Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block fake mee6 bot and others #11684

Merged
merged 3 commits into from Feb 23, 2023
Merged

Block fake mee6 bot and others #11684

merged 3 commits into from Feb 23, 2023

Conversation

dubstard
Copy link
Contributor

@dubstard dubstard commented Feb 23, 2023

Spear phish attempt via discord - fake mee6 bot - steals tokens and admin access of phished staff so scammers can post bogus links on behalf of the staff to instill trust.
This fake bot is extremely dangerous as is poses danger to the whole ecosystem.

This spear phishing scam attempt was made against a lot of DEX and DAO team members, but as the domain of the fake mee6 is fresh i imagine they might target other brands as well

I believe they wanted to get the staff team member to visit a bogus discord via web browser instead of the native client

and by "verifying" via the fake mee6 bot upon entering the fake coin market cap discord, the scammers obtain the discord tokens for access of the staff member and can then login as them (account take over)

Then they could wreck chaos by posting scam link inside the discord via the staff member's own account!!!!!

SCAM "instructions"
image

馃毄(huge red flag!)
image

TOKEN STEALING EXFIL - 馃毄(GIGA huge red flag!)
image

image
image
image
image

FAKE messages
image
image

full story:
https://twitter.com/steviepxyz/status/1628238813825847301

    "airdrop.claims",
    "antispambot.org",
    "antispambot.pro",
    "claim.uniswap.lc",
    "curvefi-wallet.co",
    "freethadrop.com",
    "harmonize-info.com",
    "mee6.rs",
    "metamask-finance.com",
    "metamask.546245.shop",
    "metamask.thisisnotalpha.com",
    "pancakeswaq.financial",
    "posvalidator-ethereum.info",
    "posvalidator-ethereum.net",
    "secure-login-coinbase.com",
    "secure-reset-coinbase.com",
    "stfx-airdrops.org",
    "xrpdouble-promotion.com",
    "mclarenautto.xyz",
    "uniswap.gg",
    "uniswap.lc",
    "user663225-metamask.ddns.net",
    "web3-dapps-pages-dev.netlify.app",
    "wvw-sushiswap.icu",
    "wwwmetamask-io.myvnc.com",
    "wwwunlockexodus.xyz", 

```
    "airdrop.claims",
    "antispambot.org",
    "antispambot.pro",
    "claim.uniswap.lc",
    "curvefi-wallet.co",
    "freethadrop.com",
    "harmonize-info.com",
    "mee6.rs",
    "metamask-finance.com",
    "metamask.546245.shop",
    "metamask.thisisnotalpha.com",
    "pancakeswaq.financial",
    "posvalidator-ethereum.info",
    "posvalidator-ethereum.net",
    "secure-login-coinbase.com",
    "secure-reset-coinbase.com",
    "stfx-airdrops.org",
    "xrpdouble-promotion.com",
    "mclarenautto.xyz",
    "uniswap.gg",
    "uniswap.lc",
    "user663225-metamask.ddns.net",
    "web3-dapps-pages-dev.netlify.app",
    "wvw-sushiswap.icu",
    "wwwmetamask-io.myvnc.com",
    "wwwunlockexodus.xyz", 
```
@409H 409H added the blocklist addition Issue or PR requesting addition of a domain to the blocklist label Feb 23, 2023
409H
409H previously approved these changes Feb 23, 2023
dupe "stfx-airdrops.org",
already existed on line 1014 (after rebasing)
Copy link
Contributor Author

@dubstard dubstard left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dupe "stfx-airdrops.org",
already existed on line 1014 (after rebasing)

@409H 409H merged commit b22ed08 into MetaMask:main Feb 23, 2023
@dubstard
Copy link
Contributor Author

Thanks for the merge chief

@dubstard dubstard deleted the patch-170 branch March 21, 2023 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
blocklist addition Issue or PR requesting addition of a domain to the blocklist
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants