Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

New “Elon Musk Club” Crypto Giveaway Scam Promoted Via Email

New “Elon Musk Club” Crypto Giveaway Scam Promoted Via Email

A new Elon Musk-themed cryptocurrency giveaway scam called the “Elon Musk Mutual Aid Fund” or “Elon Musk Club” is being promoted through spam email campaigns that started over the past few weeks.

Before you dismiss these scams, saying that no one falls for them, similar crypto scams have been hugely successful and have generated hundreds of thousands of dollars in the past.

For example, scammers made $180K in a single day in 2018, Twitter suffered a massive attack where crypto scammers earned $580K in a week in January 2021, and then another scam stole $145K in February.

Just last week, someone sent three bitcoin, or $150,074 at the time, to a known crypto giveaway scam.

Also Read: 5 Workplace Tips: Protecting Information on Mobile Devices

The Elon Musk Club scam

While most cryptocurrency scams target social media users, scammers now use email spam to promote a new “Elon Musk Club” or “Elon Musk Mutual Aid Fund” giveaway.

The phishing emails themselves are low effort and include strange non-descriptive subjects and messages. However, they include an HTML attachment named simply ‘Get Free Bitcoin – [id].htm’ or “Elon Musk Club – [id].htm,” as shown below.

Spam email with Elon Musk Club attachment
Spam email with Elon Musk Club attachment

These HTML attachments contain a single line of code that uses JavaScript to redirect the browser to the https://msto.me/elonmusk/ webpage.

Contents of HTML attachment
Contents of HTML attachment

The https://msto.me/elonmusk/ site will pretend to be an “Elon Musk – Mutual aid fund” that promises to send 0.001 to 0.055 bitcoins to all users who participate.

Elon Musk - Mutual aid fund scam site
Elon Musk – Mutual aid fund scam site

When you click on the ‘Accept an invitation” button, the site will bring you to another site called “Bitcoin Donate,” located at https://bitcoindonateur.site/.

bitcoindonateur.site scam site
bitcoindonateur.site scam site

You are prompted to enter a bitcoin address to receive the free bitcoin, your name, and an optional picture at this site.

Enter your information and wallet address
Enter your information and wallet address

When you click the ‘Accept donate’ button, the site will redirect you through a series of pages that pretend to be users donating .001 bitcoin to your account.

Also Read: The Role of A DPO During Work From Home

After your account has accrued 0.055 of fake bitcoin donations, you will be brought to a final page stating that you must first donate 0.001 bitcoins to another user to receive your “financial assistance.”

Scam site prompting victims to send 0.001 bitcoins
Scam site prompting victims to send 0.001 bitcoins

However, these bitcoin addresses are owned by the scammers who take your “donation” but do not send anything in return.

So far, BleepingComputer has seen two bitcoin addresses associated with these scams:

While the scammers have only earned ~$3,661 from these two addresses, many other bitcoin addresses are likely used in this scam.

Even worse, while writing this article, the second bitcoin address received three more “donations.” showing that this scam continues to be successful.

As these scams have the potential to generate a large amount of money for threat actors, they are not going away any time soon and will likely continue to spread to other messaging platforms.

Therefore, everyone needs to recognize that almost every crypto giveaway site is a scam, especially those that pretend to be from Elon Musk, Tesla, SpaceX, and Gemini.

If you receive emails, tweets, or other messages on social media promoting these types of giveaways, it is safer to realize that cryptocurrency you send will not produce anything in return.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us