PlatoAiStream

PlatoAiStream

  • About
  • Discover
  • OpenAi
  • DefiX
  • Features
  • Connect
  • Login
  • Register
PlatoAiStream

PlatoAiStream

  • Discover
  • Plato Search
  • Plato Verticals
    • Aerospace
    • AI
    • AR/VR
    • Automotive
    • Aviation
    • Big Data
    • Blockchain
    • Cannabis
    • Carbon
    • Cleantech
    • Code
    • Crowdfunding
    • Cybersecurity
    • Defense
    • E commerce
    • E Sports
    • Edtech
    • Fintech
    • Forex
    • Gaming
    • IOT
    • Medical Devices
    • Nano Technology
    • Patents & IP
    • Payments
    • Private Equity
    • Quantum
    • Real Estate
    • SaaS
    • Semiconductor
    • SPACs
    • Startups
    • Supply chain & Logistics
    • Venture Capital
  • Plato AiStreams
    • Arabic
    • Chinese
    • Dutch
    • English
    • Finnish
    • French
    • German
    • Greek
    • Hebrew
    • Hindi
    • Indonesian
    • Italian
    • Japanese
    • Korean
    • Norwegian
    • Polish
    • Portuguese
    • Russian
    • Spanish
    • Swedish
    • Thai
    • Turkish
    • Ukrainian
    • Vietnamese
  • Plato Newswire
  • Publications
    • 99 Bitcoins
    • ACN Newswire
    • ADVFN
    • Ai TimeJournal
    • Aisa PEVC
    • AlexaBlockchain
    • AMB Crypto
    • Asia Crypto Today
    • Asian Spectator
    • Asic Miner Market
    • Baystreet
    • Bitcoin Market Journal
    • Bitcoin PR Buzz
    • Bitcoinist
    • BitcoinNewsMiner
    • Bitcon Chaser
    • Bitpinas
    • Bitrazzi
    • Bitsonblocks
    • Blockchain Curated
    • Blockchain Health Review
    • BlockNews Africa
    • Blockpit
    • Blokt
    • BTC Upload
    • Business News Asia
    • Business News.ph
    • Business Press 24
    • Central Charts
    • ChainTimes
    • CoinBeat
    • Coinbureau
    • CoinCentral
    • Coingenius
    • Coinigy
    • Coinnounce
    • Cointelegraph
    • Cointikka
    • Coin Edition
    • Crunchbase
    • Crypto News
    • Crypto News Point
    • Crypto News Review
    • Crypto NewsZ
    • CryptoClarified
    • Cryptocointrade
    • Cryptocoinzo
    • Cryptodiffer
    • CryptoGlobe
    • Cryptomininq
    • CryptoNezo
    • CryptoNinjas
    • CryptoPotato
    • Cryptoverza
    • DC Forecasts
    • Decrypt
    • Digital Notice
    • ECrypto News
    • EthBLog
    • Ethical Markets
    • EventsNewsAsia
    • Finanzachricten
    • Finyear
    • Firmen Presse
    • Futures Trading Charts
    • Influencing
    • Inside Bitcoins
    • Intell Asia
    • Jump Start
    • Kanalcoin
    • Kraken Blog
    • Lioncity
    • MENAFN
    • MetaNews
    • Micro Small Cap
    • Multichain
    • NFX
    • News BTC
    • News Tag
    • Null TX
    • OpenZeppelin
    • Platonet
    • Protos
    • PRWire
    • Press Malaysia
    • Primafelicitas
    • Quamnet
    • Quillhash
    • Sccop
    • Sinchew Business
    • Street Insider
    • Street Signals
    • Techphile
    • Techstars
    • The Daily Hodl
    • The Merkle
    • The CoinsPost
    • Times Tech
    • TIMM
    • Today NFT News
    • Unhashed
    • W3era
    • Web3Africa
    • Weiss Crypto Ratings
    • Zaikei
    • Zephyrnet
  • DefiX Gateway
    • Bitcoin ATMs
      • Bitcoin Depot
      • Bitstop
      • Byte Federal
      • Coin Source
      • Coinflip
      • Digital Mint
      • Insta Coin
      • Kurant
      • Local Coin
      • National Bitcoin
      • Rocket Coin
      • Smart Kiosk
    • Blockchain Events
      • Ai in Payments
      • AIBC
      • Asia Crypto Hong Kong
      • Bitcoin 2022
      • Blockchain Expo Global
      • Blockchain Expo NA
      • Blockchain Fest Asia
      • Blockchain Week Rome
      • Blockchance Europe
      • Blockchian Fest
      • Construction Blockchain Consortium
      • Crypto Asset Conference
      • Digital Assets Realised
      • Finnovex
      • Finnovex South Africa
      • Futurist Conference
      • Global Defi Summit
      • Global Fintech Fest
      • Government Blockchain Week
      • Hyperledger Global Forum
      • London Digital Assets Week
      • NFT.NYC
      • NFT Summit
      • Reg Tech Summit
      • Security Tokens Realised
      • Synopsis
      • The Blockchian Event
      • The Conference. NFT
      • Token 2049
    • Compliance
      • Blockpass
      • BrightID
      • Ciphertrace
      • Coinfirm
      • Colendi
      • Elliptic
      • Gresham International
      • Identity.com
      • Jolocom
      • KYC Chain
      • Maxcorp
      • Notabene
      • Solidus Labs
    • DAO’s
      • 0xDAO
      • Aave
      • Aavegotchi
      • ADAM Oracle
      • AlgoGems
      • Alien Worlds
      • Apollo Inu
      • Avocado
      • Bancor
      • Based Money
      • Battle Saga
      • Benchmark Protocol
      • BiShares
      • BitDao
      • Bitfari
      • Boardroom
      • BondAppétit Governance
      • BOSAGORA
      • BreederDAO
      • Bright ID
      • Burn Signal
      • Cennz
      • Choise
      • Compound
      • CLR Fund
      • Cream Finance
      • Creditbit
      • CrypCade
      • Crypto Gaming United
      • Curio
      • Curve
      • DAO HAUS
      • DAOLaunch
      • DAOStack
      • dDNS DAO
      • Decentral Games
      • Decentral Games ICE
      • Decision Token
      • Defi Omega
      • Dego Finance
      • Edge Ware
      • Estonia
      • Flamingo
      • Gnosis
      • Keeper Dao
      • Lex DAO
      • Machix
      • Meta Cartel
      • Meta Gamma Delta
      • Moloch Dao
      • MStable
      • Mutual DAO
      • Nectar
      • PieDAO
      • Snapshot
      • ADAO
      • Adapulse
      • ALDEA
      • Aquadano
      • Boss DAO
      • Cardamun
      • Cardano 4 Climate
      • Cardano Link
      • Cardano Makers
      • Cardano Native Token
      • cNFT meme-DAO
      • Crypto College
      • Deentra
      • EcoCashew.com
      • finclout.io
      • FIRE Token
      • Lovelace Academy
      • PIGY Token
      • Rare Bloom
      • SANADA
      • Sherpa Token
      • Simple Cardano
      • SPO JAPAN GUILD
      • Summon Platform
      • Sustainable ADA
      • TACF NFT Pilot Program
      • TADATek
      • The Cardano Lounge
      • Token Allies
      • TosiDrop
      • Veritree
      • Zero to Haskell
    • Dapps
      • 0xWarriors
      • Angel Battles
      • BingoCash
      • BitPonies
      • Block Fight
      • Block Lords
      • Chainmonsters
      • ChickenHunt
      • Crypto Cuddles
      • Crypto Fighters
      • Crypto Mining War
      • Crypto Wars
      • CryptoCats
      • CryptodDer
      • Cryptogs
      • Dragonereum
      • Drug Wars
      • Easy Ether
      • Energy Market
      • Ether Kingdoms
      • EtherCraft
      • Ethmoji
      • FishChain
      • Fuse Studio
      • Infiniverse
      • Lordless
      • Panda Fun
      • Royal Online Vegas
      • Shrimp Farm
      • SnailThrone
      • Torpedo Launch
      • World of Ether
    • Developers
      • 3Box
      • Aquatik Studios
      • Blaize
      • Block360
      • BlockBlox
      • Blockchain Center
      • Blockchain Foundry
      • Blockhunters
      • Blockwell
      • Cardinal Cryptography
      • Celer
      • Code Zeros
      • Cubycode
      • Dapplica
      • Debut Infotech
      • DevProvider
      • Ekoios
      • Emurgo
      • Etheralabs
      • EthWorks
      • Geneva Software
      • Gnosis
      • Hashcash Consultants
      • HireNinja
      • Idealogic
      • INC4
      • InMind Software
      • Interstellar
      • Ionixx
      • IOST
      • IT Companies
      • Kaikas
      • Keep.Network
      • Lemon
      • Lightning Network
      • LimeChain
      • Liquidity.Network
      • Merehead
      • Metronome
      • Minddeft Technologies
      • mStable
      • MVP Workshop
      • Mysterium Network
      • Nest
      • Nextrope
      • Node Factory
      • Nordwhale
      • OnGraph
      • Ontology
      • OpenLedger
      • Owlab
      • Parity
      • PixelPlex
      • Proof Suite
      • Provable Things
      • pTokens
      • Qualium Systems
      • Ramlogics
      • Ren
      • Shapeshit
      • SmartBox
      • SourceX
      • Stratus Cyber
      • Swirlds
      • Teamvoy
      • TechCreatix
      • Titanium Blockchain
      • TrendLine Global
      • Ubik Group
    • DEX’s
      • AirSwap
      • Balancer
      • Beefy
      • BitPortal
      • bSWAP
      • Curve
      • DexGuru
      • DEX Screener
      • Dolomite
      • DYDX
      • Eidoo
      • Ellipsis
      • Enzyme
      • HOKK Finance
      • IDEX
      • IX Swap
      • Jelly Swap
      • LayerSwap
      • Loopring
      • Matcha
      • Mavryk
      • Newdex
      • Orion
      • PancakeSwap
      • ParaSwap
      • Poocoin
      • Quickswap
      • Rome Terminal
      • SHIBA TOKEN
      • Totle
      • Uniswap
      • WBTC.Cafe
      • AdaSwap
      • BynetDEX
      • Cardance Swap
      • Dexada
      • Maladex
      • Occamx
      • Spectrum Dex
      • Sundae Swap
      • Thothus
      • WingRiders
    • Exchanges
      • Alphaex
      • Aryana
      • Azbit
      • Beaxy
      • Bidesk
      • Bitay
      • BITEXBOOK
      • Bitpanda Pro
      • BTC Markets
      • BTC-exchange
      • CBX
      • Chilebit
      • Cobinhood
      • Coin Bureau
      • Coindeal
      • CoinEgg
      • Coinlist
      • Coins Pro
      • Compound
      • Eidoo Hybrid Exchange
      • ErisX
      • Everbloom
      • Gemini
      • Gnosis
      • iDevex
      • IDEX
      • IncoreX
      • InstantBitex
      • Just Liquidity
      • LIQNET
      • Lykke
      • Onederx
      • OpenLedger
      • Red Matter
      • SIGEN.pro
      • Sistemkoin
      • Slicex
      • SparkDEX
      • Surbitcoin
      • Switcheo
      • Theta Nuts
      • Thore
      • Uniswap
      • Uniswap (V2)
      • Vaultoro
      • VBTC
      • Yacuna
    • Gaming
      • Aavegotchi
      • Age of Rust
      • Alien Worlds
      • Battle Racers
      • Big Time
      • City States
      • Crazy Defense Heroes
      • Cryowar
      • Crypto Space Commander
      • Crypto Voxels
      • CryptoBlades
      • CryptoZoon
      • Dark Country
      • Dvision Network
      • Elementos
      • Farmers World
      • Forest Knight
      • Guild of Guardians
      • Idle Cyber
      • Illuvium
      • Metalands
      • MetaWars
      • Mines of Dalarnia
      • Monkeyballc
      • Neon District
      • Neverdie
      • Noa
      • Pet Games
      • Phantom Galaxies
      • Plant vs Undead
      • R-planet
      • Revv Racing
      • Riot Racers
      • Sipher
      • Sky Weaver
      • Soccer Manager Elite
      • Somnium Space
      • Spells of Genesis
      • Splinterlands
      • Taurion
      • Upland
      • The Six Dragons
      • War of Crypta
      • War Riders
    • Insurance
      • Asure Network
      • BITRUST
      • Citizen Health
      • Etherisc
      • Hurricaneguard.io
      • Nexus Mutual
      • Nsure
      • Opium Insurance
      • VouchForMe
    • Launchpads
      • Birchal
      • Catapoolt
      • Causes
      • Crowdcube
      • Fundly
      • Give Campus
      • Goteo
      • Harbor
      • One Planet Crowd
      • Patreon
      • RealtyMogul
      • Rocket Hub
      • Startup Explore
      • Vedaslabs
      • Venture Crowd
      • Vested
    • Lending
      • CREAM Swap
      • Definer
      • Invesrse Finance
      • Torque
    • Marketplaces
      • Airbrick
      • Atomic Market
      • Collect
      • Crypto Slam
      • Crypto Waifu
      • DAO HAUS
      • EOS Name Swaps
      • Fyooz
      • Hivelist
      • Jugger World
      • LIBER
      • Lit.it
      • Miime
      • Myth Market
      • Nagemon
      • NEAR
      • NFT Key
      • NFT Mart
      • Paras
      • Rarible
      • Secret Auctions
      • Space Finance
      • Token Trove
      • Totle
      • Treasureland
      • Wax Stash
      • WaxArena
      • Waxplorer
      • Wyvren
      • Xanalia
      • YieldX
    • Mining
      • Blockware Solutions
      • Canaan Creative
      • CoinMiner
      • Cudo Miner
      • Cyberian Mine
      • ECOS Cloud Mining
      • Iliium
      • Innosilicon
      • IQ Mining
      • Livepeer
      • Miner Bros
      • MinerGate
      • MineShop
      • MiningStore
      • myMiner
      • New Mining
      • Obelisk
      • PandaMiner
      • Quantech
      • WhatsMiner
      • Whats Miner
    • NFTs
      • Anr Key
      • ApeSwap
      • Apex Crypto
      • Art Blocks
      • Atari NFT
      • Auto Glyphs
      • Axie Infinity
      • Bbvsea
      • Billboard ChartStars
      • Blockchain Heroes
      • Bluzelle
      • BTC Origins
      • Coincast
      • Crypto Voxels
      • DeadMau5
      • DevilsFlock
      • Digital Currensy
      • Entrepot
      • Euler Beats
      • Fractional
      • GraziaNFT
      • Gunslingers
      • HALF BAYCD
      • HashRush
      • Holaplex
      • Ikonic
      • INFINITE DODOS
      • Its Nuqtah
      • Larvalabs
      • Lavish Leopards Club
      • Meet Bits
      • MetaFans
      • Meta Mansions
      • Minters Collective
      • Monsters of Rap
      • NFT20
      • NFT Summit
      • Nifty Dudes
      • NOMINT
      • Rarible
      • RPlanet
      • RTFKT
      • RtistiQ
      • Secured Sneakers
      • Somium Space
      • The Hash Masks
      • The Horrors
      • Token Ocean
      • Topps GPK
      • Topps MLB
      • Upland
      • Weezer
    • Payments
      • Baanx
      • Bitt
      • Blockmove
      • Celer Network
      • Circle Invest
      • Flexa
      • Lightning Network
      • OmiseGO
      • Sablier
      • xDai Stable Chain
    • Resources
      • 100 Tasks
      • Ahura
      • ARCISPHERE
      • Askria
      • Blockchain Council
      • Blockchain Councilus
      • Blockchain Industry Group
      • Blockchain Research Institute
      • Cloud Credential
      • Club Swan Partners
      • Cogent Law
      • Crypto Valley
      • Digital Chamber
      • District0x
      • Energy Blockchain
      • EST Cap
      • Fastbase
      • Fibree
      • GBB Council
      • GDF
      • Government Blockchain Association
      • Global Blockchain Summit
      • Global Tech Council
      • Gov Chain
      • GSDC
      • Helium
      • Intercoin
      • Market Across
      • MediaShower
      • Reblonde
      • SHEQONOMI
      • TiiQu
      • Visionary
    • Sector Directory
    • Social
      • APPICS
      • D Tube
      • D.Buzz
      • Den
      • DLike
      • Lumeos
      • QUASA
      • Sense Chat
      • Steem Leo
      • Stem Social
    • Stablecoins
      • Augmint
      • DefiDollar
      • Empty Set Dollar
      • EOSDT
      • Frax
      • Gemini Dollar
      • Money on Chain
      • pTokens
      • USD Coin
      • WBTC
    • Staking
      • 88mph
      • Autofarm
      • Balancer
      • Barnbridge
      • bEarn Fi
      • Beefy Finance
      • Cream
      • Dokia Capital
      • HyperBlocks
      • Idle
      • Mythos
      • PancakeBunny
      • Phuture
      • Pickle
      • Rari Capital
      • Stake.Fish
      • Stake Capital
      • StakeWithUs
      • Stakin
      • Staking
      • Staking Facilities
      • xDai Stable Chain
      • xFai
      • Yield Farming
    • SupplyChain
      • 300 Cubits
      • Blockfreight
      • Blockhead Technologies
      • CargoCoin
      • CargoLedger
      • IMMLA
      • Konexial
      • Modum
      • OpenPort
      • Peer Ledger
      • SigmaLedger
      • Skuchain
      • SkyCell
      • SyncFab
      • T-Mining
      • TangoTrade
      • Tradeline
      • Unicsoft
      • WAVE
    • Trading Gateway
      • ACDX
      • Aurex
      • Belfrics India
      • Betoken
      • Bitgo
      • Bitgo Wallet
      • Coinsmart
      • DefiPulse Index
      • Diversi.fi
      • Erisx
      • FinNexus Options
      • Fulcrum
      • Hegic
      • Hetoro
      • Indexed Finance
      • Kirobo
      • Lien
      • Mith Cash
      • OpenFinance
      • Opyn
      • PieDAO
      • RosyWhale
      • RoundlyX
      • Simple Swap
    • Venture Capital
      • Abstract Ventures
      • Alpha Sigma
      • Arcanum Capital
      • BlueYard
      • Boost VC
      • Breyer Capital
      • Bridgit
      • BTC Inc
      • Collaborative Fund
      • Compound VC
      • Continue Capital
      • Dekrypt Capital
      • Electric Capital
      • Ethereum Community Fund
      • Fabric Ventures
      • Founders Fund
      • FreeS Fund
      • Future Perfect Ventures
      • GBIC
      • Gumi Cryptos
      • Hard Yaka
      • Hashed
      • HashKey Group
      • IMO Ventures
      • INBlockchain
      • Initialized Capital
      • INN Mind
      • IOSG Ventures
      • June Fund
      • KR1
      • Krypital
      • L4 Ventures
      • LD Capital
      • Lemniscap
      • Lightspeed Venture Partners
      • LinkVC
      • Matrix Partners
      • MetaStable
      • Metaverse Ventures
      • NGC Ventures
      • Notation Capital
      • Outlier Ventures
      • PANTERA Capital
      • Passport Capital
      • Placeholder VC
      • Polychain Capital
      • PreAngel
      • Protocol Ventures
      • Scalar Capital
      • Sequoia Capital
      • Signal Ventures
      • Social Capital
      • SVK Crypto
      • Union Square Ventures
      • Version One
      • Vy Capital
      • Walden Bridge Capital
      • Winklevoss Capital
      • Yeoman’s Capital
      • Youbi Capital
      • YoungStartup
    • Wallets
      • Agama
      • AirGap
      • AlphaWallet
      • AnkerPay
      • ANX Vault Wallet
      • Armory Wallet
      • Atomic Wallet
      • Aurex Wallet
      • Autonomy
      • BitcoinWallet
      • BitFi
      • Bither Wallet
      • BitKeep
      • Bitpanda
      • Bitpie
      • BitPortal
      • Blockmove
      • BlockWallet
      • CAKE
      • Coffee
      • Coin Wallet
      • Coinfy
      • Crypterium
      • Crypto.com
      • Daedalus
      • DeFi Saver
      • Dharma
      • Dhedge
      • Digibyte
      • Dogecoin Core
      • Eidoo
      • ElectronCash
      • ElectrumLTC
      • Electrum Wallet
      • EO.Finance
      • Evercoin
      • Foxlet
      • Ginco
      • Gnosis Safe
      • HB Wallet
      • HelioWallet
      • Huobi Wallet
      • Joule
      • KCash
      • Ledger
      • Linen App
      • Lykke Wallet
      • MatterFi
      • Memory Box
      • MetaMask
      • Mobi
      • Monedero
      • Monerujo
      • MultiDoge
      • Multis
      • Mycelium Wallet
      • Natrium Wallet
      • NEON Wallet
      • NEVERDIE
      • NGRAVE
      • OGPay
      • OpenLedger
      • OPOLO
      • Phoenix
      • Pirate Ocean
      • Prodoge
      • qPocket
      • Rabby
      • Skull Island
      • Stratis
      • Trust Wallet
      • Trust Wallet App
      • Trustology
      • UberPay
      • Vcash Client
      • Venly
      • WallETH
      • ZenGo
      • Zerion
      • ZTLment
  • Market Data
    • BTCUSD
    • Economic Data
    • Forex
    • Global Indices
    • GS vs Coin
    • Plato X25
    • Plato X40
    • Nasdaq 100
      • Activision
      • Adobe
      • Advanced Micro Devices
      • Alexion
      • Align Technology
      • Alphabet A
      • Alphabet C
      • Amazon
      • Amgen
      • Analog Devices
      • ANSYS
      • Apple
      • Applied Materials
      • ASML
      • Atlassian
      • Autodesk
      • Automatic Data Processing
      • Biogen
      • Booking Holdings
      • Broadcom
      • Cadence
      • CDW Corp
      • Cerner Corp
      • Charter Communications
      • Check Point
      • Cintas
      • Cisco
      • Cognizant
      • Coinbase
      • Comcast A
      • Copart
      • Costco
      • CSX
      • DexCom
      • Dollar Tree
      • eBay
      • Electronic Arts
      • Exelon
      • Facebook
      • Fastenal
      • Fiserv
      • Fox Corp
      • Fox Corp Class A
      • Gilead Sciences
      • IDEXX Labs
      • Illumina
      • Incyte
      • Intel
      • Intuit
      • Intuitive Surgical
      • JD.com
      • Keurig Dr Pepper
      • KLA
      • Kraft Heinz
      • Lam
      • Lululemon
      • Marriott
      • Marvell
      • Match Group
      • Maxim
      • MercadoLibre
  • Analytics
    • 0x Tracker
    • Amberdata
    • Apex Crypto
    • APY.Vision
    • ARTiFACTS
    • Beam Explorer
    • BitcoinWiki
    • Bitcompare
    • BitRank
    • CSPR Live
    • CryptoSlam
    • Crypto Wizards
    • DEXTools
    • Gray Wolf
    • Helium
    • Liquidtyfolio
    • LoanScan
    • Maker Governance Dashboard
    • NFT Stats
    • ParaSwap
    • Pools.fyi
    • QLUE
    • Quantify Crypto
    • Rome Terminal
    • Stablecoin Index
    • Token Terminal
    • TronScan
    • Uniswap
    • UniWhales
    • Unmarshal
    • Unmarshal Analytics
    • VeChain
    • Vetter
    • VFat
    • Xscan
  • W3 Metaverse
    • 5ire
    • Aavegotchi
    • ADADEMON
    • Adhara
    • Adshares
    • Aircoins
    • Alastria
    • Alien Worlds
    • Alpha Wallet
    • Arcona
    • Atari Token
    • Atato
    • Aurory
    • Aventus
    • Badger Finance
    • BambooDefi
    • Band Protocol
    • BELLYGOM
    • Bidao
    • Big Data Protocol
    • Bitlands
    • BitcoinCore
    • Blockapps
    • Blockchain For Social Impact
    • Blockchain Monster Hunt
    • Blockchain Research
    • BOSAGORA
    • BPS Financial
    • Brain Bot
    • British Blockchain Association
    • BULLY-VERSE
    • Butterfly
    • bZx
    • Carda Station
    • Cardano City
    • Cardano Village
    • Cardania
    • Chainlink Labs
    • Chromia
    • ClearMatrics
    • Cream Finance
    • CMT Digital
    • Codex
    • Couger
    • DEAPcoin
    • Decentral Games
    • Decentral Games ICE
    • DEEPSPACE
    • DIF
    • Dotmoovs
    • Dvision Network
    • Eco Island
    • Elemon
    • ELTCoin
    • Envision Blockchain Services
    • Etherisc
    • FaraLand
    • Fasset
    • Findora
    • Finso
    • Future Fest
    • GameFi
    • Gamestate
    • Heroes Chained
    • Inferno Red
    • Illuvium
    • inSure DeFi
    • Io builders
    • IOSG
    • Juggernaut
    • Kalao
    • Kaula
    • Kaulian
    • Legend of Fantasy War
    • LimeChain
    • LUKSO
    • MAGMA
    • Mandala
    • MATELAND
    • Metacade
    • Meta Bank Defi
    • Meta Mansions
    • MetaOneVerse
    • MILC Platform
    • Mines of Dalarnia
    • MOBOX
    • Monsta Infinite
    • MRHB
    • MyNeighborAlice
    • MySwarm
    • Near Names
    • Newscrypto
    • NexBloc
    • Onooks
    • Opium Insurance
    • Parsiq
    • Pavia
    • Perkins
    • Phantasma
    • Pinnacle
    • PlayDapp
    • Pocket Towne
    • Polychain Monsters
    • Polygon
    • Protocol Labs
    • Provable Things
    • Radio Caca
    • Reach Metaverse
    • Reedll
    • Render Token
    • Ren VM
    • Revolve Games
    • Revomon
    • Runtime Verification
    • Sablier
    • SafeMoon
    • SENSO
    • SigmaLedger
    • Sinverse
    • Sollensys
    • Solice
    • Somnium Space
    • Space Tokens
    • Spacetime Meta
    • Spheroid Universe
    • Stably
    • Starlink
    • Stratis
    • Sunterra
    • Symbiont
    • Tagprotocol
    • Theta Network
    • The Machine Consultancy
    • Token Factory
    • TOWER
    • Trade Log
    • UFO Gaming
    • Unbounded.Earth
    • Unibright
    • UniWhales
    • Valid Network
    • vBlocks
    • vEmpire
    • Venus
    • Verasity
    • Verse Estate
    • Victoria VR
    • Vitro
    • WAX
    • WBTC
    • Web3 Labs
    • WEMIX
    • WeTrust
    • Wilder World
    • Wizardia
    • Wownero
    • Xaya
    • Yield Guild
    • Zap
    • ZooKeeper
  • Protocol Registry
    • Algorand
      • Algodex
      • Octorand
      • Simplecoin
      • Tinyman
    • Avalanche
      • Aave
      • Alligator
      • Alps
      • Alter Go Punks
      • Any Civilization
      • Apingavax
      • Arable
      • Avaluan
      • Avax
      • avax3d
      • Avax Blobs
      • Avax Farmer
      • Avax guitars
      • AVAX Miners
      • Avax Monkeys
      • Avax Pool
      • Avax Punks
      • Avax Stacker
      • Avax Vault
      • Avaxtars
      • AXDAO
      • Baby Azuki Social Club
      • BENQI
      • Coconuts
      • Colony
      • Complus
      • Cooked Finance
      • Crabada
      • Cycle Finance
      • Flyrise
      • Gondola
      • Insta Dapp
      • Kaloo Finance
      • Lava Financial
      • Lydia
      • Maximus
      • Pangolin
      • Pizza Game
      • Plant a Tree
      • Platypus
      • Smartwin
      • Snocat
      • Snowball
      • Spore
      • Step.App
      • The AVAX-USDC Crops Farmer
      • Toasted AVAX
      • Vector Finance
      • Wheel of Return
      • Yak
      • Yeti Finance
    • BNB Chain
      • Aircash
      • Autoshark Finance
      • Aping Drip
      • Ape Swap
      • AngeLNodes
      • Anchor Swap
      • Ample Swap
      • Amnex
      • Alita
      • Acryptos
      • 9DNFT
      • BabySwap
      • Babylons
      • Baby Chick
      • Bake Pizza Miner
      • Baked Pizza
      • Bakery Swap
      • Banana Farm
      • Bee’n’Bee
      • Beef Swap
      • BinaryX
      • Biswap
      • Biswap Marketplace
      • BNB Cherries
      • BNB Park
      • BNB Seed
      • BNB Stake
      • Bomb Crypto
      • Bomb.Money
      • Bourbon Finance
      • BSC BNB Miner
      • Buffer Finance
      • Bungee Exchange
      • BUSD Miner
      • Bushdhoney
      • Cake of Fortune
      • Candle Genie Predictions
      • Cash Pirates
      • Chain Colosseum
      • Coffee Beans
      • Coin Printer
      • Corite
      • Coso Swap
      • Cowley Farm
      • CREAM
      • Crypto VHS
      • Cub Defi
      • Cube
      • Cyball
      • CZs Kitchen
      • DDDX
      • Deep Link
      • Defi Empire Games
      • Defi Temple
      • DEFI Warrior
      • DeHero
      • Dibs Money
      • Dinosaur Eggs
      • DNA X CAT
      • DogeBets
      • DracooMaster
      • DRIP
      • Drunk Robots
      • Elephant Money
      • ELFIN Kingdom
      • Elpis Battle
      • EMP
      • Faraland
      • Fire BUSD
      • Fistiana
      • Food Court
      • Forsage
      • Forth Box
      • FortPolis
      • Frost Flakes
      • Gold Grinder
      • Gold Grinder 2.0
      • Gravis Finance
      • Grinchbucks
      • Grove Token
      • GXG Coin
      • Happyland Finance
      • Hello Arena
      • Hero Cat
      • HyperJump
      • Idle Ninja Online
      • Infinity Crypto
      • Infinity Farms
      • Jade Protocol
      • Joe The Garden
      • Jul Swap
      • Kawaii Islands
      • Knight
      • Leounicorn Swap
      • Libero Financial
      • Liqiodifty
      • Lucky Chip
      • LZ Swap
      • Market Radio Casa
      • MDEX
      • Melos Studio
      • Metakeeper
      • Metamon
      • MetaRevo
      • Mines of Dalarnia
      • Minning Tycoon V2
      • Mobox
      • Money Minnows
      • Moon Pot
      • Movey
      • Mstation
      • Mintverse
      • My Defi Pet
      • Myfunding Network
      • MyRich Farm
      • NFTB
      • Ninneko
      • Niob Finance
      • Oceans Finance
      • Onyx Token
      • Pacoca
      • Pan Cake Bunny
      • Pancake Swap
      • Peace DAO
      • Pink Sale
      • Piston Token
      • Popcorn Cash
      • Position Exchange
      • QUK
      • Revault Network
      • Revault Network
      • Rothschild Winery BNB
      • Rug Zombie
      • Rune
      • Sea Scape
      • Second Live
      • Senspark
      • Solar Farm
      • SOLV Finance
      • Sport E
      • Star Mon
      • Step
      • The Crops Farmer
      • The Crypto You
      • Tiny World
      • Titan Hunters
      • Tomato Farm
      • Transit Swap
      • Turdburglar
      • Tuttu Frutti
      • USDT Miner
      • Venus
      • Vizsla Swap
      • Wanaka Farm
      • Warden
      • WazirX NFT
      • WidiLand
      • Win Per Minute Now
      • Zodium
    • Cardano
      • A SHIB
      • Aada
      • Acta Finance
      • ADAHEADZ
      • Adalantic
      • AdaMeds
      • ADANFT
      • ADAPunks
      • AdaQuest
      • AdaSwap
      • ADATools.io
      • Ardana
      • ArtGallery_AI
      • Astarter
      • Atomic Wallet
      • Baby Alien Club
      • Baby Dragon
      • Bidali
      • BingoToken
      • BISON COIN
      • Blockademia
      • Blockchain Samurai
      • Blockchaingames
      • Blockfrost
      • Cardacity
      • Cardance Swap
      • Cardano City
      • Cardano Dragonz
      • Cardano Kombat
      • Cardano Postal Service
      • CardanoKidz
      • Cardanomoon
      • CardanoPix
      • Cardashift
      • Cardoggo Token
      • Cardoonz
      • Catjam Token
      • CatKinson
      • Centaurify
      • ChaosColony
      • Clay Nation
      • CryptoRaggies
      • Cult of Pigeons
      • Daedalus Wallet
      • DB Studio
      • dcSpark
      • DEADPXLZ
      • Dracano
      • Empowa
      • Ergo
      • Flickto
      • Fort Gotten
      • Galactico
      • Genesis Auction House
      • Genius Petz
      • GOAT Tribe
      • H.Y.P.E
      • HashGuardians
      • Horrocubes
      • Hosky Inu
      • Inherited Plants
      • Jurassik Chained
      • Koios
      • LEAF Token
      • Lucid Dream
      • MAGIK RUNES
      • Maladex
      • Masked On Buttons
      • MechVerse
      • MetaDEX
      • Moonimals
      • MoonRock NFT
      • OccamX
      • OceanPals
      • OOZ1ES
      • Optim Finance
      • PIGY Token
      • Pixel Vampire Club
      • PlayerMint
      • PoolPerks
      • PoolTool
      • PumpkinCatz
      • PunkAss
      • Reach Metaverse
      • Ridotto
      • Rugg Project
      • Shibada Token
      • SingularityDAO
    • Cosmos
      • Agoric
      • Aleph.im
      • Althea
      • Anatha
      • Anchor Protocol
      • Ankr
      • Antlia
      • Archway
      • Artiqox
      • Astro Canvas
      • Band Chain
      • BEPSwap
      • BiDAO
      • BitCanna
      • BitSong
      • Blockchainhelppro
      • BTU
      • Bytom
      • Bytom
      • Foundation
      • Cardchain
      • Carnot
      • Centaur
      • CHAI
      • Chainpoint
      • CodeChain
      • CoinSwap
      • Commercio Network
      • Cosmos Hub
      • Cyber
      • Datopia
      • Dawn
      • Decentr
      • DecentRandom
      • Demex
      • Desmos Network
      • Dfinance
      • Didcomauth
      • DREP Chain
      • Dulce + Allies
      • Eco
      • Electron
      • Epc Chain
      • Ercoin
      • Fetch AI
      • FirmaChain
      • FOAM
      • Gallactic
      • Gravity Bridge
      • Gravity Dex
      • Hash Gaurd
      • Ho Chain (the Force Chain)
      • HoneyWood
      • IDEP Network
      • Impact Data Consortium Chain
      • Injective Protocol
      • Internet of Impact
      • IRIS Hub
      • Juno
      • Kira Interchain Exchange
      • Konstellation
      • Kosu
      • Kvartalo Chain
      • Lambda
      • LCNEM
      • Left Gallery Registry
      • MakeOS
      • Maxon Row
      • Medibloc
      • MEDIBLOCK
      • Minter
      • Mir
      • MMX
      • Mooncake
      • NDAU
      • Noah City
      • NOMIC
      • Nym Protocol
      • OmniFlix Network
      • OneLedger
      • Onomy
      • Oraichain
      • Osmosis
      • Ourboros
      • Penumbra
      • Pocket Network
      • Polygon (Prev. Matic)
      • Pylons
      • Qredo
      • QuarkChain
      • Ren Protocol
      • Rizon
      • Saturn Money
      • Scynet
      • Secret Finance
      • Secret Network (prev. Enigma)
      • Shentu Chain
      • Sifchain
      • SmartPesa
      • Sommelier Finance
      • Sputnik Network
      • Starname (iov)
      • Stateset
      • Supernova
      • Tgrade
      • THORChain
      • Twilight
      • U Network
      • Unification WRK Oracle
      • WenChang
      • WeTrust
      • Xar Network
      • Zefi
    • Dfinity
      • Aedile
      • Agryo
      • Axon
      • crowdEats
      • Dank
      • DECKDECKGO
      • Entrepot
      • EVM On ICP
      • Fleek
      • ICKitties NFTs
      • ICNaming
      • ICMoji Origins
      • ICP Explorer
      • ICP Squad NFT
      • ICPSwap
      • ICPunks
      • ICSnakes
      • InfinitySwap
      • Lo-Fi Player
      • MetaSports Basketball
      • Mission is Possible
      • Motoko Playground
      • NFT Studio
      • Origyn
      • Osmosis
      • Plug
      • PokedStudio Bots
      • Rise of the Magni
      • Saga Taro
      • SLY
      • Sonic
      • Stoic Wallet
      • Sudograph
      • Terabethia
      • The Internet Computer Association
      • The Wall
      • Toniq Labs
      • Uniswap front end hosted
      • Wild and West NFTs
    • Elrond
      • Aerovek
      • Age of Zalmoxis
      • Angry Bears Club
      • Angry Penguins
      • Apes Launchpad
      • Aquaverse
      • Arda Run
      • Ascensive Assets
      • AshSwap
      • Beskar Dao
      • BH Network
      • BHero
      • Blok
      • BunnyVerse
      • Cantina Royale
      • Captain Planet
      • Carpathian Stake
      • Cats Mafia
      • CheckerChain
      • CLUB GORGON
      • Cybers In Action
      • Dead Rare
      • Dice
      • Disruptive Digital
      • Dragons Arena
      • DRIFTERS
      • E-Compass
      • eGold Jobs
      • Eldar
      • Elrond 2038
      • Elrond Apes
      • Elrond Bunny
      • Elrond Castle
      • Elrond Coin Flip
      • Elrond Gallery
      • Elrond Giants
      • Elrond Index
      • Elrond Lions Club
      • Elrond Mobsters
      • Elrond Monitor
      • Elrond NFT Swap
      • Elrond Punks
      • Elrond Scan
      • Elrond Voice
      • Elrond Warriorz
      • Elrond Wiki
      • ElrondCity
      • ElrondPartners
      • Elven Tools
      • Eneftor
      • ENFT DAO
      • Entity
      • Erd Nft
      • Erd360
      • ESDT Market
      • Frame It
      • Gaupa Labs
      • Helios Staking
      • High Street Wolf
      • HODLcards
      • Isengard Market
      • Istari Vision
      • J-Corp | Battle of Gods
      • JEXchange
      • Kahunuts
      • Krogan
      • Krogan Launchpad
      • Lightning Bolts
      • Lkmex Bet
      • LockedMEX
      • MADZ Alpacas
      • Maiar
      • Maiar Kart Racing
      • Maiar Launchpad
      • Mechanism Capital
      • MGStaking
      • Mice City Club
      • Middle Staking
      • Middleman.nft
      • Moon Mission
      • MyERD
      • Natural Born Degenz
      • Nifty Rex
      • Nuts Token
      • Odin DeFi Protocol
      • Omniscient Tools
      • Partner Staking
      • Pawn Whale
      • Plata Network
      • Prize-me
      • Proteo
      • QoWatt
      • Rariry Market
      • Realm of Karitha
      • RisaSoft
      • RosettaStake
      • Salvadorian Ape Club
      • Smart Chain Connection
      • Space Robots
      • Spark Digital Capital
      • Staking Agency
      • Stramosi
      • Subcarpati OG
      • Super Rare Bears
      • Superciety
      • Trust Staking
      • Tigers On Chain
      • The Palm Tree Network
      • The Faceless Many
      • The Art Coiner
      • Symbiosis
      • Vital Network
      • Validators
      • World Wide Wine
      • Woodstock
      • Whaley
      • Web3Pirates
      • WalletFP
      • XOXNO
      • ZoidPay
    • EoS
      • 0x Racers
      • Alcor
      • Atomic Assets
      • Atomic Market
      • Bank of Staked
      • Bapbet
      • BBS Market
      • BC Games
      • Bet Spider
      • BetHash
      • Candy Popduel
      • CETF
      • Chainzarena
      • CrossWorlds
      • Crypto Dynasty
      • Log out
      • Defi Box
      • Dolphin Swap
      • EOS Games
      • EOS Royale
      • Equilibrium
      • Evodex
      • Gen Pool
      • New Dex
      • Pizza
      • SportBet
      • Vigor
    • Hedera
      • DOVU
      • Hash Axis
      • Hashpack
      • Justpayme
      • Stader
    • IoTex
      • BurnDrop
      • Crypto Farmer
      • Cyclone
      • Hemes
      • IoTex Galaxy
      • IoTex Punks
      • IoTex Shiba
      • IoTube
      • Magic Land
      • Mimo Exchange
      • Mimo Swap
      • Multi Sender
      • Parrot Defi
      • Pixie Soccer
      • Sumotex
      • Swagull Finance
      • Treasureland
      • Unifi Protocol
      • Wow Swap
      • Zoom Swap
    • Polygon
      • 0x Universe
      • Ankr
      • AP Wine
      • Arche Network
      • Art.army
      • Artvatars
      • BattleVerse
      • Biconomy
      • BitQuery
      • Blockchain Game Alliance
      • Blocks United
      • Boring DAO
      • BTU Protocol
      • Cashaa
      • CatJumping
      • Cipher Masters
      • Coin League
      • Commitpool
      • Creaton
      • Cryptopunt
      • Definer
      • Dexkit
      • DSCVR.Finance
      • Emiswap
      • Entropyart AI
      • EthaLend
      • Everest
      • First One
      • Fully Rekt
      • ibetyou
      • IDEX
      • InstaDapp
      • Inverse Finance
      • Kattana
      • Kuku Token
      • Marginswap
      • Math Wallet
      • Meme
      • Metapass
      • Mobius Finance
      • Moonwolf
      • Mywish
      • Neon District
      • NFT Hub
      • NiftyGram
      • Noname DAO
      • Openlake
      • Polydefy
      • ProtonGaming
      • Potato Media
      • Polyquity
      • Qwala
      • Quadrant
      • Risk Harbor
      • Ricochet
      • Realm
      • Raze Network
      • Straming Fast
      • Straightfire
      • Standard Protocol
      • Solo Top
      • Satoshi City
      • Sakura Casino
      • Synergy of Serra
      • Swirge
      • Sushi Swap
      • USD Coin
      • Unreal Finance
      • Unilend
      • Vulcan Verse
      • Vodra
      • Verox
      • WildCards
      • Whale Street
      • Waypoint
      • Yin Finance
    • Ripple
      • 2sync
      • Alphacat
      • Arrington Capital
      • AsiaMTM Group
      • Atomic Wallet
      • B1X
      • Beachhead
      • Beeders
      • Bichip
      • BitPanda
      • Bitso
      • BitStickers
      • Bitvolo
      • BookcoinShop
      • Bronn Travel
      • Bullion79
      • Catalyst Corporate
      • CenterServ
      • Cinnamon
      • Codius
      • CoinJar
      • Coolwallet
      • Creative Click
      • Crypto Coffee
      • Crypto Whale Clothing
      • Cryptojaunt
      • Cuallix (ODL)
    • Solana
      • 01 Decentralized
      • Apricot Finance
      • Audius
      • CropperFinance
      • Dexlab
      • Francium
      • Grape Protocol
      • Holaplex
      • Jet Protocol
      • Lumos Exchange
      • Magic Eden
      • Mango
      • Metaplex
      • Orca
      • Port Finance
      • Raydium
      • Squads
      • Solsea
      • Solend
      • Solanart
      • Solanalysis
      • Serum
      • Saber
      • Tulip Protocol
      • Velas
    • Stellar
      • Anchor MXN
      • Anchor USD
      • Answap
      • ARF
      • Armenotech
      • BitGo
      • BitSo
      • Block Time
      • Blockdemon
      • Circle
      • Clic
      • Click Pesa
      • Community Fund
      • Dinaro
      • Dtransfer
      • Firefly
      • Franklin Templeton
      • Interstellar
      • Kunst21
      • Ledger
      • Ledgerads
      • Lightnet
      • Lockerx
      • Mintx
      • Mobie
      • Moneyclick
      • Moneygram
      • Mozart
      • Mvpworks
      • Nicetrade
      • Nodle
      • Ownbit
      • Pago Biccos
      • Paymnt
      • Payscript
      • Rehive
      • Revelry
      • Ripple Fox
      • SatoshiPay
      • Securrency
      • Settle
      • SHARIYAH REVIEW BUREAU
      • Simba
      • Socuply
      • Solarwallet
      • Stablex
      • Stably
      • Stellar Expert
      • Suitebox
      • Synced
      • Tala
      • Tamil Token
      • Task
      • Vonder Heydt
      • Wyre
      • Zagg network
    • Tezos
      • Archetype
      • Bakebuddy
      • Bazaar
      • Beacon
      • Better Call Dev
      • Byteblock NFT
      • CCP Games
      • Chinstrap
      • Crunchy
      • CTez
      • DNS.xyz
      • Electis
      • Emergents
      • FlameDefi
      • FXHash
      • Gap Threads
      • Gravity
      • HENTO
      • InterPop
      • Juster
      • Kalamint
      • Kiln
      • LigoLang
      • Liquidity Baking
      • Lugh
      • MatterDeFi
      • Mavyrk
      • My Tezos Defi
      • Objkt
      • OneOf
      • PixelPotus
      • Play with BRIO
      • Plenty
      • Quipuswap
      • Rarible
      • Rocket Launchpad
      • Smartlink
      • SmartPy
      • SpicySwap
      • Stakenow
      • Taquito
      • TezBlock
      • TezID
      • Tezos Snapshots
      • Tezotopia
      • Teztnets
      • TZColors
      • TzFlow
      • Ubisoft Quartz
      • USDS
      • USDTZ
      • VerticalCrypto Art
      • WRAP
      • XP.NETWORK
      • Youves
    • Tron
      • 0x Warriors
      • 0xRacers
      • 4Freedom
      • 888starz
      • Alpha Tron
      • Bananacoin
      • BSG
      • Chain Zarena
      • Crycade
      • Cukies
      • Devikins
      • Exon
      • Frag Token
      • GalaxyOnline
      • HodlST
      • Intercrone Swap
      • Just Lend
      • Just Money
      • Kraftly
      • Luminous
      • MrWebfinance
      • Oikos
      • Social Swap
      • Starway
      • Sunswap
      • T2X
      • TBlocksW
      • Tofu Swap
      • Transit Finance
      • Tron Bulk Sender
      • Tron Bull Club
      • Tron Holders
      • Tron Prime
      • TronFarmers
      • TronSweep
      • Trunswap
      • Unifi Protocol
      • Unswap
      • Void Swap
      • Zethyr
      • Zethyr Finance
    • XDC
      • Comtech Gold
      • DATACHAIN
      • Globiance Exchange
      • LedgerMail
      • NOTA
      • Plugin
      • StorX
      • XSwap Protocol (XSP)
  • Zephyrnet
  • AmpliFi PR
  • Plato Support
  • Terms of Use
  • Privacy Policy
  • Cookies Policy
  • DMCA Notice
  • GDPR
S3 Ep124: When so-called security apps go rogue [Audio + Text]
Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

Cyber SecurityTime Stamp: March 2, 2023 10:40 AM
Source Node: 1988654
Republished By Plato

Republished By Plato

Followers: 0
by Paul Ducklin

A ROGUES’ GALLERY

Rogue software packages. Rogue “sysadmins”. Rogue keyloggers. Rogue authenticators.

No audio player below? Listen directly on Soundcloud.

With Doug Aamoth and Paul Ducklin. Intro and outro music by Edith Mudge.

You can listen to us on Soundcloud, Apple Podcasts, Google Podcasts, Spotify, Stitcher and anywhere that good podcasts are found. Or just drop the URL of our RSS feed into your favourite podcatcher.


READ THE TRANSCRIPT

DOUG.  Scambaiting, rogue 2FA apps, and we haven’t heard the last of LastPass.

All that, and more, on the Naked Security podcast.

[MUSICAL MODEM]

Welcome to the podcast, everybody.

I am Doug Aamoth; he is Paul Ducklin.

Paul, how do you do today?


DUCK.  Chilly, Doug.

Apparently, March is going to to be colder than February.


DOUG.  We are having the same problem here, the same challenge.

So, fret not – I have a very interesting This Week in Tech History segment.

This week, on 05 March 1975, the first gathering of the Homebrew Computer Club took place in Menlo Park, California, hosted by Fred Moore and Gordon French.

The first meeting saw around 30 technology enthusiasts discussing, among other things, the Altair.

And about a year later, on 01 March 1976, Steve Wozniak showed up to a meeting with a circuit board he created, aiming to give away the plans.

Steve Jobs talked him out of it, and the two went on to start Apple.

And the rest is history, Paul.


DUCK.  Well, it certainly is history, Doug!

Altair, eh?

Wow!

The computer that persuaded Bill Gates to drop out of Harvard.

And in true entrepreneurial fashion, together with Paul Allen and Monty Davidoff – I think that was the trio who wrote the Altair Basic – decamped to New Mexico.

Go and work at the hardware vendor’s property in Albuquerque!


DOUG.  Perhaps something that’s maybe not going to make history…

…we’ll start the show off with an unsophisticated yet interesting scambaiting campaign, Paul.

NPM JavaScript packages abused to create scambait links in bulk


DUCK.  Yes, I wrote this up on Naked Security, Doug, under the headline NPM JavaScript packages abused to create scambait links in bulk (it’s a lot wordier to say than it seemed at the time when I wrote it)…

…because I felt it was an interesting angle on the sort of web property that we tend to associate directly, and only, with so-called supply-chain source code attacks.

And in this case, the crooks figured, “Hey, we don’t want to distribute poisoned source code. We’re not into that kind of supply-chain attack. What we’re looking for is just a series of links that people can click on that won’t arouse any suspicions.”

So, if you want a Web page that someone can visit that has a load of links to dodgy sites… like “Get your free Amazon bonus codes here” and “Get your free bingo spins” – there were literally tens of thousands of these…

…why not choose a site like the NPM Package Manager, and create a whole load of packages?

Then you don’t even need to learn HTML, Doug!

You could just use good old Markdown, and there you’ve got essentially a good-looking, trusted source of links you can click through to.

And those links that they were using, as far as I can make out, went off to essentially unsuspicious blog sites, community sites, whatever, that had unmoderated or poorly moderated comments, or where they were easily able to create accounts and then make comments that had links in.

So they’re basically building a chain of links that wouldn’t arouse suspicion.


DOUG.  So, we have some advice: Don’t click freebie links, even if you find you are interested or intrigued.


DUCK.  That’s my advice, Doug.

Maybe there are some free codes, or maybe there’s some coupon stuff that I could get… maybe there’s no harm in having a look.

But if there’s some kind of affiliated ad revenue with that, that the cooks are making just by enticing you bogusly to a particular site?

No matter how minuscule the amount is that they’re making, why give them anything for nothing?

That’s my advice.

“Best way to avoid punch is no be there,” as always.


DOUG.  [LAUGHS] And then we have: Don’t fill in online surveys, no matter how harmless they seem.


DUCK.  Yes, we’ve said that many times on Naked Security.

For all you know, you might be giving your name here, your phone number there, you maybe give your date of birth to something for a free gift there, and you think, “What’s the harm?”

But if all that information is actually ending up in one giant bucket, then, over time, the crooks are just getting more and more about you, sometimes perhaps including data that it’s very difficult to change.

You can get a new credit card tomorrow, but it’s rather harder to get a new birthday or to move house!


DOUG.  And last, but certainly not least: Don’t run blogs or community sites that allow unmoderated posts or comments.

And if anyone’s ever run, say, a WordPress site, the thought of allowing unmoderated comments is just short of mind-blowing, because there will be thousands of them.

It is an epidemic.


DUCK.  Even if you’ve got an automated anti-spamming service on your comment system, that will do a great job…

…but don’t let the other stuff through and think, “Oh, well, I’ll go back and remove it, if I see that it looks dodgy afterwards,” because, like you said, it’s at epidemic proportions…


DOUG.  That’s a full time job, yes!


DUCK.  …and has been for ages.


DOUG.  And you were able, I’m delighted to see, to work in two of our favourite mantras around here.

At the end of the article: Think before you click, and: If in doubt…


DUCK.  …don’t give it out.

It really is as simple as that.


DOUG.  Speaking of giving things out, three youngsters allegedly made off with millions in extortion money:

Dutch police arrest three cyberextortion suspects who allegedly earned millions


DUCK.  Yes.

They were busted in the Netherlands for crimes that they are alleged to have started committing… I think it’s two years ago, Doug.

And they are 18 years, 21 years, and 21 years old now.

So they were pretty young when they started.

And the prime suspect, who is 21 years old… the cops allege he has made about two-and-a-half-million Euros.

That is a lot of money for a youngster, Doug.

It’s a lot of money for anybody!


DOUG.  I don’t know what you were making at 21, but I was not making that much, not even close. [LAUGHS]


DUCK.  Maybe two Euros fifty an hour? [LAUGHTER]

It seems that their modus operandi was not to end up with ransomware, but to leave you with the *threat* of ransomware because they were already in.

So they’d come in, they’d do all the data theft, and then instead of actually bothering to encrypt your files, it sounds as though what they’d do is they’d say, “Look, we’ve got the data; we can come back and ruin everything, or you can pay.”

And the demands were somewhere between €100,000 and €700,000 per victim.

And if it’s true that one of them made €2,500,000 in the past two years out of his cybercriminality, you can imagine that they probably blackmailed quite a few victims into paying up, for fear of what might get revealed…


DOUG.  We’ve said around here, “We’re not going to judge, but we urge people not to pay up in instances like this, or in instances like ransomware.”

And for good reason!

Because, in this case, the police note that paying the blackmail didn’t always work out.

They said:

In many cases, stolen data was leaked online even after the affected companies had paid up.


DUCK.  So. if you ever thought, “I wonder if I can trust those guys not to leak the data, or for it not to appear online?”…

…I think you’ve got your answer there!

And bear in mind that it may not be that these particular crooks were just ultra-duplicitous, and that they took the money and leaked it anyway.

We don’t know that *they* were necessarily the people who leaked it.

They could have just been so bad at security themselves that they stole it; they had to put it somewhere; and while they were negotiating, telling you, “We’ll delete the data”…

…for all we know, someone else could have stolen it in the meantime.

And that’s always a risk, so paying for silence rarely works out well.


DOUG.  And we’ve seen more and more attacks like this where ransomware actually looks a little bit more straightforward: “Pay me for the decryption key; you pay me; I’ll give it to you; you can unlock your files.”

Well, now they’re going in and saying, “We’re not going to lock anything up, or we’re going to lock it up but we’re also going to leak it online if you don’t pay…”


DUCK.  Yes, it’s three sorts of extortion, isn’t it?

There’s, “We locked up your files, pay the money or your business will stay derailed.”

There’s, “We stole your files. Pay up or we’ll leak them, and then we might come back and ransomware you anyway.”

And there’s the double-ground that some crooks seem to like, where they steal your data *and* they scramble the files, and they say, “You might as well pay up to decrypt your files, and no extra charge, Doug, we’ll delete the data as well!”

So, can you trust them?

Well, here’s your answer…

Probably not!


DOUG.  All right, head over and read about that.

There’s further insight and context at the bottom of that article… Paul, you did an interview with our own Peter Mackenzie, who is the Director of Incident Response here at Sophos. (Full transcript available.)

No audio player below? Listen directly on Soundcloud.

And, as we always say in cases like these, if you’re affected by this, report the activity to the police so that they have as much information as they can get in order to put their case together.

I’m happy to report that we said we’d keep an eye on it; we did; and we’ve got a LastPass update:

LastPass: Keylogger on home PC led to cracked corporate password vault


DUCK.  We have indeed, Doug!

This is indicating how the breach of their corporate passwords allowed the attack to go from being a “little thing” where they got source code to something rather more dramatic.

LastPass seem to have figured out how that actually happened… and in this report, there are effectively, if not words of wisdom, at least words of warning.

And I did repeat, in the article I wrote about this, what we said on last week’s podcast promo video, Doug, namely:

“As simple as the attack was, it would be a bold company that would claim that not one of their users, ever, would fall for this kind of thing…”

Listen now – Learn more!https://t.co/CdZpuDSW2f pic.twitter.com/0DFb4wALhi

— Naked Security (@NakedSecurity) February 24, 2023

Sadly, it seems that one of the developers, who just happened to have the password to unlock the corporate password vault, was running some kind of media-related software that they hadn’t patched.

And the crooks were able to use an exploit against it… to install a keylogger, Doug!

From which, of course, they got that super-secret password that opened the next stage of the equation.

If you’ve ever heard the term lateral movement – that’s a Jargon term you’ll hear a lot.

The analogy you have with conventional criminality is…

..get into the lobby of the building; hang around a little bit; then sneak into a corner of the security office; wait in the shadows so nobody sees you until the guards go and make a cup of tea; then go to the shelf next to the desk and grab one of those access cards; that gets you into the secure area next to the bathroom; and in there, you’ll find the key to the safe.

You see how far you can get, and then you work out probably what you need, or what you’ll do, to get you the next step, and so on.

Beware the keylogger, Doug! [LAUGHS]


DOUG.  Yes!


DUCK.  Good, old-school, non-ransomware malware is [A] alive and well, and [B] can be just as harmful to your business.


DOUG.  Yes!

And we’ve got some advice, of course.

Patch early, patch often, and patch everywhere.


DUCK.  Yes.

LastPass were very polite, and they didn’t blurt out, “It was XYZ software that had the vulnerability.”

If they’d said, “Oh, the software that was hacked was X”…

…then people who didn’t have X would go, “I can stand down from blue alert; I don’t use that software.”

In fact, that’s why we say not just patch early, patch often… but patch *everywhere*.

Just patching the software that affected LastPass is not going to be enough in your network.

It does need to be something you do all the time.


DOUG.  And then we’ve said this before, and we’ll continue to say it until the sun burns out: Enable 2FA wherever you can.


DUCK.  Yes.

It is *not* a panacea, but at least it means that passwords alone are not enough.

So it doesn’t raise the bar all the way, but it definitely doesn’t make it easier for the crooks.


DOUG.  And I believe we’ve said this recently: Don’t wait to change credentials or reset 2FA seeds after a successful attack.


DUCK.  As we’ve said before, a rule that says, “You have to change your password – change for change’s sake, do it every two months regardless”…

…we don’t agree with that.

We just think that is getting everybody into the habit of a bad habit.

But if you think there might be a good reason to change your passwords, even though it’s a real pain in the neck to do it…

…if you think it might help, why not just do it anyway?

If you’ve got a reason to start the change process, then just go through with the whole thing.

Don’t delay/Do it today.

[QUIETLY] See what I did there, Doug?


DOUG.  Perfect!

Alright, let’s stay on the subject of 2FA.

We are seeing a spike in rogue 2FA apps in both app stores.

Could this be because of the Twitter 2FA kerfuffle, or some other reason?

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!


DUCK.  I don’t know that it’s specifically due to the Twitter 2FA kerfuffle, where Twitter have said, for whatever reasons they have, “Ooh, we’re not going to use SMS two-factor authentication anymore, unless you pay us money.!

And since the majority of people aren’t going to be Twitter Blue badge holders, they’re going to have to switch.

So I don’t know that that’s caused a surge in rogue apps in App Store and Google Play, but it certainly drew the attention of some researchers who are good friends to Naked Security: @mysk_co, if you want to find them on Twitter.

They thought, “I bet lots of people are actually looking for 2FA authenticator apps right now. I wonder what happens if you go to the App Store or Google Play and just type in Authenticator app?”

And if you go to the article on Naked Security, entitled “Beware rogue 2FA apps”, you will see a screenshot that those researchers prepared.

It’s just row after row after row of identically-looking authenticators. [LAUGHS]


DOUG.  [LAUGHS] They’re all called Authenticator, all with a lock and a shield!


DUCK.  Some of them are legit, and some of them aren’t.

Annoyingly. When I went – even after this had got into the news… when I went to the App Store, the top app that came up was, as far as I could see, one of these rogue apps.

And I was really surprised!

I thought, “Crikey – this app is signed in the name of a very well known Chinese mobile phone company.”

Luckily, the app looked rather unprofessional (the wording was very bad), so I didn’t for a moment believe that it really was this mobile phone company.

But I thought, “How on earth did they manage to get a code-signing certificate in the name of a legitimate company, when clearly they wouldn’t have had any documentation to prove that they were that company?” (I won’t mention its name.)

Then I read the name really carefully… and it was, in fact, a typosquat, Doug!

One of the letters in the middle of the word had, how can I say, a very similar shape and size to the one belonging to the real company.

And so, presumably, it had therefore passed automated tests.

It didn’t match any known brand name that somebody already had a code signing certificate for.

And even I had to read it twice… even though I knew that I was looking at a rogue app, because I’d been told to go there!

On Google Play, I also came across an app that I was alerted to by the chaps who did this research…

…which is one that doesn’t just ask you to pay $40 a year for something you could get for free built into iOS, or directly from Play Store with Google’s name on it for free.

It also stole the starting seeds for your 2FA accounts, and uploaded them to the developer’s analytics account.

How about that, Doug?

So that’s at best extreme incompetence.

And, at worst, it’s just outright malevolent.

And yet, there it was… top result when the researchers went looking in the Play Store, presumably because they splashed a little bit of ad love on it.

Remember, if someone gets that starting seed, that magic thing that’s in the QR code when you set up app-based 2FA…

…they can generate the right code for you, for any 30-second login window in the future, forever and ever, Doug.

It’s as simple as that.

That shared secret is *literally* the key to all your future one-time codes.


DOUG.  And we’ve got a reader comment on this rogue 2FA story.

Naked Security reader LR comments, in part:

I dumped Twitter and Facebook ages ago.

Since I am not using them, do I need to be concerned about the two-factor situation?


DUCK.  Yes, that’s an intriguing question, and the answer is, as usual, “It depends.”

Certainly if you’re not using Twitter, you could still choose badly when it comes to installing a 2FA app…

…and you might be more inclined to go and get one, now 2FA has been in the news because of the Twitter story, than you would have weeks, months, or years ago.

And if you *are* going to go and opt for 2FA, just make sure you do it as safely as you can.

Don’t just go and search, and download what seems like the most obvious app, because here is strong evidence that you could put yourself very much in harm’s way.

Even if you’re on the App Store or on Google Play, and not sideloading some made-up app that you got from somewhere else!

So, if you are using SMS-based 2FA but you don’t have Twitter, then you don’t need to switch away from it.

If you choose to do so, however, make sure you pick your app wisely.


DOUG.  Alright, great advice, and thank you very much, LR, for sending that in.

If you have an interesting story, comment or question you’d like to submit, we’d love to read it on the podcast.

You can email tips@sophos.com, you can kind comment on any one of our articles, or you can hit us up on social: @nakedsecurity.

That’s our show for today – thanks very much for listening.

For Paul Ducklin, I’m Doug Aamoth, reminding you until next time to…


BOTH.  Stay secure!

[MUSICAL MODEM]


  • SEO Powered Content & PR Distribution. Get Amplified Today.
  • Platoblockchain. Web3 Metaverse Intelligence. Knowledge Amplified. Access Here.
  • Source: https://nakedsecurity.sophos.com/2023/03/02/s3-ep124-when-so-called-security-apps-go-rogue-audio-text/

Time Stamp: March 2, 2023

  • 000
  • 2FA
  • a
  • Able
  • About
  • access
  • Account
  • Accounts
  • across
  • activity
  • actually
  • Ad
  • advice
  • Affiliated
  • After
  • against
  • Ages
  • Aiming
  • Alert
  • All
  • alleged
  • allegedly
  • Allowing
  • alone
  • already
  • Alright
  • always
  • Amazon
  • among
  • amount
  • analytics
  • and
  • answer
  • anywhere
  • app
  • app store
  • app stores
  • appear
  • Apple
  • apps
  • AREA
  • around
  • arrest
  • article
  • articles
  • Associate
  • attack
  • Attacks
  • attention
  • audio
  • Authentication
  • author
  • Automated
  • available
  • avoid
  • back
  • Bad
  • badly
  • bar
  • basic
  • Basically
  • Bear
  • because
  • before
  • being
  • believe
  • below
  • BEST
  • Bet
  • between
  • Bill
  • Bill Gates
  • bingo
  • birth
  • Bit
  • Blackmail
  • Blog
  • blogs
  • Blue
  • blue badge
  • board
  • bold
  • Bonus
  • Bottom
  • brand
  • breach
  • Building
  • built
  • business
  • california
  • called
  • Campaign
  • Can Get
  • card
  • Cards
  • case
  • cases
  • caused
  • certainly
  • certificate
  • chain
  • challenge
  • change
  • charge
  • chinese
  • Choose
  • claim
  • clearly
  • Close
  • club
  • code
  • Codes
  • COM
  • come
  • comment
  • comments
  • community
  • Companies
  • company
  • computer
  • concerned
  • context
  • continue
  • conventional
  • cops
  • Corner
  • Corporate
  • could
  • coupon
  • course
  • cracked
  • create
  • created
  • Credentials
  • credit
  • credit card
  • Crimes
  • Crooks
  • Cup
  • cyberextortion
  • data
  • Date
  • Decrypt
  • definitely
  • delighted
  • demands
  • depends
  • developers
  • DID
  • difficult
  • directly
  • Director
  • discussing
  • distribute
  • documentation
  • Doesn’t
  • Dont
  • down
  • download
  • dramatic
  • Drop
  • Early
  • earned
  • earth
  • easier
  • easily
  • effectively
  • email
  • enough
  • enthusiasts
  • entrepreneurial
  • Epidemic
  • essentially
  • Euros
  • Even
  • EVER
  • Every
  • everything
  • evidence
  • Exploit
  • extortion
  • extra
  • extreme
  • eye
  • Facebook
  • Fall
  • far
  • Fashion
  • fear
  • February
  • few
  • figured
  • Files
  • fill
  • Find
  • First
  • forever
  • found
  • Free
  • French
  • friends
  • from
  • full
  • further
  • future
  • Gates
  • gathering
  • generate
  • get
  • getting
  • giant
  • gift
  • Give
  • Giving
  • Go
  • going
  • good
  • Google
  • Google Play
  • Google’s
  • grab
  • great
  • hacked
  • Hang
  • happened
  • happens
  • happy
  • Hardware
  • harmful
  • harvard
  • having
  • head
  • headline
  • hear
  • heard
  • help
  • here
  • history
  • Hit
  • holders
  • Home
  • hosted
  • How
  • However
  • HTML
  • HTTPS
  • I’LL
  • in
  • incident
  • incident response
  • Inclined
  • Including
  • incompetence
  • information
  • insight
  • install
  • installing
  • instead
  • interested
  • interesting
  • iOS
  • IT
  • jargon
  • JavaScript
  • Job
  • Jobs
  • judge
  • Keep
  • Key
  • Kind
  • Know
  • known
  • Last
  • LastPass
  • leak
  • LEARN
  • Leave
  • Led
  • Legit
  • links
  • Listening
  • little
  • load
  • Lobby
  • locked
  • Look
  • looked
  • looking
  • LOOKS
  • Lot
  • love
  • made
  • magic
  • Majority
  • make
  • Making
  • malware
  • manage
  • manager
  • many
  • March
  • Match
  • Matter
  • means
  • meantime
  • meeting
  • Mexico
  • Middle
  • might
  • mind
  • Mobile
  • mobile phone
  • Modus
  • moment
  • money
  • months
  • more
  • most
  • move
  • Music
  • musical
  • Naked Security
  • Naked Security Podcast
  • name
  • namely
  • necessarily
  • Need
  • Netherlands
  • network
  • New
  • news
  • next
  • number
  • obvious
  • Office
  • Old
  • ONE
  • online
  • opened
  • order
  • Other
  • own
  • package
  • packages
  • paid
  • Pain
  • panacea
  • Park
  • part
  • particular
  • passed
  • Password
  • Passwords
  • past
  • Patch
  • Patching
  • Paul
  • Pay
  • paying
  • PC
  • People
  • perhaps
  • persuaded
  • Peter
  • phone
  • pick
  • Place
  • plans
  • plato
  • Plato Data Intelligence
  • PlatoData
  • Play
  • Play Store
  • player
  • podcast
  • Podcasts
  • Police
  • Posts
  • prepared
  • pretty
  • Prime
  • probably
  • Problem
  • process
  • property
  • Prove
  • punch
  • put
  • QR code
  • question
  • quietly
  • raise
  • ransomware
  • Read
  • Reader
  • real
  • reason
  • reasons
  • recently
  • remove
  • repeat
  • report
  • researchers
  • response
  • REST
  • result
  • revenue
  • Risk
  • ROW
  • rss
  • ruin
  • Rule
  • Run
  • running
  • safe
  • safely
  • Said
  • sake
  • same
  • says
  • Search
  • Secret
  • secure
  • security
  • seed
  • seeds
  • seeing
  • seemed
  • seems
  • sees
  • segment
  • sending
  • Series
  • service
  • set
  • Shape
  • shared
  • Shelf
  • Short
  • show
  • sideloading
  • signed
  • signing
  • Silence
  • similar
  • Simple
  • since
  • site
  • Sites
  • situation
  • Size
  • SMS
  • sneak
  • So
  • Social
  • Software
  • some
  • Someone
  • something
  • somewhere
  • Source
  • source code
  • speaking
  • specifically
  • spike
  • Spotify
  • Stage
  • stand
  • start
  • started
  • Starting
  • stay
  • Step
  • Steve
  • Steve Wozniak
  • Still
  • stole
  • stolen
  • store
  • stores
  • Story
  • straightforward
  • strong
  • submit
  • successful
  • Sun
  • surge
  • Switch
  • system
  • Tea
  • tech
  • Technology
  • tests
  • The
  • The Future
  • the Netherlands
  • theft
  • their
  • themselves
  • therefore
  • thing
  • things
  • Think
  • thought
  • thousands
  • three
  • Through
  • time
  • times
  • to
  • today
  • together
  • tomorrow
  • top
  • true
  • Trust
  • trusted
  • twitter
  • under
  • unlock
  • uploaded
  • URL
  • us
  • use
  • users
  • Vault
  • Victim
  • victims
  • Video
  • vulnerability
  • wait
  • warning
  • web
  • week
  • Weeks
  • What
  • which
  • while
  • WHO
  • will
  • wisdom
  • Word
  • wording
  • WordPress
  • words
  • Work
  • work out
  • works
  • Worst
  • would
  • X
  • year
  • years
  • young
  • Your
  • yourself
  • zephyrnet

More from Naked Security

Mystery iPhone update patches against iOS 16 mail crash-attack

Source Cluster:
Naked Security
Source Node: 1721431
Time Stamp: Oct 10, 2022
GoDaddy admits: Crooks hit us with malware, poisoned customer websites

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

Source Cluster:
Naked Security
Source Node: 1967466
Time Stamp: Feb 19, 2023

Google patches “in-the-wild” Chrome zero-day – update now!

Source Cluster:
Naked Security
Source Node: 1579294
Time Stamp: Jul 5, 2022

Apple patches double zero-day in browser and kernel – update now!

Source Cluster:
Naked Security
Source Node: 1627633
Time Stamp: Aug 17, 2022
LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…

Source Cluster:
Naked Security
Source Node: 1782418
Time Stamp: Dec 23, 2022

Chrome issues urgent zero-day fix – update now!

Source Cluster:
Naked Security
Source Node: 1731532
Time Stamp: Oct 29, 2022

The CHRISTMA EXEC network worm – 35 years and counting!

Source Cluster:
Naked Security
Source Node: 1765547
Time Stamp: Dec 1, 2022
Serious Security: GnuTLS follows OpenSSL, fixes timing attack bug

Serious Security: GnuTLS follows OpenSSL, fixes timing attack bug

Source Cluster:
Naked Security
Source Node: 1956368
Time Stamp: Feb 13, 2023

S3 Ep105: WONTFIX! The MS Office cryptofail that “isn’t a security flaw” [Audio + Text]

Source Cluster:
Naked Security
Source Node: 1726750
Time Stamp: Oct 20, 2022

Credit card skimming – the long and winding road of supply chain failure

Source Cluster:
Naked Security
Source Node: 1768850
Time Stamp: Dec 8, 2022

S3 Ep100.5: Uber breach – an expert speaks [Audio + Text]

Source Cluster:
Naked Security
Source Node: 1669034
Time Stamp: Sep 17, 2022

S3 Ep111: The business risk of a sleazy “nudity unfilter” [Audio + Text]

Source Cluster:
Naked Security
Source Node: 1765130
Time Stamp: Dec 1, 2022

About Us

  • Open Intelligence
  • Culture
  • Data Ecosystem
  • W3 Disruption
  • Team

Vertical Search & Ai

  • The Evolution of Search
  • What is Vertical Search
  • What is Vertical Intelligence
  • Ai Data Defragmentation
  • Data As A Service (DaaS)

Platform

  • Platform Features
  • Plato Analytics Reporting
  • PlatoAi NLP Engine
  • Sectors / Verticals
  • How Plato Works

Stay Connected

  • Governance
  • Register
  • Live Chat
  • Connect
  • Social

Account

  • Register
  • Packages
  • Enterprise
  • Listing
  • Partnerships
null
null

Copyright @ 2022 Plato Technologies Inc