emails – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 03 Sep 2025 19:49:26 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 emails – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 I get lots of emails and do they say there’s a little coin for you to charge? (Duplicate) https://earlybirdsinvest.com/i-get-lots-of-emails-and-do-they-say-theres-a-little-coin-for-you-to-charge-duplicate/ https://earlybirdsinvest.com/i-get-lots-of-emails-and-do-they-say-theres-a-little-coin-for-you-to-charge-duplicate/#respond Wed, 03 Sep 2025 19:49:26 +0000 https://earlybirdsinvest.com/i-get-lots-of-emails-and-do-they-say-theres-a-little-coin-for-you-to-charge-duplicate/

No, when transferring or selling Bitcoin, you do not need to pay any additional fees in advance first.

Being asked to pay with extra money for any kind of fee is the trick of a confident trickster (conmen, con artist, con artist)

A regular Bitcoin transaction deducts a small amount of Bitcoin from the balance Transaction fee (Not a transfer fee) But this is not an extra thing you pay. Currently, transaction fees are very high at around $30 per transaction (it was under $1 a year ago). Actual fees vary depending on the complexity of the transaction and the speed at which the transaction is processed. You should not make any further payments and will need to automatically deduct any additional amounts from your Bitcoin balance. This is transaction It’s not a price transfer commission. Regular Bitcoin transactions do not have transfer fees or transfer codes.

When dealing with any business, there is no surprise fee. You should be able to find business conditions on their webpage Without talking to anyone in the business. The fees that come as a surprise are signs of a possible scam.

]]>
https://earlybirdsinvest.com/i-get-lots-of-emails-and-do-they-say-theres-a-little-coin-for-you-to-charge-duplicate/feed/ 0 56596
Kroll Hit With Lawsuit After FTX Creditors Slam Daily Scam Emails https://earlybirdsinvest.com/kroll-hit-with-lawsuit-after-ftx-creditors-slam-daily-scam-emails/ https://earlybirdsinvest.com/kroll-hit-with-lawsuit-after-ftx-creditors-slam-daily-scam-emails/#respond Sun, 24 Aug 2025 03:16:39 +0000 https://earlybirdsinvest.com/kroll-hit-with-lawsuit-after-ftx-creditors-slam-daily-scam-emails/

Kroll, a risk and financial advisory firm, is facing a class-action lawsuit over its handling of an August 2023 data breach that exposed information belonging to creditors of FTX, BlockFi, and Genesis.

The case, filed by Hall Attorneys in a US district court, represents FTX customer Jacob Repko and other affected creditors.

The complaint argues that attackers used stolen details from the breach to launch ongoing phishing campaigns. Many creditors said they receive scam emails almost every day.

Sidechains in Crypto Explained EASILY (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

FTX creditor Sunil Kavuri shared screenshots showing repeated attempts, including several messages sent between August 14 and 17.

The lawsuit also pointed to weaknesses in how Kroll contacted creditors. The company relied only on email, a method that scammers could easily imitate. According to the filing, the method weakened trust, disrupted the claims process, and in some cases led to losses.

The plaintiffs are asking not only for damages but also for changes in Kroll’s communication methods. They argued that creditors should not be left with a single channel that criminals can copy.

Nicholas Hall, who leads Bankruptcy and Complex Litigation at Hall Attorneys, noted that affected creditors could be eligible for compensation. He added that the case could push Kroll to update its operations.

Hall also runs the FTX Claims website, which helps creditors manage their claims.

On August 11, FTX’s former users asked a court to let them update their lawsuit against Fenwick & West. What did they say? Read the full story.


]]>
https://earlybirdsinvest.com/kroll-hit-with-lawsuit-after-ftx-creditors-slam-daily-scam-emails/feed/ 0 54816
PayPal “New Address” feature abused to send phishing emails https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/ https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/#respond Sun, 23 Feb 2025 22:45:09 +0000 https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/

PayPal

An ongoing PayPal email scam exploits the platform’s address settings to send fake purchase notifications, tricking users into granting remote access to scammers

For the past month, BleepingComputer and others [1, 2] have received emails from PayPal stating, “You added a new address. This is just a quick confirmation that you added an address in your PayPal account.” 

The email includes the new address that was allegedly added to your PayPal account, including a message claiming to be a purchase confirmation for a MacBook M4, and to call the enclosed PayPal number if you did not authorize the purchase.

“Confirmation: Your shipping address for the MacBook M4 Max 1 TB ($1098.95) has been changed. If you did not authorize this update, please reach out to PayPal at +1-888-668-2508′,” reads the scam email.

PayPal smishing text and landing page
PayPal “new address” feature abused in scam
Source: BleepingComputer

The emails are being sent directly by PayPal from the address “service@paypal.com,” causing people to be concerned their account was hacked.

However, those who received this email confirmed that no new addresses were actually added to their accounts. In our case, the scam email was sent to an email address with no PayPal account.

Furthermore, as the emails are legitimate PayPal emails, they are bypassing security and spam filters. In the next section, we will explain how scammers send these emails.

The goal of these emails is to trick recipients into thinking their account was hacked to purchase a MacBook and scare the email recipient into calling the scammer’s “PayPal support” phone number.

When calling the number, a recording will automatically play stating that you have reached PayPal customer service and to hold while a support person becomes available. The call will then attempt to connect you to a “customer support” person.

This scammer will try to scare you into thinking your account was hacked and convince you to download and run the software so that they can “help” you regain access to the account and block the alleged transaction.

The scammer will direct you to visit a site like pplassist[.]com and enter a service code given by the fake PayPal employee. Entering this code will download a ConnectWise ScreenConnect client [VirusTotal] from lokermy.numaduliton[.]icu or other sites, which the scammer will ask you to run.

Scammer's site to distribute ConnectWise ScreenConnect
Scammer’s site to distribute ConnectWise ScreenConnect
Source: BleepingComputer

At this point, we hung up on the scammer and did not execute the program on our devices.

However, in previous scams like this, once the threat actor gains access to the computer, they attempt to steal money from bank accounts, deploy malware, or steal data from the computer.

Therefore, if you receive a legitimate email from PayPal stating you updated your address, and it contains a bogus purchase confirmation, simply ignore the email and do not contact the listed phone number as it belongs to the scammer.

To be safe, instead, log into your PayPal account and confirm no additional addresses were added, and if not, junk the email.

How the PayPal scam works

When BleepingComputer first received this email, we were confused as the email was sent from “service@paypal.com” to an email address that does not have a PayPal account associated with it.

Furthermore, the mail headers show that the emails are legitimate, passing DKIM email security checks and originating directly from PayPal’s mail server, as shown below.

Received: from mx1.phx.paypal.com (mx1.phx.paypal.com. [66.211.170.87])
        by mx.google.com with ESMTPS id 41be03b00d2f7-addf237d3e1si10521113a12.387.2025.02.18.07.30.09
        for 

It was unclear at first how these legitimate emails were being sent from PayPal until we noticed this text at the bottom of the email.

“If you want to link your credit card to this address, or make it your primary address, log in to your PayPal account and go to your Profile,” reads the PayPal email notification.

“Since this address is a gift address, you can send packages to it with just a click.”

Further research revealed that “gift addresses” are just additional addresses you can add to your PayPal profile.

In a test, BleepingComputer added a new address to one of our accounts and pasted the scammer’s fake MacBook purchase confirmation message into the Address 2 field.

After saving the address, PayPal sent us the same confirmation email, notifying us of the new address we added, which also included the fake purchase message.

Now that we know how they are generating the email from PayPal, we still do not know how they are getting PayPal to send it to all of the targets.

Upon further analysis of the mail headers, we can see that the email is actually being sent to the address “noreply_@usaea.institute,” which is the email address associated with the scammer’s PayPal address.

The headers further show that this email address automatically forwards the email it receives to “bill_complete1@zodu.onmicrosoft.com”, an account associated with a Microsoft 365 tenant.

This account is likely a mailing list, which automatically forwards any email it receives to all other group members. In this case, the members are you and I, the scammer’s targets.

When they add the scam address to PayPal, the payment platform will email a confirmation to the threat actor’s email, which will then forward it to the Microsoft 365 account, which then forwards it to everyone on the mailing list, as shown in the flow chart below.

Scam attack flow
Scam attack flow
Source: BleepingComputer

PayPal enables this scam by not limiting the number of characters in the address form fields, allowing the threat actors to inject their scam message.

To fix this, PayPal needs to restrict the number of characters in the address field to a reasonable character count, like 50 characters, if not less.

BleepingComputer contacted PayPal about this scam and is awaiting a response to our email.

]]>
https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/feed/ 0 21454
Hackers steal emails in device code phishing attacks https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/ https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/#respond Sat, 15 Feb 2025 21:38:16 +0000 https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/

Microsoft: Hackers steal emails in device code phishing attacks

An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing.

The targets are in the government, NGO, IT services and technology, defense, telecommunications, health, and energy/oil and gas sectors in Europe, North America, Africa, and the Middle East.

Microsoft Threat Intelligence Center tracks the threat actors behind the device code phishing campaign as ‘Storm-237’, Based on interests, victimology, and tradecraft, the researchers have medium confidence that the activity is associated with a nation-state operation that aligns with Russia’s interests.

Device code phishing attacks

Input constrained devices – those that lack keyboard or browser support, like smart TVs and some IoTs, rely on a code authentication flow to allow allowing users to sign into an application by typing an authorization code on a separate device like a smartphone or computer.

Microsoft researchers discovered that since last August, Storm-2372 abuses this authentication flow by tricking users into entering attacker-generated device codes on legitimate sign-in pages.

The operatives initiate the attack after first establishing a connection with the target by “falsely posing as a prominent person relevant to the target” over messaging platforms like WhatsApp, Signal, and Microsoft Teams.

Messages Storm-2372 sent to targets
Messages Storm-2372 sent to targets
Source: Microsoft

The threat actor gradually establishes a rapport before sending a fake online meeting invitation via email or message.

According to the researchers, victim receives a Teams meeting invite that includes a device code generated by the attacker.

“The invitations lure the user into completing a device code authentication request emulating the experience of the messaging service, which provides Storm-2372 initial access to victim accounts and enables Graph API data collection activities, such as email harvesting,” Microsoft says.

This gives the hackers access to the victim’s Microsoft services (email, cloud storage) without needing a password for as long as the stolen tokens remain valid.

Device code phishing attack overview
Device code phishing attack overview
Source: Microsoft

However, Microsoft says that the attacker is now using the specific client ID for Microsoft Authentication Broker in the device code sign-in flow, which allows them to generate new tokens.

This opens new attack and persistence possiblities as the threat actor can use the client ID to register devices to Entra ID, Microsoft’s cloud-based identity and access management solution.

“With the same refresh token and the new device identity, Storm-2372 is able to obtain a Primary Refresh Token (PRT) and access an organization’s resources. We have observed Storm-2372 using the connected device to collect emails” – Microsoft

Defending against Storm-2372

To counter device code phishing attacks used by Storm-2372, Microsoft proposes blocking device code flow where possible and enforcing Conditional Access policies in Microsoft Entra ID to limit its use to trusted devices or networks.

If device code phishing is suspected, immediately revoke the user’s refresh tokens using ‘revokeSignInSessions’ and set a Conditional Access Policy to force re-authentication for affected users.

Finally, use Microsoft Entra ID’s sign-in logs to monitor for, and quickly identify high volumes of authentication attempts in a short period, device code logins from unrecognized IPs, and unexpected prompts for device code authentication sent to multiple users.

]]>
https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/feed/ 0 19711