Exposing the Kroll Crypto Wallet Scam
ID: 7c4ed4b3-8143-5870-b9f4-45f309a873a3
STIX ID: report--7c4ed4b3-8143-5870-b9f4-45f309a873a3
Feed Name: KnowBe4 Blog
Threat Score
The report describes a phishing campaign impersonating Kroll that leveraged legitimate sender domains and a newly-registered malicious landing domain to redirect victims to a page prompting WalletConnect/MetaMask approval; the author analyzes domain WHOIS/DMARC results, redirect behavior, and the wallet-connection flow, warning that supplying wallet credentials or approving connections would permit attackers to drain funds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
