Scan to download
BTC $78,809.95 -2.14%
ETH $2,219.31 -1.52%
BNB $663.71 -2.41%
XRP $1.42 -3.03%
SOL $88.35 -2.60%
TRX $0.3508 -0.60%
DOGE $0.1112 -2.62%
ADA $0.2571 -3.56%
BCH $423.30 -2.50%
LINK $9.91 -3.46%
HYPE $42.05 -8.06%
AAVE $90.15 -6.69%
SUI $1.06 -7.21%
XLM $0.1527 -4.15%
ZEC $501.51 -7.43%
BTC $78,809.95 -2.14%
ETH $2,219.31 -1.52%
BNB $663.71 -2.41%
XRP $1.42 -3.03%
SOL $88.35 -2.60%
TRX $0.3508 -0.60%
DOGE $0.1112 -2.62%
ADA $0.2571 -3.56%
BCH $423.30 -2.50%
LINK $9.91 -3.46%
HYPE $42.05 -8.06%
AAVE $90.15 -6.69%
SUI $1.06 -7.21%
XLM $0.1527 -4.15%
ZEC $501.51 -7.43%

Slow Fog: Attackers exploit XSS vulnerability on Cointelegraph website for phishing

2024-11-28 09:35:52
Collection

ChainCatcher news, Slow Mist founder Yuxian disclosed an XSS attack targeting the crypto industry on the X platform. The attacker exploited an XSS vulnerability on the crypto media website Cointelegraph to lure target users into opening a link to the official Cointelegraph website (with XSS malicious script), resulting in:

  • Malicious script loading and execution;
  • The address bar being set to a suspicious address (which at first glance looks like an official unpublished draft);
  • A fake Sign in with X pop-up appearing;
  • After clicking Sign in with X, the third-party application authorization for X opens, with a large blank section in the permissions list. If you inadvertently click to authorize without paying attention, your X-related permissions will be taken over by the attacker.

This type of phishing with a slight exploit is particularly difficult for the general public to defend against, so extra caution is needed.

app_icon
ChainCatcher Building the Web3 world with innovations.