Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Anyone got Metamask Phishing mail on your Berohost specific Email

2

Comments

  • BlembimBlembim Member
    edited March 28

    @xvps said:

    In other words, it might be an old email address leak that have been fixed a long time ago.

    I wish wishing that this would be the case, if i has never been berohost customer before until 2 months ago 😔

    Thanked by 2xvps oloke
  • xvpsxvps Member
    edited March 28

    I just took a deeper look at their website’s code in the browser, and I have another guess.

    There are indications (hashed ID value) that they are using an outdated version of Livewire with a known RCE vulnerability.

    (They might have patched it manually, but that it not how it's normally done.)

    There are some conditions that have to be met, but if so, an attacker could send a specially crafted JSON payload to the Livewire update endpoint that could trick the server into executing arbitrary PHP code and, for example, dump the user database.

    There are also indications (data sent to logs) that several of their Plesk servers haven’t been updated in a long time, so combined with their nonchalant answer, I would just back up my data and move on if I were their customer.

  • defaultdefault Veteran

    @Neoon said:
    I also got the phishing mail, same sender etc.
    Someone def. breached something.

  • olokeoloke Member, Host Rep

    @default said:

    @Neoon said:
    I also got the phishing mail, same sender etc.
    Someone def. breached something.

    @sillycat stop smoking - it's unhealthy :neutral:

  • kkonekokkoneko Member

    I didn't get any email like that... yet.

    Thanked by 1oloke
  • @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

  • NeoonNeoon Community Contributor, Veteran

    @NotFoundException said:

    @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

  • I can confirm that I got an email from that metamask thing into my inbox through my email alias (SimpleLogin with custom domain) that I am using on BeroHost.

    Thanked by 1mandala
  • i received an email like that. but I can't figure out where the leak came from. how did you end up on @berohost ?

    Thanked by 2oloke COLBYLICIOUS
  • 655655 Member

    @655 said:
    I have not received it, but iirc I had opted out of newsletters.

    just got the mail

    Thanked by 1mandala
  • lukast__lukast__ Member, Megathread Squad

    Also got such an email yesterday:

  • NeoonNeoon Community Contributor, Veteran

    @default said:

    @Neoon said:
    I also got the phishing mail, same sender etc.
    Someone def. breached something.

    Thanked by 1zejjnt
  • xvpsxvps Member
    edited March 28

    @NotFoundException said:

    @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

    Bero-host is a reseller of synlinq.de (AS44486) or famesystems.de/resellerapi.de, so it might be worth checking whether you’re using another of their resellers or if there are other things you have in common.

    Edit: @FameSystems added and tagged.

  • xvpsxvps Member
    edited March 28

    @xvps said:

    @NotFoundException said:

    @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

    Bero-host is a reseller of synlinq.de (AS44486), so it might be worth checking whether you’re using another of their resellers or if there are other things you have in common.

    prepaid-host.com (@PrepaidHost) is one of the resellers that also advertise on LET with same or similar setup.

  • defaultdefault Veteran

    @Neoon said:

    @default said:

    @Neoon said:
    I also got the phishing mail, same sender etc.
    Someone def. breached something.

    Thanked by 2oloke zejjnt
  • zejjntzejjnt Member
    edited March 28

    Well let's start here;

    https://mxtoolbox.com/SuperTool.aspx?action=dmarc:scep.gob.gt&run=toolpage

    Status Problem DMARC Policy Not Enabled DMARC Quarantine/Reject policy not enabled

    https://mxtoolbox.com/SuperTool.aspx?action=spf:scep.gob.gt&run=toolpage

    SPF Syntax Check Invalid syntax found Information More Info
    Status Problem DMARC Policy Not Enabled It is recommended to use a quarantine or reject policy. To enable BIMI, it is required to have one of these at 100%.

    https://zonemaster.se/en/result/9bb0539304ff564c/

    SPF policy validation
    Zone11
    Warning
    The SPF policy of scep.gob.gt has a syntax error. Policy retrieved from the following nameservers: ns1.dnsguatemala26.com/184.107.141.138;
    ns2.dnsguatemala26.com/184.107.141.138.

    So while it's not exactly a free hole enter here it can sure as fuck be used for kinda whatever in regards to spoofing e-mails.

    Not sure if that helps but it's always either SPF, DKIM, DMARC or fucking DNS with these things.

    Thanked by 1mandala
  • xvpsxvps Member

    @zejjnt said:
    Well let's start here;

    https://mxtoolbox.com/SuperTool.aspx?action=dmarc:scep.gob.gt&run=toolpage

    Status Problem DMARC Policy Not Enabled DMARC Quarantine/Reject policy not enabled

    https://mxtoolbox.com/SuperTool.aspx?action=spf:scep.gob.gt&run=toolpage

    SPF Syntax Check Invalid syntax found Information More Info
    Status Problem DMARC Policy Not Enabled It is recommended to use a quarantine or reject policy. To enable BIMI, it is required to have one of these at 100%.

    https://zonemaster.se/en/result/9bb0539304ff564c/

    SPF policy validation
    Zone11
    Warning
    The SPF policy of scep.gob.gt has a syntax error. Policy retrieved from the following nameservers: ns1.dnsguatemala26.com/184.107.141.138;
    ns2.dnsguatemala26.com/184.107.141.138.

    So while it's not exactly a free hole enter here it can sure as fuck be used for kinda whatever in regards to spoofing e-mails.

    Not sure if that helps but it's always either SPF, DKIM, DMARC or fucking DNS with these things.

    It is more important to determine where the leak is.

    @FAT32, if it is reseller software that is leaking customer data and multiple LET providers are affected, it might be a good idea to postpone the provider poll for a couple of days.

    Thanked by 1FAT32
  • ObelousObelous Member

    @xvps said: It is more important to determine where the leak is.

    Well for now there's no evidence pointing to anything but berohost.

  • xvpsxvps Member

    @Obelous said:

    @xvps said: It is more important to determine where the leak is.

    Well for now there's no evidence pointing to anything but berohost.

    Then explain this:

    @NotFoundException said:

    @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

    Thanked by 1mandala
  • emghemgh Member, Megathread Squad

    @xvps said:

    @Obelous said:

    @xvps said: It is more important to determine where the leak is.

    Well for now there's no evidence pointing to anything but berohost.

    Then explain this:

    @NotFoundException said:

    @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

    1. The spammers targetting more than just bero
    2. The amount of people who only used it with bero makes it probable that bero’s clients emails were leaked

    Although it would be funny if someone breached like simplelogin and started targetting only emails for specific domains to make it look like a provider breach

  • matey0matey0 Member
    edited March 28

    I wonder if only users who paid with MetaMask supported coins received these E-Mails.
    Either way, E-Mail lists aren't really valuable and the phishing E-Mail seems low effort, so probably not a targeted breach.

    @berohost can't be trusted judging by their response in this thread though.
    Report the domains & E-Mails and move on.

    Thanked by 1COLBYLICIOUS
  • networknetwork Member
    edited March 28

    @matey0 said: I wonder if only users who paid with MetaMask supported coins received these E-Mails.

    I got this email at 15:10 UTC today on an address that is used on multiple hosts including BeroHost and I have no idea what MetaMask is. I paid with PayPal.

  • berohostberohost Member, Patron Provider

    @xvps said:

    @NotFoundException said:

    @NotFoundException said:
    I didn't opt in to newsletter and didn't receive the email. My account is relativly new tho

    I now received this exact email on one of my emails, that I didn't even use at bero.

    Bero-host is a reseller of synlinq.de (AS44486) or famesystems.de/resellerapi.de, so it might be worth checking whether you’re using another of their resellers or if there are other things you have in common.

    Edit: @FameSystems added and tagged.

    We are not a reseller. We only purchase the network uplink from Synlinq. Otherwise, we operate our own switches and server hardware.

  • berohostberohost Member, Patron Provider

    @xvps said:
    I just took a deeper look at their website’s code in the browser, and I have another guess.

    There are indications (hashed ID value) that they are using an outdated version of Livewire with a known RCE vulnerability.

    (They might have patched it manually, but that it not how it's normally done.)

    There are some conditions that have to be met, but if so, an attacker could send a specially crafted JSON payload to the Livewire update endpoint that could trick the server into executing arbitrary PHP code and, for example, dump the user database.

    There are also indications (data sent to logs) that several of their Plesk servers haven’t been updated in a long time, so combined with their nonchalant answer, I would just back up my data and move on if I were their customer.

    We are currently using Livewire v3.7.11 and will be updating to the latest version 4 shortly. The version we are using has no known vulnerabilities.

    Thanked by 1oloke
  • berohostberohost Member, Patron Provider

    We take your reports very seriously and are currently working to identify the cause. Based on the information we have at this time, no data has been stolen from our customer database. Our website and internal servers have not experienced any unusual access attempts or security breaches. However, we are working with an external security firm to analyze the issue so we can determine the cause. Since we also use various external services, the problem may originate there. However, it is often difficult to get meaningful feedback on this over the weekend.
    We would like to ask all affected customers who can verify that they use the email address exclusively with us to contact us via our ticket system so that we can narrow down the cause. This helps us check important details such as the registration date, newsletter settings, etc.

    Thanked by 2matey0 tux
  • I didn't find it but I actually received this too! On the 17th of Feb.

    X-Mozilla-Status: 0001
    X-Mozilla-Status2: 00000000
    Return-Path: <<redacted>[email protected]>
    Delivered-To: <redacted>
    Received: from <redacted> ([127.0.0.1])
        by <redacted> with LMTP
        id <redacted>
        (envelope-from <<redacted>[email protected]>)
        for <redacted>; Tue, 17 Feb 2026 XX:XX:XX +0000
    Received: from e<redacted>.smtp-out.us-east-2.amazonses.com (e<redacted>.smtp-out.us-east-2.amazonses.com [23.251.226.11])
        by <redacted> (Postfix) with ESMTPS id <redacted>
        for <redacted>; Tue, 17 Feb 2026 XX:XX:XX +0000 (UTC)
    Authentication-Results: <redacted>;
        dkim=pass header.d=fixeat.cl header.s=<redacted> header.b=<redacted>;
        dkim=pass header.d=amazonses.com header.s=<redacted> header.b=<redacted>;
        dmarc=pass (policy=none) header.from=fixeat.cl;
        spf=pass smtp.mailfrom=<redacted>[email protected]
    DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
        s=<redacted>; d=fixeat.cl; t=<redacted>;
        h=Content-Type:MIME-Version:From:To:Subject:Message-ID:Date;
        bh=<redacted>;
        b=<redacted>
    DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
        s=<redacted>; d=amazonses.com; t=<redacted>;
        h=Content-Type:MIME-Version:From:To:Subject:Message-ID:Date:Feedback-ID;
        bh=<redacted>;
        b=<redacted>
    Content-Type: multipart/mixed; boundary="===============<redacted>=="
    MIME-Version: 1.0
    From: "[email protected]" <[email protected]>
    To: <redacted>
    Subject: =?UTF-8?B?<redacted>==?= {Noreply} #<redacted>
    Message-ID: <redacted>
    Date: Tue, 17 Feb 2026 XX:XX:XX +0000
    Feedback-ID: ::1.us-east-2.<redacted>=:AmazonSES
    X-SES-Outgoing: 2026.02.17-23.251.226.11
    X-Spamd-Bar: +++
    X-Spam-Level: ***
    
    --===============<redacted>==
    Content-Type: text/html; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: base64
    
    <redacted body>
    --===============<redacted>==--
    

    This is as well a bero-only mail address, which has never been used for any other service.
    I have used PayPal & CreditCard for orders, so nothing related to crypto.

    I guess there is a databreach then...?

  • xvpsxvps Member
    edited March 28

    @berohost said:

    @xvps said:
    I just took a deeper look at their website’s code in the browser, and I have another guess.

    There are indications (hashed ID value) that they are using an outdated version of Livewire with a known RCE vulnerability.

    (They might have patched it manually, but that it not how it's normally done.)

    There are some conditions that have to be met, but if so, an attacker could send a specially crafted JSON payload to the Livewire update endpoint that could trick the server into executing arbitrary PHP code and, for example, dump the user database.

    There are also indications (data sent to logs) that several of their Plesk servers haven’t been updated in a long time, so combined with their nonchalant answer, I would just back up my data and move on if I were their customer.

    We are currently using Livewire v3.7.11 and will be updating to the latest version 4 shortly. The version we are using has no known vulnerabilities.

    Yes, I can see you have made some updates since I wrote the above.

    It's easy to check because the id hash in script src="/livewire/livewire.js?.. changes per release.

  • Got the mail too.

  • Got the same mail here.
    27/03/2026, 14:37:18 23.251.226.5 [email protected]

    Also dedicated email for berohost.

  • ymlsmymlsm Member
    edited March 28

    Next mail to email dedicated only for berohost

Sign In or Register to comment.