216.73.217.22

Disallow: /security-research? Crypto Phishing Sites' Failed Attempt to Block Investigators

· Published 30/09/2025 18:11 · Modified 30/09/2025 20:09

Export JSON

Essential information

Published
30/09/2025 18:11
Modified
30/09/2025 20:09
Tags
2025-09-30 cloudflare pages cryptocurrency github hardware wallets phishing robots.txt
Related entities
2 observables, 4 techniques (mitre), 2 others

Description

An analysis of files revealed over 60 pages impersonating hardware wallet brands Trezor and Ledger. The actor behind these pages attempted to block reporting sites by including their endpoints in the file, demonstrating a misunderstanding of its function. Most sites were hosted on , with a few on custom domains. The campaign's unusual pattern was also found in repositories containing crypto-themed spoof pages. Merge conflicts in README files suggest the actor may lack web development expertise. Various free web hosting providers were used for similar spoofed pages. The campaign highlights the ongoing targeting of users and the potential effectiveness of even poorly executed attempts.

External references