Bitcoin Forum
May 09, 2024, 10:57:29 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Beware] Ongoing Electrum Phishing Attempt  (Read 199 times)
DireWolfM14 (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2184
Merit: 4238


Join the world-leading crypto sportsbook NOW!


View Profile WWW
February 18, 2019, 06:18:49 AM
Merited by suchmoon (4), HCP (2)
 #1

Several weeks ago a few users of the popular bitcoin desktop wallet Electrum reported loss of their bitcoin after downloading a malicious versions of software.

The scammers were able to infect Electrum servers to broadcast messages to users of older versions of the software.  The message would trick users into downloading the malware.  Recent releases of Electrum are able to prevent the messages from being broadcast by the compromised servers, but users who are still using versions prior to 3.3.3 are still vulnerable.  

I'm posting this here to help bring awareness to the issue.  If you are using an older version of Electrum it is recommended you upgrade to the latest version.

Only download Electrum from the official website:  https://electrum.org/
Don't forget to check the signature.  

More information can be found here: https://github.com/spesmilo/electrum/issues/4968

Originally the scammers directed victims to download the malware from the impostor's github repository, but github has since shut down the scammers account.  However it appears the scammer is still attempting to take advantage of the vulnerability by now directing his potential victims to a new site for downloading the malware.

Warning: Do not visit the site listed blow.  It is displayed only for your reference.
Code:
https://electrumdownload.com/


  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715252249
Hero Member
*
Offline Offline

Posts: 1715252249

View Profile Personal Message (Offline)

Ignore
1715252249
Reply with quote  #2

1715252249
Report to moderator
judeafante
Sr. Member
****
Offline Offline

Activity: 2254
Merit: 258



View Profile
February 19, 2019, 11:21:30 AM
 #2

Metacert is now a paying subscription but for $5 or more a month, it will save you from a phishing attack, sometimes it's hard to detect the right one from the wrong one and of course, only download from official sites, some duplicate download sites are injected with redirection.

██▄     ▄▄░
▀██▄ ▄██▀
▄▄███████████████████▄▄
▄█████▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
████▀                   ▀████
████       ▄▄█████▄▄  ▀▄   ████
████      ▄██████████▄▀    ████
████      ████████▀▀       ████
████  ▄▀ ▄██▀▀▀   ▄██      ████
████   ▀▀     ▄▄███▀       ████
████▄                   ▄████
▀█████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀▀███████████████████▀▀
.
SECONDLIVE
.
CHOOSE LIFE      CHOOSE SPACE      CHOOSE FRIENDS
.
|    Twitter    |  Telegram  |   Medium   |  YouTube  |   Discord   |    TikTok    |    GitHub    |
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
   S T A K E   L I T T L E   W I N   B I G   
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
        ▄▄███████▄▄▄
    ▄▄████████████████▄▄
   ████████████████████▄
  ███████▀▀▀█████████████
 ██████▌     ▀████████████
███████▀ ▀▀▄▄██▀▀▀█████████
██████             ▀███████
██████▄             ███████
 ███████▄▄        ▄███████
  ███████████▄▄▄▄█████████
   ▀███████████████████▀
     ▀████████████████▀▀
   ██████████████████████
Theb
Hero Member
*****
Offline Offline

Activity: 1680
Merit: 655


View Profile
February 19, 2019, 11:56:30 AM
 #3

Here is the message being broadcasted to the older versions of Electrum:


I found this on the issues tab of Electrum in Github, and it looks like users using an older version of Electrum who are trying to send Bitcoin will receive this message at the same time their transaction won't be created. Electrum has been in similar attacks with their software before but this one is unique on how they try to infiltrate their users, the good thing is Electrum is quick to act and I know see on their website that they have announced the current situation.

..bustadice..         ▄▄████████████▄▄
     ▄▄████████▀▀▀▀████████▄▄
   ▄███████████    ███████████▄
  █████    ████▄▄▄▄████    █████
 ██████    ████████▀▀██    ██████
██████████████████   █████████████
█████████████████▌  ▐█████████████
███    ██████████   ███████    ███
███    ████████▀   ▐███████    ███
██████████████      ██████████████
██████████████      ██████████████
 ██████████████▄▄▄▄██████████████
  ▀████████████████████████████▀
                     ▄▄███████▄▄
                  ▄███████████████▄
   ███████████  ▄████▀▀       ▀▀████▄
               ████▀      ██     ▀████
 ███████████  ████        ██       ████
             ████         ██        ████
███████████  ████     ▄▄▄▄██        ████
             ████     ▀▀▀▀▀▀        ████
 ███████████  ████                 ████
               ████▄             ▄████
   ███████████  ▀████▄▄       ▄▄████▀
                  ▀███████████████▀
                     ▀▀███████▀▀
           ▄██▄
           ████
            ██
            ▀▀
 ▄██████████████████████▄
██████▀▀██████████▀▀██████
█████    ████████    █████
█████▄  ▄████████▄  ▄█████
██████████████████████████
██████████████████████████
    ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
    ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
       ████████████
......Play......
hugeblack
Legendary
*
Offline Offline

Activity: 2506
Merit: 3649


Buy/Sell crypto at BestChange


View Profile WWW
February 19, 2019, 07:18:36 PM
 #4

the good thing is Electrum is quick to act and I know see on their website that they have announced the current situation.
Not only that, but the fame of this wallet makes any hack under the radar is easy to identify and reveal, especially in this forum or reddit.com/r/Bitcoin.
I have read about this attack a few days ago so I do not expect the impact of many users.
generally, thanks to everyone who contributed to the warning others.

Also, traditional tips help to avoid a lot of stuff.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!