Trezor hardware wallet users have been targeted by an unusually convincing phishing campaign after attackers compromised a third-party email provider used by the manufacturer. A fraudulent email titled « Critical Security Alert: STM32 Entropy Vulnerability » was distributed to some customers. The malicious messages passed SPF, DKIM, and DMARC security checks and appeared to come from the address help@trezor.io, making them difficult to detect. The attackers attempted to create urgency by claiming devices had an entropy vulnerability and redirected users to a fake security verification process. Companies BitBox and CoinTracking also reportedly fell victim to similar campaigns, with email provider Brevo being identified by some investigators as the common infrastructure.
Source: Read the original article

