Saturday, July 17, 2021

Baby Twitter Coin is Not From Twitter

 Baby Coin Mania Fuels Surge in Crypto Fraud


Unofficial Baby Twitter Coin


Warning New Baby Twitter Coin is not from Twitter. 

New BEP20 tokens are popping up daily flooding the market with fake coins being created out of thin air in many cases. Many coins are copying other coins and projects. Buyer beware.

I caught this fake Baby Twitter Coin operator last week attempting to offer the non official Twitter named baby coin.


Baby Twitter Coin website



After a few days offline the fake Baby Twitter Coin website is back up. The Twitter profiles are inactive but open. 

Opening a new website and Twitter account the unofficial Twitter baby coin operators were quick to attempt to tweet an offering pictured below.



I informed Twitter and responded to the tweet and quickly got blocked. What a surprise. A block is meaningless to a cybersecurity professional because there are always ways to get information legally. 

Original operators Twitter profile, changed several times.


Operators Twitter profile


Blocked after informing Twitter and questioning the coin operators.


Blocked after questioning.

These operators look to be out of Germany with initial registrations and are on the run changing details trying to sell this fake offer.

There is a great follow feature on Twitter the operators don't know about. Even if you are blocked the profile still shows up with all of your changes.

Example shown below of the alleged Baby Twitter Coin operator.


Alleged Baby Twitter Coin operator.


Always do your research and know who is backing your coin or project. This Baby Twitter Coin is not from Twitter. Always go to official Twitter sites for information on Twitter projects.

This unofficial Twitter baby coin even pitched a charity component. Selling a fake coin and giving some to charity doesn't legitimize the fake offer. 

Fake coin charity.

Elon Musk has fueled the baby coin mania and there is no end in sight. The Securities and Exchange Commission is due to give an official stance on crypto by the end of July. As always be careful what you buy and click on. This is not an official Twitter sponsored coin. 

Fake Twitter tokens are being offered on other non official Twitter knock offs like Twitter-Finance[.]com which is also not from Twitter.



The Cyber Show
Dominic Alvieri
Not on Facebook
Twitter @AlvieriD

Wednesday, July 7, 2021

Do Smart Contracts Make You Feel Dumb?

 

Stablecoins May Not Be Very Stable.

What is a Coin? What is a Token?

By Dominic Alvieri, @AlvieriD
July 7th, 2021 


The Crypto Craze
The Crypto Craze.



The proposed STABLE Act will require stablecoin issuers to have a banking charter and report holdings.


The STABLE Act may be coming soon. Additional reporting and disclosure of assets securitizing stablecoins is a move in the right direction for security sake.

You probably have heard Bitcoin is an investment or a store of value .
You may have also heard most ransomware is paid in Bitcoins.

Do you know the difference between a coin and a token?
Do you know about different blockchains?
Do you know what fungible means?


What or who is backing your stablecoins?



Bitcoin, Ethereum, Ripple and stablecoins are not all created equal. Bitcoin is a digital currency to invest, hold or purchase in exchange for goods or services much the way a dollar in the local store would. Your one dollar or Bitcoin is fungible or able to replace or is interchangeable or equal to the next one. What or who is behind and backing your stablecoin?



Do you know the difference between Bitcoin and Ethereum.
Do you know the difference between BTC and ETH?


What is a coin and what is a token?

Do you know the difference between a coin and a token? A coin is referred to as a cryptocurrency and can be held as an investment or used  like Bitcoin in exchange for an item, good or service.

A token is issued as a smart contract on the Ethereum blockchain and there are three main types of tokens. A token may currently be a utility, commodity or security based token. In brief a utility token generally is used between a site for a use. A commodity based token is backed by a certain asset or commodity such as gold. A security token implies ownership in that company or decentralized unit. 

Cryptocurrency and tokens have different values. Ethereum has gas to defend infinite loops.
Keccak that. Is that still used? What is that?

Obtain full details before investing in any cryptocurrency, token or other investment in general.

Smart contracts make you feel dumb?


ERC-20 and ERC-721 basics.

In short smart contracts use blockchain technologies and software to execute the exchange of an asset or property between a buyer and a seller written directly into the code of the contract on the Ethereum framework are called ERC 20s. Rather than running a separate blockchain, ERC 20 is the main technological standard and set of rules that apply to issuing smart contracts via the Ethereum blockchain. There are six basic rules and are in place for uniformity among contracts. Several digital currencies including Augur and Maker use the ERC 20 standard.

An ERC 721 is a non-fungible token. There is more to.


The wild world of cryptocurrencies.
There are many different stablecoin issuers.


A word of caution.


A word of caution going forward. Government central banks will be issuing Central Bank Digital Currencies, or CBDCs. A stablecoin is not a CBDC.

 A CBDC is not backed by any Bitcoin, Ethereum or any other digital cryptocurrency. 
It will be issued by a government.

Tether backed stablecoin assets have been questioned before.


 A stablecoin is not backed by either a CBDC, BTC, ETH, etc. Check with your actual investment prospecuts or white paper.  With Tether and other stablecoins you are trusting in a company to maintain its peg rate and assets securitizing the underlying stablecoin. 

The STABLE Act will require stablecoin issuers to acquire a banking charter or license and file reports showing detailed investment holdings backing stablecoin investments.  



Buyer beware security is on you too.
Buyer beware, the security is on you as well.


The crypto craze continues.


Be careful with valuations and security. Do use cold storage and secure 2FA for your accounts. 
The main difference between 2FA and MFA is more factors. 2FA implying two factors and MFA more than two. The more the merrier with security.

Separating MFA between devices will give you an added layer of security. If one of your security factors gets bypassed, your phone ported for example, you will still be able to maintain that second layer of defense to restrict access to that account. 

Having your tokenized security app, email second factor or even SMS alert on another private secure line is a great added layer of security. Secure your accounts with tokenized 2FA at a minimum. 



Fungible or non fungible cyber show?
Blockchain, cryptocurrency, stablecoin or token, Each are different



There are different types of blockchains, public, private and permissioned. 
There are different types of cryptocurrencies.
There are different types of stablecoins.
There are different types of tokens.

Know the difference between Bitcoin, Ethereum and Libra before you invest. Be careful with misinformation when it comes to crypto and investing in general.

 Get verified information.


The Cybersecurity Show By Dominic Alvieri
The Cyber Show by Dominic Alvieri, @AlvieriD

The Cybersecurity Show by Dominic Alvieri
The Cyber Show on Google Blogger and YouTube
    @AlvieriD

Wednesday, April 21, 2021

US DMV Information Comes From China

Fake DMV Links to Chinese Phishing Company

By Dominic Alvieri
April 21, 2021

DMV Scams

GEICO has just reported a data breach. Customer drivers license numbers stolen from a bug for unemployment and other nefarious end goals according to Zack Whittaker. A similar DL breach was reported last month. 

This is data theft 101. Every state has victims of identity theft.


It doesn't matter where you live your data is available online. The simple annoying scam of it all.

The stolen data often gets resold after original criminals get what they can from them.


DMV Scams from China


The stolen lists often trickle down to these types of cyber criminals.

Drivers from California to New York are dealing with a variety of DMV spoofs. The Division of Motor Vehicles doesn't send out refunds or rebates.

That would be nice.


DMV refunds?


If it sounds to good to be true...



New domain info.


...it usually is.




China based scam group.


The same scam group runs a myriad of Amazon, Apple, Netflix and others phishing scams run on a daily basis.

The problem is that all of these scams are coming from the same malicious group in China. Scam after scam all coming from the same building location. A phishing company. The 21st century fishermen.


Amazon fake delivery notices.



Same DMV IP address


Same DMV IP address.

IP Geolocation


Malicious IP geolocation


Avoiding the plebian effort goes without saying but in this case the cybersecurity ears go up.

Direct spoofs are always annoying coming from a stolen data list and resold countless times over to different scammers on the DarkWeb. 

I can pinpoint the physical address and even pick it up on satellite. Official agencies have to follow up and apprehend the guilty party. This isn't as advanced as the GEICO bug breach but those lists wind up in these spoofing hands.




The Cyber Show on Google Blogger
by Dominic Alvieri




Thursday, April 8, 2021

The Masters of Spoof

 Can anyone compete with Chinese spoofs?




The Cyber Show on Blogger

What makes a good spoof?


The Cyber Show on Blogger


Chinese imported counterfeit goods have been around as long as time itself. Reproducing an item as close to the original as possible. Logo color and style. 

For the cyber criminal the goal is the same, just replicate and add urgency.


Amazon spoofs



Amazon is a global target.
The links are difficult to replicate but they they try.



The Chinese gangs use the same MO: NameCheap registers, Alibaba hosts and anything that can be will be spoofed. Amazon, Apple, Hulu, Netflix, USPS. The online version of the knock off brand.

NameCheap often surfaces with these new short link scam domains. The Chinese aren't the only ones playing this game but with years of experience they are ahead of the pack.

Often targeting the largest companies Amazon, Apple and Netflix to name a few.


Often rerunning the same campaigns with great success.


The Netflix scam
2020 Netflix scam resurfaces again.

The devil is in the details. Examine all links with great care. Or you can just not answer any email, text or call. Warranty anyone? 

Some are easier to spot. Best Buy and spot gold.






You can always go back to a landline, otherwise examine all links and go directly to the company.
The above spoofs are all pedestrian, at best. The better spoofs have been withheld to avoid duplication.

The email spoof is still the number one entry for a cyber criminal to gain access to your system.
Stay safe online and off.



The Cyber Show
by Dominic Alvieri
Twitter, @AlvieriD



Tuesday, March 16, 2021

What the Spoof

All Spoofs All the Time. 

By Dominic Alvieri, @AlvieriD
March 10th 2021



The Cyber Show by Dominic Alvieri



Everyone wants something for free.



Free Netflix and Hulu for a year?


Free Netflix and Hulu for a year to help us stay home? 

Forget about that the BMW lottery came in, and some alert in France? 







All of the following offers are coming from China. 



Spoofed SMS texts


Fake USPS delivery notices continue.




Fake USPS delivery notice.

Fake USPS SMS spoofs coming from China.


------.py


Free Netflix for a year to help you stay home.



This is a Netflix spoof.


Free Hulu for a year to help you stay home?

Is it Netflix or Hulu?





The new short domain attack continues.



                                  DO NOT

                               [click here] 









Spoofed emails have been around since the beginning of the internet. Spoofed SMS texts have been proliferating in the past few years. Knowing the domain endings is critical. Newly created short domains have been popping up with the same group. 

Technological reverse psychology if you will by tracking the bad guys back. The building below is from a Google Earth trace address of the malicious links geolocation. 



Geolocation of malicious SMS texts.
Geolocation of malicious SMS text links.


Time to harden your network security. Use VPNs and encrypted communication like Signal to minimize your surface. Use MFA and tokenized apps like Google or Microsoft Authenticator over SMS. Incognito mode is not optimal security for your browser. Tor is acceptable but slow. Nothing is full proof. Check your home network and make sure to disable port forwarding and also disable the plug n play otherwise you are leaving a back door open.

IoT devices should be secured. Check for open standards, basic passwords and check for any and all updates and patches. Patch often and early. Do not hesitate. Within 12 hours of the server exchange hack Russian bad actors were scanning for the vulnerability according to Bad Packets, a malicious scanning alert firm. 

Security minimums are no longer effective. Update to longer more difficult passwords and do not click on any suspicious link. Or avoid all links. Not realistic but you get the point. 

This IP with "no site" is the USPS spoofed SMS malicious text link above in this report.



IP address of SMS text malicious links.
Courtesy of DomainTools.



The enemies are at the gates, computers, networks, phones...








The Cyber Show on Google Blogger
by Dominic Alvieri


Twitter @AlvieriD

Friday, February 12, 2021

New edX Course Links to the Chinese Chief Information Office

 Redirected Link is Now Direct Link

 By Dominic Alvieri

Twitter @AlvieriD


January 23rd, 2021


Redirected link on edX is now a direct link.
Redirected link on edX.

The second largest online educational platform edX created by Harvard and MIT has been breached. Or has it?

A new Rochester Institute of Technology online advanced cybersecurity course on edX was redirected last week to the Chinese Government Chief Information Office in Wanchai, Hong Kong China.

Now the US InfoSec portion links directly to InfoSec China


Redirected edX link to China.
Redirected link last week.

The link above leads to the Chinese Government Chief Information Office in Wanchai, Hong Kong.


Link leads to Chinese Government Information Office.
Link leads to Chinese Government Chief Information Office.


Well how did that get there?

Rochester Institute of Technology and the Chinese professor were unavailable for comment. The redirected link in week one now have direct links to the Chinese government Chief Information Office.

The US InfoSec link now leads directly to the Chinese Chief Information Officer. That is not a typo.

It is still unclear if that is the destined source for the course information. After weeks of question still no answers to why they are still there.


US InfoSec page leads to InfoSec China


Unknown joint educational operation?



Redirected page is now direct.
Redirected page is now directly linked.


US Institutions of higher learning have been probed during the pandemic and warned by the FBI for collaborating with communist groups. The persistent picture painting and data collection by the communist government is under investigation and will update the information is confirmed.

I highly doubt this is the intended educational path for US Cybersecurity masters students but things may have changed in a year, besides the Presidency. 

Update pending with comments due some time in February, 2021.



The Cyber Show


Dominic Alvieri
Twitter @AlvieriD
The Cyber Show
The CyberSecurity Show on
Google Blogger and Medium.

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...