Elaborate zero-day browser break-out betrayed by unusual behavior
Coinbase chief information security officer Philip Martin this week published an incident report covering the recent attack on the cryptocurrency exchange, revealing a phishing campaign of surprising sophistication.
At some point prior to that, the attackers â a group known to Coinbase as CRYPTO-3 or sometimes HYDSEVEN â compromised or created two email accounts at Cambridge.
Two days before the initial emails went out, they registered a domain to deliver their exploit, Martin said.
After corresponding with the initial set of targets â about 200 â through a series of messages over several weeks, the hackers winnowed their list of prospective victims down to five specific marks.
"Stage one of this attack first identified the operating system and browser, and displayed a convincing error to macOS users who were not currently using Firefox, instructing them to install the latest version from Mozilla," Martin wrote.