Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Anyone got Metamask Phishing mail on your Berohost specific Email

BlembimBlembim Member
edited March 27 in General

Helo Yurier

I gor this

Title: Bank-Level Protection for Your Wallet {Noreply} #274164787

Sender is: "metamask.io | [email protected]"

This mail was sent to my email that was specifically only for berohost

I have asked 2 different LET users, and they both recived the same email on their Berohost exclusive mailbox

I cannot provide any header since its forwarded mail. But probably other can do this

Anyone got this too?

«13

Comments

  • MurvMurv Member, Megathread Squad

    Can I have your seed please

  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @Blembim said: I cannot provide any header since its forwarded mail. But probably other can do this

    From my outlook email that received it directly: https://fumo.me/api/snippet/OPbnPgyunuhS/raw

  • BlembimBlembim Member

    @Murv said:
    Can I have your seed please

    Anything but public obscene allow. But my DM always open for that

    Thanked by 4Murv mandala forest admax
  • BlembimBlembim Member

    @beanman109 said:

    @Blembim said: I cannot provide any header since its forwarded mail. But probably other can do this

    From my outlook email that received it directly: https://fumo.me/api/snippet/OPbnPgyunuhS/raw

    Can you leaks mail, regards

    Thanked by 3beanman109 zejjnt admax
  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @Blembim said:

    @beanman109 said:

    @Blembim said: I cannot provide any header since its forwarded mail. But probably other can do this

    From my outlook email that received it directly: https://fumo.me/api/snippet/OPbnPgyunuhS/raw

    Can you leaks mail, regards

    [email protected]

  • MurvMurv Member, Megathread Squad

    @Blembim said:

    @Murv said:
    Can I have your seed please

    Anything but public obscene allow. But my DM always open for that

  • kenjing789kenjing789 Member
    edited March 27

    Can you send me time they send that mail ? Im unable to find one mail like that from both spambox or inbox

  • NekoparaNekopara Member
    edited March 27

    yes, just got that too. also on my bero-host specific alias.
    "This email failed anti-phishing checks when it was received by SimpleLogin, be careful with its content. More info on anti-phishing measure"

    Thanked by 1oloke
  • BlembimBlembim Member

    @kenjing789 said:
    Can you send me time they send that mail ? Im unable to find one mail like that from both spambox or inbox

    From what i saw on @beanman109 . Bro got around 13:08:00 +0000 . I got on 13:25:00 +00.00

    Thanked by 1admax
  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @kenjing789 said:
    Can you send me time they send that mail ? Im unable to find one mail like that from both spambox or inbox

    I received it at 6:08AM PST

    Thanked by 1Blembim
  • allthemtingsallthemtings Member, Megathread Squad

    Gotta do what you gotta do, hardware aint cheap @berohost 22k btc in my friends wallet please email [email protected]

  • DecicusDecicus Member

    hello I confirm I receive mine at 2:24 PM Central European Time today

    I have dedicated email alias for Bero, so it's definitely from them in some way. Hopefully not the customer DB and instead just some newsletter list 🙃

  • 655655 Member

    I have not received it, but iirc I had opted out of newsletters.

  • +1 on this. I received the same phishing email today on my specific berohost only alias.

    What's more concerning: I just dug through my spam folder and found another similar email sent to this exact alias on February 17th that I completely missed until today. So, it looks like this leak isn't a new development and their list has been compromised for over a month now.

    I've already contacted berohost support about the leak but haven't received any answer so far. Really hoping they step in here soon to explain exactly what happened and what data was accessed.

  • BlembimBlembim Member

    @berohost any statement on this tho

  • berohostberohost Member, Patron Provider

    So far, we have no information indicating that any data has been stolen. We ask affected customers to notify us via a support ticket so that we can investigate the matter further.

  • anakaraanakara Member

    I also saw a similar email in the spam mail. It seems like everyone is the same

  • @Blembim said:

    @kenjing789 said:
    Can you send me time they send that mail ? Im unable to find one mail like that from both spambox or inbox

    From what i saw on @beanman109 . Bro got around 13:08:00 +0000 . I got on 13:25:00 +00.00

    Um i didnt get it, but im option out of newsletter so I probably same as @655

    They prob got api leaked ?

  • Actually @655, do your email have alias ? postfix +

    Thanked by 1zejjnt
  • barbarosbarbaros Member
    edited March 27

    Yeah I got it to the email I use in my berohost account. 4 hours ago at 13:21 +00.00

  • JabJabJabJab Member

    @beanman109 said:

    @Blembim said: I cannot provide any header since its forwarded mail. But probably other can do this

    From my outlook email that received it directly: https://fumo.me/api/snippet/OPbnPgyunuhS/raw

    Looking at headers I don't see any specific mailling list / software used? So kinda uhmmm fucked?

  • @JabJab said:

    @beanman109 said:

    @Blembim said: I cannot provide any header since its forwarded mail. But probably other can do this

    From my outlook email that received it directly: https://fumo.me/api/snippet/OPbnPgyunuhS/raw

    Looking at headers I don't see any specific mailling list / software used? So kinda uhmmm fucked?

    Well they probably pulled the customer emails (and other stuff) from Berohost and sent just usual spam.

  • ObelousObelous Member

    @JabJab said:

    @beanman109 said:

    @Blembim said: I cannot provide any header since its forwarded mail. But probably other can do this

    From my outlook email that received it directly: https://fumo.me/api/snippet/OPbnPgyunuhS/raw

    Looking at headers I don't see any specific mailling list / software used? So kinda uhmmm fucked?

    Some don't add any extra identifying headers.

    Also never considered that if they had access to the mailing software they could've just exported the list and sent it using something else?

  • I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

  • ymlsmymlsm Member
    edited March 27


    also got it, mail was used only for bero.

    I was not subscribed to the newsletter

    Thanked by 1oloke
  • NeoonNeoon Community Contributor, Veteran

    Thanked by 3oloke xvps zejjnt
  • 655655 Member

    @kenjing789 said:
    Actually @655, do your email have alias ? postfix +

    yes it does

  • xvpsxvps Member
    edited March 27

    Are you guys sure this is something new?

    Bero-host has been using lottie-player@latest (2.0.12) for some time, but lottie-player versions 2.0.5–2.0.7 had a similar security issue more than a year ago, where hackers were targeting MetaMask and other wallets in phishing attacks.

    I think those who were affected saw a strange popup when they visited a website that used lottie-player.

    Your email addresses might have been scraped through that vulnerability back then.

    Be aware that the email headers posted in the thread show that the email was sent using compromised AWS SES credentials belonging to scep.gob.gt (Guatemalan government)*. Because it’s sent from a high-reputation AWS IP, basic spam filters are bypassed.

    Earlier, similar phishing emails sent from less trusted IP addresses might have been filtered, deleted, or rejected before they reached your inbox.

    In other words, it might be an old email address leak that have been fixed a long time ago.

    *I haven’t looked into this, but IP addresses belonging to scep.gob.gt have some security issues where you can download PHP code etc and might be why their mail server is/was compromised.

    Edit: I just noticed that AWS SES is not authorized as a sender, but DMARC is set to p=none (monitor only). It's not a scep.gob.gt server who send the phishing mail. It might still be an old leak.

    Thanked by 1zejjnt
  • NeoonNeoon Community Contributor, Veteran
    edited March 27

    I also got the phishing mail, same sender etc.
    Someone def. breached something.

  • zGatozGato Member
    edited March 28

    Received same email, a few hours ago. I don't have an unique email, but I usually don't get any spam to this one ._.

    something's sure going on and @berohost doesn't seem to care much as per their previous comment.

    Thanked by 3oloke Nekopara admax
Sign In or Register to comment.