We dealt with 45 total incidents over the past week. Reported losses by threat category:

1) Protocol compromise $5.7M

2) Wallet drain $2.8M

3) DPRK intrusion $1.5M

4) "Fake support" caller $320k + 3 BTC + 3.4 ETH

5) Cause unknown $123.7k

6) Malware $52 BTC + $5k

What we collected

  • 4,926 phishing domains
  • 5,056 indicators published
  • 129 wallets86 URLs

565 of those domains impersonate Ledger, 8x more than the next closest brand.

IOCs

Fake meetings cluster (currently tracked by SEAL as SINT-69 - an uncategorized intrusion set):

  • microteam[.]app
  • teamms[.]app
  • neowixbox[.]us
  • wirevixbox[.]us
  • 45.61.144[.]43
  • 45.61.144[.]44
  • 88.119.174[.]194

Confirmed DPRK / UNC1069 domains we saw this week:

  • us05lives[.]us
  • us06liues[.]us
  • teans[.]live
  • teamsliuvs[.]com
  • teamsmicsoft[.]com
  • tezmslive[.]com

Fake video conferencing cluster (Traffers), new brand deployed:

  • mefex[.]app
  • mefex[.]me
  • mefex[.]online
  • customefex[.]net
  • custo-mefex[.]world

Fake podcast and recording lures:

  • streamyard[.]im
  • riverside[.]stream

Our incident response service is free to anyone who needs it, and stays that way because people from the community fund it.If this week's numbers are useful to you, fund the next one: https://securityalliance.org/donate

If you require a direct data feed from SEAL-ISAC, contact us at [email protected].

The link has been copied!