북한 에서 만든 스타벅스 NFT 피싱 사이트-starbucks-nft(.)marketing(2023.07.18)
2023-07-20 • Sakai • Starbucks NFT phishing site created in North Korea - starbucks-nft(.)marketing (2023.07.18) •
The source reports a North Korea-attributed phishing site at starbucks-nft.marketing that impersonated Starbucks Korea rewards content to lure users into a fake NFT airdrop. The page contrasted with the legitimate Starbucks site by offering a 'Starbucks Gift Card NFT' and prompting visitors to connect a cryptocurrency wallet through a WalletConnect QR flow. The operator used trust cues such as redirects to the real Starbucks site while the fake domain lacked the legitimate certificate and used Cloudflare infrastructure. The author noted that major security vendors did not yet flag the site at the time of testing and submitted reports to several blocking services.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.googletagmanager.co… | 2023-07-20 | 2023-07-20 |
| DOMAIN | 2fd.bridge.walletconnect.org | 2023-07-20 | 2023-07-20 |