logo

Fake Lawsuit Threat Exposes Privnote Phishing Sites

ID: a401f5e8-b77f-5e27-ad70-0f140b6c11f2

STIX ID: report--a401f5e8-b77f-5e27-ad70-0f140b6c11f2

Feed Name: Krebs on Security

Threat Score
70/100

Date Published: 2024-04-04

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

A network of phishing sites impersonating the self-destructing messaging service Privnote (e.g., tornote.io, privnote.co, privatemessage.net and many similar domains) is actively replacing cryptocurrency addresses in user-created notes with attacker-controlled addresses to steal funds. The report documents domain registration patterns (including ties to registrant strings like “BPW” and “Tambov district”), shared hosting and IP infrastructure (including DDoS-Guard and IP 186.2.163.216), related phishing domains (including MetaMask phishing lookalikes), and measured financial activity (one set of malicious addresses collected nearly $18,000 between March 15–19, 2024).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.