Coinfomania Bookmark Phishing Attack Targets FOMO Users
Article Content
- •FOMO users are targeted by a bookmark phishing attack that drains crypto assets.
- •Attackers use fake CAPTCHA prompts to trick users into activating malicious bookmarks.
- •Security researchers are documenting the phishing pages and attacker wallet addresses.
FOMO users are facing a new phishing threat involving malicious bookmarks that hijack accounts. Attackers trick users into dragging JavaScript code into their bookmarks under the pretense of completing a CAPTCHA verification. Once activated, these bookmarks can drain crypto assets from the compromised accounts after a few clicks. Security researchers have documented the phishing pages and associated wallet addresses for investigation. Users are advised to be cautious and verify the legitimacy of authentication prompts on the FOMO platform. The phishing method exploits the growing sophistication of online threats, particularly in the crypto space. As of now, trading volumes on FOMO are reported to be at zero, indicating a potential decline in user confidence amidst these security alerts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
How does the phishing attack work?
What should FOMO users do to protect themselves?
Is there any ongoing investigation into this attack?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…