Author

Topic: Someone is sending fake Bitmaintech emails with attached wallet stealer (Read 7375 times)

DrG
legendary
Activity: 2086
Merit: 1035
For new uses, simple ways to protect your coins:
1) Don't access the web/internet on the machine that hosts your wallet
2) If you have the time, move/convert your wallet (the file with your private keys) into a paper wallet.  Paper might be ancient but I have yet to see a trojan/malware that is able to read paper (except somebody hacking your webcam)
3) If using a digital wallet file, encrypt it with a password/passphrase that is unique (not used anywhere else) and is difficult enough to not be bruteforced
4) Learn to use cold wallets and put the majority of your coins in that wallet

Learn to use the tools that the community has created.  There are several alternatives to the base Bitcoin-QT that can offer increased security options.  If you have a significant value of coins it may be prudent to invest a little time learning how to use something like a cold walllet with Armory or one of the other alternative clients:
https://bitcointalk.org/index.php?board=37.0

Armory has a walkthough of how to make a offline/cold wallet here:
https://bitcoinarmory.com/about/using-our-wallet/
sr. member
Activity: 1439
Merit: 380
Bitcoin Casino Est. 2013
.Jar , yes must careful when download this kind of file.
And now i see some scammer try to spread this via skype , they act nicely ,talk something good and at last he will send some file for us to download.
Maybe he will say that file is bot , free btc etc.
legendary
Activity: 1401
Merit: 1008
northern exposure
ty xzempt for advert us, maybe some ppl will think that this is stupid and only stupid ppl got scammed, but beleive me, there is lot of ppl that got scammed bacause of that scam emails.

LOL fake emails never get old Cheesy

and this is a real problem, there is always ppl trying to fu*k you, as i always recommend, common sense is the best wall you can have agains those things.
hero member
Activity: 532
Merit: 500
Maybe it's BFL or AMT both desperate for cash seeing how they could not get away with scamming new customers and need other sources of revenue Tongue
legendary
Activity: 1274
Merit: 1004
I just got an email with a shipping notice from Bitcoinrigs.org, even though I've never ordered anything from them.
The reply to address appears to be from Stamps.com, through I didn't actually load any of the content to look at it.

I wonder if they're related?
legendary
Activity: 1666
Merit: 1185
dogiecoin.com
Received an email today from them. Unsure how they got my mail address.

Subject:
[Bitmaintech.com]  Invoice Payment (#4142)

Message:
Invoice Payment Confirmation

Kind regards ,
Bitmain Tech

14836 E Valley Blvd
La Puente, CA 91746
Email: [email protected]
Phone: (888) 933-2313

Attachment:
invoice_4142.jar


Using Gmail, it didn't reach my spam, right in my main inbox.

I had one in this format
hero member
Activity: 537
Merit: 524
About a month a go I was getting these spam emails with a jar attached from knc, cointerra and cloudhashing. Never registered with two of them so I'm guessing my emailaddress was leaked from somewhere else.

recently i started getting phising emails from various well known businesses such as btc-e , minereu , and many other exchange sites.

Not sure if it is only me but is there something i am missing? I will get about 4-5 a week. Anyone else having this same problem?

There's been so many bitcoin site hacks over the years that if you've been in it long enough it's all but guaranteed you have an email on a list somewhere.  If you're lucky, you used a throw-away/spam only address.  MtGox and Bitstamp both had database compromises that at the very least dumped a complete list of all their users emails on multiple occasions.

Just be careful about opening attachments as usual (aka: don't do it).  I probably get about a dozen a week with .jar files attached pretending to be invoices/miner screenshots.
Also, btctalk was ofcourse hacked a while back so not surprising my emailaddress is out there.


Also, this spam/phishing with jar files is nothing new:

https://bitcointalksearch.org/topic/who-else-is-getting-the-jar-email-spam-694747
https://bitcointalksearch.org/topic/malware-spam-targeting-bitcointalk-users-774167
https://bitcointalksearch.org/topic/beware-multiplatform-malware-try-to-steal-your-wallet-652085
hero member
Activity: 532
Merit: 500
The question noone seems to be asking is....how did they get those emails in the first place? It seems there may be a common thread there. Was BCT hacked and we are not aware of it? Or were one of the vendors hacked and the emails gotten that way? There clearly was a security breach or else the scammers would not know to specifically target people who have bought mining hardware.
member
Activity: 70
Merit: 10
Burn the wings off those bastards.
Viper (Scrypt) Miner - Alpha Technology email came in with a JAR file as well.

Someone pushing it hard.
ojm
newbie
Activity: 13
Merit: 0
Received an email today from them. Unsure how they got my mail address.

Subject:
[Bitmaintech.com]  Invoice Payment (#4142)

Message:
Invoice Payment Confirmation

Kind regards ,
Bitmain Tech

14836 E Valley Blvd
La Puente, CA 91746
Email: [email protected]
Phone: (888) 933-2313

Attachment:
invoice_4142.jar


Using Gmail, it didn't reach my spam, right in my main inbox.
sr. member
Activity: 392
Merit: 250
What a pity ,that they can't find a decent job. Instead go around the web stealing people money that doesn't belong to them.
sr. member
Activity: 378
Merit: 250
cant even spell address properly,what scrubs
sr. member
Activity: 462
Merit: 251
LOL fake emails never get old Cheesy
hero member
Activity: 572
Merit: 500
The mining business is transforming Smiley now the emergent tech is to mine wallets directly .. LOL
hero member
Activity: 714
Merit: 500
jar files are java executable, don´t download it (there is only a very small amount of software that is actually a jar, and you would rememer ordering such a software).

This has happened with several spoofed email adresses of hardware manufacturers, so it is more likely the actual email list was leaked on another platform
(or that all email adresses from these manufacturers are stored in an unsafe way)
full member
Activity: 206
Merit: 100
i just got something similar from [email protected] but all mine said was payment confirmation and then a invoice_424.jar file.
sr. member
Activity: 358
Merit: 255
I have been getting these for the past week or so all claiming to be from different vendors.


 
hero member
Activity: 798
Merit: 1000
Seems like scammers are trying everything they can to phish for bitcoins these days. Simply follow the golden rule:
Don't click on links from people you don't know.
hero member
Activity: 504
Merit: 500
Just got this in an email overnight.






-----------------------------------------


Dear User

Thank you For shopping form bitmaintech.com

we have received Miner order

we have send you link invoice to see shipping adress and  product
 
To show invoice , go to:

it had a url that went to vanguardsingle.com.au/xxxxxxxxxx/invoice.pdf..........jar



Regards,


Administration of  bitmaintech.com

be careful please.
Jump to: