receive stolen credentials. They often use HTML forms or embedded JavaScript code, so that the victim’s browser sends captured login credentials to the endpoints under threat actor control.

Web3 2023 Outlook

Forrester stated in its trend report “Web3 Promises A Better Online Future But Contains The Seeds Of A Dystopian Nightmare” that CIOs, CMOs and other executives should approach Web3 with extreme caution, even as investment in Web3 technologies continues to skyrocket.

As Web3 technology gains adoption in the everyday life of users and organizations, the opportunity for abuse will only grow. The decentralized nature of these platforms puts the responsibility of security in the individuals’ hands and as Web3 platforms increase in popularity, threat actors will continue to take advantage of this opportunity, making it essential for users to remain educated and vigilant to avoid exploitation via Web3 phishing threats.

Photo credit: wk1003mike / Shutterstock

Brad Haas is Threat Intelligence Analyst, Cofense.





Read More: news.google.com

Tags: AbusingCampaignsIncreasedphishingplatformsweb 3.0Web3
ADVERTISEMENT

Recent

Labor Dept Rescinds Biden-Era Guidance

Labor Dept Rescinds Biden-Era Guidance

May 28, 2025
Nvidia Reports Strong Results, but Outlook is Tempered

Nvidia Reports Strong Results, but Outlook is Tempered

May 28, 2025
JD Vance Calls Crypto Market Structure Bill a ‘Priority’ for Trump Administration

JD Vance Calls Crypto Market Structure Bill a ‘Priority’ for Trump Administration

May 28, 2025

Categories

  • Bitcoin (4,594)
  • Blockchain (10,921)
  • Crypto (8,866)
  • Dark Web (467)
  • DeFi (8,171)
  • Ethereum (4,622)
  • Metaverse (6,953)
  • Monero (258)
  • NFT (1,171)
  • Solana (4,946)
  • Web3 (20,022)
  • Zcash (473)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Labor Dept Rescinds Biden-Era Guidance

    Labor Dept Rescinds Biden-Era Guidance

    May 28, 2025
    Nvidia Reports Strong Results, but Outlook is Tempered

    Nvidia Reports Strong Results, but Outlook is Tempered

    May 28, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 107,845.00
    • ethereumEthereum (ETH) $ 2,675.90
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.27
    • bnbBNB (BNB) $ 687.67
    • solanaSolana (SOL) $ 172.17
    • usd-coinUSDC (USDC) $ 0.999776
    • dogecoinDogecoin (DOGE) $ 0.221086
    • cardanoCardano (ADA) $ 0.746590
    • tronTRON (TRX) $ 0.273655
    • staked-etherLido Staked Ether (STETH) $ 2,671.10
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 107,894.00
    • suiSui (SUI) $ 3.60
    • hyperliquidHyperliquid (HYPE) $ 34.29
    • wrapped-stethWrapped stETH (WSTETH) $ 3,219.00
    • chainlinkChainlink (LINK) $ 15.64
    • avalanche-2Avalanche (AVAX) $ 23.46
    • stellarStellar (XLM) $ 0.284849
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 9.08
    • bitcoin-cashBitcoin Cash (BCH) $ 418.82
    • the-open-networkToncoin (TON) $ 3.33
    • hedera-hashgraphHedera (HBAR) $ 0.185783
    • wethWETH (WETH) $ 2,675.28
    • litecoinLitecoin (LTC) $ 95.37
    • polkadotPolkadot (DOT) $ 4.57
    • usdsUSDS (USDS) $ 0.999742
    • wrapped-eethWrapped eETH (WEETH) $ 2,854.58
    • moneroMonero (XMR) $ 347.43
    • bitget-tokenBitget Token (BGB) $ 5.25
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • pepePepe (PEPE) $ 0.000014
    • pi-networkPi Network (PI) $ 0.731176
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,747.00
    • whitebitWhiteBIT Coin (WBT) $ 31.59
    • uniswapUniswap (UNI) $ 6.76
    • aaveAave (AAVE) $ 263.95
    • bittensorBittensor (TAO) $ 433.65
    • daiDai (DAI) $ 0.999959
    • nearNEAR Protocol (NEAR) $ 2.85
    • aptosAptos (APT) $ 5.39
    • okbOKB (OKB) $ 52.55
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.34
    • tokenize-xchangeTokenize Xchange (TKX) $ 38.78
    • ondo-financeOndo (ONDO) $ 0.931393
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.097715
    • internet-computerInternet Computer (ICP) $ 5.42
    • ethereum-classicEthereum Classic (ETC) $ 18.42
    • bitcoinBitcoin (BTC) $ 107,845.00
    • ethereumEthereum (ETH) $ 2,675.90
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.27
    • bnbBNB (BNB) $ 687.67
    • solanaSolana (SOL) $ 172.17
    • usd-coinUSDC (USDC) $ 0.999776
    • dogecoinDogecoin (DOGE) $ 0.221086
    • cardanoCardano (ADA) $ 0.746590
    • tronTRON (TRX) $ 0.273655
    • staked-etherLido Staked Ether (STETH) $ 2,671.10
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 107,894.00
    • suiSui (SUI) $ 3.60
    • hyperliquidHyperliquid (HYPE) $ 34.29
    • wrapped-stethWrapped stETH (WSTETH) $ 3,219.00
    • chainlinkChainlink (LINK) $ 15.64
    • avalanche-2Avalanche (AVAX) $ 23.46
    • stellarStellar (XLM) $ 0.284849
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 9.08
    • bitcoin-cashBitcoin Cash (BCH) $ 418.82
    • the-open-networkToncoin (TON) $ 3.33
    • hedera-hashgraphHedera (HBAR) $ 0.185783
    • wethWETH (WETH) $ 2,675.28
    • litecoinLitecoin (LTC) $ 95.37
    • polkadotPolkadot (DOT) $ 4.57
    • usdsUSDS (USDS) $ 0.999742
    • wrapped-eethWrapped eETH (WEETH) $ 2,854.58
    • moneroMonero (XMR) $ 347.43
    • bitget-tokenBitget Token (BGB) $ 5.25
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • pepePepe (PEPE) $ 0.000014
    • pi-networkPi Network (PI) $ 0.731176
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,747.00
    • whitebitWhiteBIT Coin (WBT) $ 31.59
    • uniswapUniswap (UNI) $ 6.76
    • aaveAave (AAVE) $ 263.95
    • bittensorBittensor (TAO) $ 433.65
    • daiDai (DAI) $ 0.999959
    • nearNEAR Protocol (NEAR) $ 2.85
    • aptosAptos (APT) $ 5.39
    • okbOKB (OKB) $ 52.55
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.34
    • tokenize-xchangeTokenize Xchange (TKX) $ 38.78
    • ondo-financeOndo (ONDO) $ 0.931393
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.097715
    • internet-computerInternet Computer (ICP) $ 5.42
    • ethereum-classicEthereum Classic (ETC) $ 18.42