http://www.reddit.com/r/Bitcoin/comments/1zaqvy/bitstamp_email_list_used_to_spread_mtgox_malware/I have a domain that I use to create unique emails for signing up at all kinds of services. It's all explained at bustspammers.com. Today I received this email:
---------------------------- Original Message ----------------------------
Subject: [MtGox] Dear Clients ..
From: "MtGox" <
[email protected]>
Date: Sat, March 1, 2014 12:29 pm
To: "[redacted]" <[redacted]@bustspammers.com>
--------------------------------------------------------------------------
Dear MtGox Customers,
Please sign the papers attached, we can complete the process of closing the account
and send you what the balance to another Wallet Address.
Sincerely ,
Tomas Karpeles
1 / March 2014
Download Documents
This is the plain-text version. In the original HTML email, the "Download Documents" link led to a page on deseobc.com distributing malware (a .pif executable, they attempted to make it look like a .pdf). This means one of three things:
Bitstamp is actively pushing malware onto their own clients.
Someone stole Bitstamp's email list.
Bitstamp sold their email list to scammers.
Knowing that many Bitstamp users likely were also Mt.Gox users and might be easy targets, provides an obvious motivation for a scam. I asked Bitstamp for comment, will update this post if I hear anything back.
Bitstamp's email list was confirmed stolen ~2 weeks ago, when a boatload of emails claiming to be from
[email protected] (but not sent from any of the BTC Guild mail servers) went out talking about a 3.201 bitcoin transfer. After replying to the people shouting at me for being a scammer, I was eventually able to narrow the source of the leak to Bitstamp at the very least, and likely a few other sources on top of it.
I informed Bitstamp that they had at least a breach on their email list, if not the rest of their system. At first they denied it, but in a follow up they eventually admitted to it.They then sent out a little security update email mentioning 2FA/password security.
I can confirm 3 same email "from" mtgox"
Dear MtGox Customers,
Please sign the papers attached, we can complete the process of closing the account and send you what the balance to another Wallet Address.
Sincerely,
Mark Karpeles
February 26th 2014
Download Documents
first 2 emails didn't have URL in "Download Documents"
and 3rd one was:
Dear MtGox Customers,
Please sign the papers attached, we can complete the process of closing the account and send you what the balance to another Wallet Address.
Sincerely ,
Tomas Karpeles
1 / March 2014
Download Documents
This (3rd one) is linking to
http://dese--DO-NOT-CLICK--obc.com/style/imports/goxdocuments/?PaperMtgox.pdfSry for didn't post sooner - was thinking its known already - but now i didnt find any thread (and sry again if there already are some - pls posts links as reply) about it ...
And I also received 3 from btcguild.
1st:
2nd+3rd within 1 hour:
https://www.btcguild.com/A recent phishing scam has been pretending to be from [email protected]. This email did not come from us, and is trying to spread a virus. WARNING * mtgox SPAM SCAM fake Documents downloads - bitstamp btcguild btc-e