In a cybercrime scheme that happened between November 2022 and November 2023, the now-defunct Inferno Drainer operated under a scam-as-a-service model, raking in over $87 million in illicit profits. The operators behind this malicious campaign crafted more than 16,000 unique domains, employing sophisticated tactics to deceive unsuspecting users.
What is Inferno Drainer?
According to a report by Singapore-headquartered Group-IB, Inferno Drainer leveraged high-quality phishing pages to trick users into connecting their crypto wallets with the attackers’ infrastructure. The attackers spoofed Web3 protocols by creating fake pages that looked like more than 100 different cryptocurrency brands.
The malware’s modus operandi involved enticing victims to authorize transactions. More than 137,000 individuals fell prey to this elaborate phishing attack. Group-IB estimates that the criminals successfully scammed victims out of $87 million over the course of a year.
Under the scam-as-a-service model, affiliates could upload the malware to their own phishing sites or utilize the developer’s services for creating and hosting phishing websites. The developers took a 20% cut of the earnings from these affiliates, creating a profitable and organized cybercrime operation.
What did they do?
The malicious domains hosting the Inferno Drainer were not static. The criminals actively employed a variety of tactics to obfuscate their activities. The initial analysis of 500 domains showed that the JavaScript-based drainer was hosting on GitHub repositories. For instance, one repository, “kuzdaz.github[.]io/seaport/seaport.js,” hosted the drainer before it was incorporated directly into websites. Notably, the GitHub user “kuzdaz” no longer exists.
Another set of 350 sites included a JavaScript file, “coinbase-wallet-sdk.js,” hosted on a different GitHub repository, “kasrlorcian.github[.]io.” The attackers distributed these malicious websites on platforms like Discord and X (formerly Twitter), enticing victims with promises of free tokens (airdrops) and urging them to connect their wallets. Once the attackers gained approval for transactions, they drained the victims’ assets.
The criminals behind Inferno Drainer tried hard to hide what they were doing. They set up the fake websites in a way that stopped users from looking at the code behind the website using hotkeys or right-clicking. They did this to keep their harmful scripts and illegal actions hidden from the people they were tricking.
Despite the cessation of Inferno Drainer’s activity, the threat landscape remains severe for cryptocurrency holders. Andrey Kolmakov, head of Group-IB’s High-Tech Crime Investigation Department, emphasized the ongoing risks as drainers continue to evolve. “Inferno Drainer may have ceased its activity, but its prominence throughout 2023 highlights the severe risks to cryptocurrency holders as drainers continue to develop further,” Kolmakov warned.
Cybercriminals continuously adapt and change their tactics to exploit vulnerabilities. Google’s Mandiant X account got hacked, spreading links to a CLINKSINK cryptocurrency drainer phishing page.Dealing with newer cyber threats calls for vigilance and the use of strong safety measures to keep one’s digital assets safe.
