AhnLab’s Mobile Analysis Team identifies romance scams in which perpetrators pose as overseas friends or partners to solicit money through fake cryptocurrency investments. The attackers push a counterfeit exchange named “CoinB,” use social media and translation-enabled messengers, and deploy a staged app to extract money and personal information. #CoinB #Namuwiki
Keypoints
- Romance scammers pose as overseas friends or partners to initiate financial requests tied to cryptocurrency investments.
- Luring victims occurs on social media, followed by messages in a translation-enabled messenger to continue the con.
- The scam entices with “secret cryptocurrency profits” and references to fake exchanges to build trust.
-
MITRE Techniques
- [T1566.003] Spearphishing via Service – Luring Victims with DM after following posts and urging a move to a translation-enabled messenger app. Quote: “The perpetrator expresses gratitude through a direct message (DM) and continues the conversation until eventually urging the victim to move to a messenger app with translation capabilities.”
- [T1036] Masquerading – Fake cryptocurrency exchange “CoinB” designed to mislead; Quote: “The fake cryptocurrency exchange called ‘CoinB’ introduced by the perpetrator was found to be listed on platforms such as Namuwiki and Wikipedia.”
- [T1583] Acquire Infrastructure – Establishing fake exchange pages and distribution via apps; Quote: “the homepage of the mentioned cryptocurrency exchange (coinb.top) is not currently operational, and the address provided by the perpetrator for ‘CoinB’ leads to a different domain.”
Indicators of Compromise
- [MD5] MD5 hashes – 7353b685c49432783906cd74ce4cefdc, f1e88bc7c240507b2bbbea646205c8de, 8977ff762385e1c5dd1515d098147ad2, 41d5e86dbfd90c994c3b2de8e014c89c, 6443f4586afdd3ca6f8372ab569c2911, f42db78ae4fa84e85905c831087ca210 – hashes associated with the analyzed samples.
- [Domain] coinb.top – homepage of the fake exchange used in the scam and linked distribution.
- [Domain] protonmail.com – virtual account registered with ProtonMail used in the scam flow.
Read more: https://asec.ahnlab.com/en/65370/