Threat Intelligence Brief
Curated summary with source attribution
Source: malwarebytes.com
Threat Risk: High
Victim: Cryptocurrency companies and their newsletter subscribers
Incident: Supply-chain phishing campaign originating from a SAML SSO exploit at Brevo.
Impact: Potential theft of cryptocurrency funds through the compromise of wallet recovery phrases.
Attacker: Unidentified threat actors
Analysis: Threat actors exploited a SAML SSO vulnerability at Brevo to hijack customer accounts and export contact lists. By leveraging legitimate company domains, attackers sent highly convincing phishing emails to cryptocurrency users, specifically targeting subscribers of Trezor and CoinTracking. The campaign used urgent technical warnings about hardware bugs to trick victims into revealing private wallet backups.
Recommendations: Verify urgent security alerts via official company websites or apps; Avoid downloading software or entering seed phrases through email links; Implement robust email filtering and user awareness training regarding supply chain phishing
Source: Malwarebytes
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source