02-10-2020, 05:35 AM
| 0 | 0 | ||
How Coinbase was targeted with emails booby trapped with Firefox zero-days
Elaborate browser break-out betrayed by unusual behavior
Coinbase chief information security officer Philip Martin this week published an incident report covering the recent attack on the cryptocurrency exchange, revealing a phishing campaign of surprising sophistication.
The thwarted attack began with email messages on May 30 to more than a dozen Coinbase employees that appeared to be from Gregory Harris, a research grant administrator at the University of Cambridge in the UK.
At some point prior to that, the attackers – a group known to Coinbase as CRYPTO-3 or sometimes HYDSEVEN – compromised or created two email accounts at Cambridge. Two days before the initial emails went out, they registered a domain to deliver their exploit, Martin said.
These messages represented reconnaissance for a phishing campaign that extended beyond Coinbase. After corresponding with the initial set of targets – about 200 – through a series of messages over several weeks, the hackers winnowed their list of prospective victims down to five specific marks. These individuals – macOS users not using Firefox – received messages with malicious links.
In an Aug. 8 blog post that sets out in technical detail how the plot unfolded and how the exchange countered the attempted theft, Coinbase said the hackers used a combination of means to try and hoodwink staff and access vital systems – methods that included spear phishing, social engineering and browser zero-day exploits
"Stage one of this attack first identified the operating system and browser, and displayed a convincing error to macOS users who were not currently using Firefox, instructing them to install the latest version from Mozilla," Martin wrote. "After visiting the page in Firefox, the exploit code was delivered from a separate domain, analyticsfit com, which was registered on May 28."
The exploit payload used two Firefox zero-day vulnerabilities, a JavaScript privilege escalation flaw (CVE-2019–11707) and a browser sandbox escape (CVE-2019–11708), now patched by Mozilla. According to Martin, the latter vulnerability was discovered simultaneously by Samuel Groß, a security researcher with Google’s Project Zero, and someone in the attack group or someone who provided it to them.













