logo

Disallow: /security-research? Crypto Phishing Sites' Failed Attempt to Block Investigators

ID: 43eeac6f-998c-574f-be22-7650eaf693ab

STIX ID: report--43eeac6f-998c-574f-be22-7650eaf693ab

Feed Name: Censys Blog

Threat Score
55/100

Date Published: 2025-09-29

Date Updated: 2026-04-27

Author: Ivonne Francia; Emily Austin

...
...

*Executive Summary:* Censys discovered a phishing campaign impersonating Ledger and Trezor hardware wallet sites by searching for an unusual robots.txt entry (Disallow:/add_web_phish.php), finding over 60 spoofed pages—mostly hosted on free static-site platforms (Cloudflare Pages) and linked to GitHub repositories with similar artifacts and misconfigured READMEs; the campaign appears low in technical sophistication but poses direct financial risk to unsuspecting cryptocurrency users and includes actionable indicators (hostnames, robots.txt pattern, repository traces) for detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.