An in depth analysis of the latest scams following the breach of the Ledger database
Last updated
Background
Following the news of the latest hack targeting the Ledger database and the leak of millions of emails, phishing attacks have rapidly increased. The leaked data does not contain any financial information according to Ledger, but emails and personal information are already being used in targeted phishing campaigns, as we can see from the banner on their website.
Ledger has also started a counter-campaign to take down phishing websites called #StopTheSpammers. More details are available here:
We have been tracking the presence of Ledger leaked data online in the last few days and most of the published archives have been proactively removed, while some are still available for download as shown from the paste below dated Dec 20th, 2020 (links have been cropped).
Three days after the leak, we already detected many domains created to carry out phishing attacks, using different techniques including typo-squatted domains. We started actively investigating few of the many domains.
The phishing attacks that have been submitted to us starts with a text email that contains the following text (URLs have been sanitized)
From: Ledger Alerts <noreply@ledger.com-ez29-server-33-secure.az26-s8-smtp.cloud>
Date: Wed, 23 Dec 2020 at 01:32
Subject: XG ZAAY2
To: <.....>
Your Wallet has been blocked.
You are required to verify your identity:
https://docs.google.com/document/d/e/2PACX-1vTlnW_iGFZ5IXXXXXXXXXXXXXXXXXXXXXXXXuuzJQMuPhseCByGZG2nS2CZuBLkb6dxPpBuyd/pub?embedded=true
Ledger Support Team.
6G3L-Q3QP0Q78LQ PL6649
Once the user clicks on the Google doc link, Google shows the classic redirect message, with the wrong text/address (ledger.com) as shown below:
but actually, the victim will be redirected to the actual phishing website:
The first screen invites the user to choose its Ledger Nano model
When the user selects the model, the website simulates the connection of the hardware device to the computer
and ask for the passphrase to unlock it, collecting some more details about the victim like in the screenshot below. We can see the mnemonic_phrase being asked as well.
After the victim fills in the sensitive information it is being sent in a POST request to the server where it is being saved. Using this information the attackers can continue their attack to potentially steal the coins.
The website had also some attention from other security researchers on Twitter, and Ledger confirmed the scam.
Looking at the WHOIS information, the domain was registered on the 15-12-2020 and edited on the 20th of the same month. The data below are collected from the Phoenix platform (see Conclusions)
{
"domain_name": "login-account.app",
"registrar": "NameSilo, LLC",
"whois_server": "whois.nic.google",
"updated_date": "2020-12-25 14:00:38",
"creation_date": "2020-12-15 15:35:11",
"expiration_date": "2021-12-15 15:35:11",
"name_servers": [
"a.dnspod.com",
"c.dnspod.com"
],
"status": [
"clientHold https://icann.org/epp#clientHold",
"clientTransferProhibited https://icann.org/epp#clientTransferProhibited"
],
"emails": "namesilo@registry.google",
"registrant_email": "Please query the WHOIS server of the owning registrar identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.",
"registrant_phone": "REDACTED FOR PRIVACY",
"dnssec": "unsigned",
"name": "REDACTED FOR PRIVACY",
"org": "See PrivacyGuardian.org",
"address": "REDACTED FOR PRIVACY",
"city": "REDACTED FOR PRIVACY",
"state": "AZ",
"zipcode": "REDACTED FOR PRIVACY",
"country": "US"
}
The domains are currently hosted on popular cloud platforms such as Alibaba and Amazon cloud and the WHOIS information are privacy protected (hidden). Getting them would require a subpoena. :)
During our analysis, we identified a file containing some balances publicly available on the phishing website.
This information cannot be connected to legit accounts yet but helps us to further understand how the clone kit operates, giving insights on possible ways of recovering stolen credentials.
About the domain
Similar domains have been already used in the past to host phishing websites targeting different companies such as
The phishing website is what we normally see in phishing websites. It misses a lot of functionality and is only focused on getting sensitive information out. The front end is HTML/CSS website and uses the jQuery JavaScript library. The back end is written in PHP with databases support and runs behind an Nginx reverse proxy that supports HTTP/2. The phishing website runs over TLS with a Let's Encrypt generated certificate.
Based on the comments (//прописываем куку) that are left in parts of the JavaScript on the website we can with some certainty conclude that it is built by a Russian speaking crew.
This claim is also supported by some of PHP file names that we have identified on the server, for example spisok.php which translates as 'list.php' in english.
$ curl -vv https://ledger.com.login-verification.app/settings/spisok.php*TCP_NODELAY set* Connected to localhost (::1) port 8079 (#0)* allocate connect buffer!* Establish HTTP proxy tunnel to ledger.com.login-verification.app:443>CONNECTledger.com.login-verification.app:443HTTP/1.1> Host:ledger.com.login-verification.app:443> User-Agent: curl/7.64.1> Proxy-Connection: Keep-Alive><HTTP/1.1200OK< Date: Sat,26 Dec 202011:02:20GMT< Connection: Close<* Proxy replied 200 to CONNECT request*CONNECT phase completed!*ALPN, offering h2*ALPN, offering http/1.1* successfully set certificate verify locations:* CAfile:/etc/ssl/cert.pem CApath: none* TLSv1.2 (OUT),TLS handshake, Client hello (1):*CONNECT phase completed!*CONNECT phase completed!* TLSv1.2 (IN),TLS handshake, Server hello (2):* TLSv1.2 (IN),TLS handshake,Certificate (11):* TLSv1.2 (IN),TLS handshake, Server key exchange (12):* TLSv1.2 (IN),TLS handshake, Server finished (14):* TLSv1.2 (OUT),TLS handshake, Client key exchange (16):* TLSv1.2 (OUT),TLS change cipher, Change cipher spec (1):* TLSv1.2 (OUT),TLS handshake,Finished (20):* TLSv1.2 (IN),TLS change cipher, Change cipher spec (1):* TLSv1.2 (IN),TLS handshake,Finished (20):*SSL connection usingTLSv1.2 / ECDHE-RSA-AES256-GCM-SHA384*ALPN, server accepted to use h2* Server certificate:* subject:CN=ledger.com.login-verification.app* start date: Dec 2114:32:462020GMT* expire date: Mar 2114:32:462021GMT* subjectAltName: host "ledger.com.login-verification.app" matched cert's "ledger.com.login-verification.app"* issuer:C=US; O=Let's Encrypt; CN=R3*SSL certificate verify ok.* Using HTTP2, server supports multi-use* Connection state changed (HTTP/2 confirmed)* Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0* Using Stream ID:1 (easy handle 0x7fec6100d200)>GET/settings/spisok.php HTTP/2> Host:ledger.com.login-verification.app> User-Agent: curl/xxx> Accept:*/*> * Connection state changed (MAX_CONCURRENT_STREAMS == 128)!< HTTP/2 200 < server: nginx/1.16.0< date: Sat, 26 Dec 2020 11:02:17 GMT< content-type: text/html; charset=UTF-8< content-length: 0< strict-transport-security: max-age=604800< accept-ranges: bytes< * Connection #0 to host localhost left intact* Closing connection 0
Malware campaign
Another campaign is tricking users into downloading the Ledger desktop application for Win, Mac, or Linux. This campaign is heavily relying on typo squatted websites to distribute malware. The first screen looks exactly like the "Download" page of the original website
where the user can choose the OS for which the application will be downloaded. We compared the original desktop application against the malicious one and indeed the hash is different, due to new code added.
As soon as the app is launched, there is a call made to the C&C as we can see from the image below, but because the website is currently down at the moment of writing, the application returns an error, disclosing the endpoint
https://happyflyingcow[.]com
Code Analysis
The original Electron application has been repackaged to include JavaScript code that sends back information about the user and the newly chosen passphrase. As soon as the application is started, it tries to connect back to the C&C server using the following code
Once the connection has been established, and the C&C is up, the user is presented with fake Onboarding screens, where the 24 words used in the passphrase will be entered
switch (window.wwn) {case2://alert("words undefined");//setWordN("2nd");document.getElementById("words-input-title").innerText ="Enter the 2nd word of your Recovery phrase:";document.getElementById("onboarding-reset-button").style.display ="flex";break;case3://setWordN("3rd");document.getElementById("words-input-title").innerText ="Enter the 3rd word of your Recovery phrase:";break;case4://setWordN("4th");document.getElementById("words-input-title").innerText ="Enter the 4th word of your Recovery phrase:";break;case5://setWordN("5th");document.getElementById("words-input-title").innerText ="Enter the 5th word of your Recovery phrase:";break;case6://setWordN("6th");document.getElementById("words-input-title").innerText ="Enter the 6th word of your Recovery phrase:";break;case7://setWordN("7th");document.getElementById("words-input-title").innerText ="Enter the 7th word of your Recovery phrase:";break;case8://setWordN("8th");document.getElementById("words-input-title").innerText ="Enter the 8th word of your Recovery phrase:";break;case9://setWordN("9th");document.getElementById("words-input-title").innerText ="Enter the 9th word of your Recovery phrase:";break;case10://setWordN("10th");document.getElementById("words-input-title").innerText ="Enter the 10th word of your Recovery phrase:";break;case11://setWordN("11th");document.getElementById("words-input-title").innerText ="Enter the 11th word of your Recovery phrase:";break;case12://setWordN("12th");document.getElementById("words-input-title").innerText ="Enter the 12th word of your Recovery phrase:";document.getElementById("words-input").value ="";break;case13://setWordN("13th");document.getElementById("words-input-title").innerText ="Enter the 13th word of your Recovery phrase:";break;case14://setWordN("14th");document.getElementById("words-input-title").innerText ="Enter the 14th word of your Recovery phrase:";break;case15://setWordN("15th");document.getElementById("words-input-title").innerText ="Enter the 15th word of your Recovery phrase:";break;case16://setWordN("16th");document.getElementById("words-input-title").innerText ="Enter the 16th word of your Recovery phrase:";break;case17://setWordN("17th");document.getElementById("words-input-title").innerText ="Enter the 17th word of your Recovery phrase:";break;case18://setWordN("18th");document.getElementById("words-input-title").innerText ="Enter the 18th word of your Recovery phrase:";break;case19://setWordN("19th");document.getElementById("words-input-title").innerText ="Enter the 19th word of your Recovery phrase:";break;case20://setWordN("20th");document.getElementById("words-input-title").innerText ="Enter the 20th word of your Recovery phrase:";break;case21://setWordN("21st");document.getElementById("words-input-title").innerText ="Enter the 21st word of your Recovery phrase:";break;case22://setWordN("22nd");document.getElementById("words-input-title").innerText ="Enter the 22nd word of your Recovery phrase:";break;case23://setWordN("23rd");document.getElementById("words-input-title").innerText ="Enter the 23rd word of your Recovery phrase:";break;case24://setWordN("24th");document.getElementById("words-input-title").innerText ="Enter the 24th word of your Recovery phrase:";break; }document.getElementById("words-input").value =""; } }
and then collected using a POST request to {SERVER}/rss.php as shown below on line 13
If you received an email or an SMS redirecting to a phishing website, contact us and we will take immediate action to report the phishing website to the right authorities
Forward the phishing email/link to info@dcodx.com
In case you are a victim of the breach, please follow the recommendation provided by Ledger at
Phoenix is our antiphishing tool that can proactively detect and report phishing attacks, combining different discovery techniques and automated reporting plugins. We constantly monitor all the new registered domains, typo-squatted domains, blacklists, deep web, forums, and more to provide insights on new attacks. Our light agent is capable of detecting clones even before they are online.
The detected websites are indeed phishing websites, trying to steal the backup phrase
Conclusions
Cryptocurrencies are one of the most valuable targets for phishers that are constantly trying to find different ways of bypassing security measures in place such as Multi-Factor Authentication (MFA). Many attacks are still ongoing and immediate action to take down the websites is needed. Continuous awareness, detection, and response can improve the impact of phishing attacks. Check how DCODX can help you detect stolen credentials and make phishing websites disappear in seconds using Phinix, putting you in control of the phishing website and being one step ahead of the phishers.