Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)
Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)
Why Ask Credentials If There Are Secret Codes? - SANS ISC --> Internet Storm Center Sign In Sign Up Handler on Duty: Xavier Mertens Threat Level: green previous Click HERE to learn more about classes Xavier is teaching for SANS Why Ask Credentials If There Are Secret Codes? Published : 2026-07-01. Last Updated : 2026-07-01 05:10:20 UTC by Xavier Mertens (Version: 1) 0 comment(s) This morning, an interesting phishing email hit my mailbox. It targets Metamask[ 1 ], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It’s pretty popular, so a juicy target for criminals. In February, I already mentioned a campaign against them[ 2 ]. Today’s email was different and used another approach. Most services that we use daily ask us to implement a 2nd authentication factor. That makes simple credentials useless if you can’t interact with the victim and grab the temporary token, code, … But most services also offer a “password recovery” process. In the case of Metamask, it’s based on your secret security phrase that you created during the account creation process[ 3 ]. That’s exactly the target of this phishing campaign. They ask you to provide this secret phrase. First, they put some pressure on you, pretending that your wallet is at risk: Then, they ask you to provide your secret phrase: The campaing relies on the domain captchasolve[.]help that has been registered two days ago. [1] https://metamask.io [2] https://isc.sans.edu/diary/Fake+Incident+Report+Used+in+Phishing+Campaign/32722 [3] https://support.metamask.io/configure/wallet/how-can-i-reset-my-password/ Xavier Mertens (@xme) Xameco Senior ISC Handler - Freelance Cyber Security Consultant PGP Key Keywords: Phrase Secret Wallet Metamask Phishing 0 comment(s) Click HERE to learn more about classes Xavier is teaching for SANS previous Comments Login here to join the discussion. Top of page × Diary Archives Homepage Diaries Podcasts Jobs Data TCP/UDP Port Activity Port Trends SSH/Telnet Scanning Activity Weblogs Domains Threat Feeds Activity Threat Feeds Map Useful InfoSec Links Presentations & Papers Research Papers API Tools DShield Sensor DNS Looking Glass Honeypot (RPi/AWS) InfoSec Glossary Contact Us Contact Us About Us Handlers About Us Slack Channel Mastodon Bluesky X © 2026 SANS™ Internet Storm Center Developers: We have an API for you! Link To Us About Us Handlers Privacy Policy
📌 来源: SANS ISC | 📅 2026-07-01