← AVOID.NET
Entity Graph
Browse extracted entities, relationships, and potential duplicates.
Total entities
22,536
Relationships
17,946
Potential duplicates
0
Filter by kind
Entities
↯cc64569c
Crypto.com's phishing warning circulates further; GridinSoft and other security outlets document the specific lure types (fake bank-account additions, unrecognized-login alerts, identity-verification demands) being used against Crypto.com customers.(2026-07-31:crypto-com-phishing-campaign-email-domain-abuse-august-2026)event
↯09343553
Crypto.com posts a public warning on X (Twitter) alerting users to 'an increase in targeted industry-wide phishing attacks' and listing protective measures including the Anti-Phishing Code and the Crypto.com Verify tool. One user comments the warning appears to have arrived twelve hours after some fraudulent emails were already received.(2026-07-30:crypto-com-phishing-campaign-email-domain-abuse-august-2026)event
↯0b43e2b5
CoinTracking discloses a structurally identical attack: an unauthorized actor accessed its SendGrid marketing account and sent phishing emails from the company's own verified domain to approximately 128,000 external addresses.(2024-11-04:crypto-com-phishing-campaign-email-domain-abuse-august-2026)event
□654e1b7a
Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)organization
↯3e2331d6
Crypto Times reports that over 100 crypto projects shut down in H1 2026, citing RootData data, listing Leap Wallet among the closures and attributing the broader wave to financial exhaustion rather than fraud.(2026-08-04:leap-wallet)event
↯0e4c824e
All Leap Wallet products permanently cease operation. The leapwallet.io domain displays a farewell page. Users who have not exported recovery phrases by this date must retain their seed phrase to recover funds via a compatible wallet.(2026-05-28:leap-wallet)event
↯4cce4e26
Leap Wallet announces permanent shutdown of all products effective May 28, 2026. Affected products include the browser extension, iOS and Android apps, Compass Wallet, Swapfast, the Leap Cosmos Hub validator, and Leap Cosmos Snaps. No specific reason disclosed.(2026-04-03:leap-wallet)event
↯23bea4dc
Leap begins building on the Cosmos interchain. Within approximately one year, the team reports over 300,000 users across its product suite.(2022-07-01:leap-wallet)event
↯67ecb25f
Terra blockchain collapses. Terraform Labs — an investor in Leap — fails. Leap begins pivoting to the broader Cosmos ecosystem.(2022-05-01:leap-wallet)event
↯687f522d
Leap announces $3.2 million private token sale co-led by CoinFund and Pantera Capital, with participation from Arrington Capital, Accel, and Terraform Labs. Implied valuation approximately $40 million.(2022-04-05:leap-wallet)event
↯37b32f26
Leap Wallet founded by Sanjeev Rao in Vancouver, British Columbia, with a $50,000 grant from Terraform Labs. Initial product is a Terra ecosystem browser extension.(2021-11-01:leap-wallet)event
◎9254c74b
cyberrecaps.comdomain
◎6bae58ef
trojan-killer.netdomain
◎07280d03
research.veryserious.systemsdomain
◎e3d3f4f4
opensourcemalware.comdomain
↯07302fd3
The Hacker News publishes comprehensive coverage citing Sonatype and OpenSourceMalware research, describing 1,033 total packages, crypto drain capabilities, Aeza Group infrastructure link, and connection to Moika campaign.(2026-08-10:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯f4cbb8ed
SC Media and other outlets publish coverage. OpenSourceMalware co-founder Jenn Gile reports total confirmed WEL1DROPPER packages at 1,033.(2026-08-08:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯5e3300d2
Sonatype Research Labs publishes campaign tracking under the name 'Flooding Dropper' (sonatype-2026-005660), identifying 846 malicious npm components. Campaign velocity reportedly slowed after discovery week.(2026-08-07:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯5161d8a1
OpenSourceMalware publishes analysis of the AI slopsquatting campaign, documenting 700+ malicious npm packages published in approximately 48 hours and naming the campaign 'WEL1DROPPER'.(2026-08-06:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯071b6040
OpenSourceMalware researchers identify bigops-backend as the first documented WEL1DROPPER package, triggering a cross-platform native binary payload on Windows, Linux, and macOS.(2026-08-05:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯6bedb4be
Moika Wave 3: Fourth account emcd-vue publishes packages impersonating EMCD cryptocurrency exchange with advanced obfuscation.(2026-06-01:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯d8527b17
Moika Wave 2: Third account t-in-one adds 12 packages, including impersonation of Sberbank's payment widget. Microsoft Security Blog separately documents 33 malicious npm packages abusing dependency confusion.(2026-05-29:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯26228231
Moika Wave 1: npm accounts mr.4nd3r50n and pik-libs publish 164 malicious packages targeting cloud platform and financial services internal scopes within 25 minutes.(2026-05-27:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
↯4aed43cd
Moika dependency confusion campaign begins: over 250 malicious npm packages published, exfiltrating process.env contents and delivering OS-specific second-stage payloads. Assessed by OpenSourceMalware as a predecessor to WEL1DROPPER.(2026-04-01:wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-2026)event
□3b14d02f
WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)organization
◎cba73d53
↯4fcd67cc
French Finance Ministry confirms the June 2026 DGFiP breach affecting 678,437 taxpayers. Multiple outlets including The Block, Decrypt, and Bitcoin Magazine publish warnings to crypto holders about the compounded physical attack risk.(2026-08-14:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯7634bed2
Threat actor ZeroBytes publicly claims responsibility for the DGFiP breach on breach forums, stating data from more than 600,000 individuals was obtained.(2026-08-12:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯829f3c40
CryptoTimes and other outlets report Chainalysis data confirming France as the global wrench attack hotspot in H1 2026, with over USD 30 million stolen.(2026-08-06:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯9198d588
CertiK Intel3D H1 2026 Wrench Attacks Report formally published via GlobeNewswire press release.(2026-07-25:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯82963edf
CertiK publishes its H1 2026 Wrench Attacks Report, recording 52 verified global incidents (33 in France), USD 124.1 million in estimated financial exposure, and a 33% year-over-year surge.(2026-07-22:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯edc7fb5c
French Interior Minister Laurent Nuñez publicly discloses that authorities have logged more than 70 crypto-related violent incidents. DGFiP cuts off attacker's access around this period.(2026-06-30:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯b1e93452
Unauthorized intrusion into DGFiP systems occurs. Attacker allegedly gains access using stolen or misused credentials of a legitimate user, connects to the internal VPN, and uses an internal search tool to extract taxpayer records.(2026-06-26:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯b1709b8c
CoinDesk publishes investigation into the rise of wrench attacks, documenting France's emergence as global epicenter and quoting TRM Labs on the strategic shift from technical to physical targeting.(2026-04-19:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯9afe5015
Forbes publishes investigation into France's crypto kidnapping crisis, noting a pattern of 'zero convictions' as a contributing factor in the escalating attack rate.(2026-02-14:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯4af3349f
Ghalia C., the Bobigny tax office employee, is reported to have lost a bail appeal and remains in custody, facing charges of complicity in violence and criminal conspiracy. Case reported by Gizmodo.(2026-01-10:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯5733d346
Stolen Waltio database — containing data on approximately 50,000 users of the French crypto tax platform — appeared for sale on BreachForums. The breach had not yet been detected by Waltio.(2025-12-24:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯ab2a4978
Ledger co-founder David Balland kidnapped in France. One of his fingers was reportedly severed before police rescued him, in a case that drew international attention to France's crypto violence problem.(2025-01-01:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
↯1b88b907
Three armed men assaulted a La Santé prison guard in his Montreuil home. French investigators later allege that Ghalia C., a Bobigny tax office employee, provided the attackers with the victim's address using unauthorized access to Mira, the tax administration's internal software.(2024-09-01:france-dgfip-tax-data-breach-crypto-wrench-attack-enablement-august-2026)event
⌂c70d7203
France DGFIP Tax Data Breach — Crypto Wrench Attack Enablement (August 2026)protocol
◎2150cec2
levelblue.comdomain
◎41b4df54
itsecurityguru.orgdomain
◎cd11a04b
applemagazine.comdomain
↯5139148c
Huntress published full technical analysis of the Go-based macOS infostealer, documenting the DRAIN function, Aeza Group C2 infrastructure, IOCs, and remediation steps. AppleInsider, The Hacker News, BleepingComputer, IT Security Guru, Infosecurity Magazine, SOC Prime, and AppleMagazine covered the findings the same day.(2026-08-06:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
↯554a2485
Microsoft Security Blog published an analysis documenting that a macOS ClickFix campaign had evolved to include new obfuscation techniques, providing broader context for the threat landscape one day before the Huntress publication.(2026-08-05:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
↯e7d65cfc
Huntress analyst Andrew Brandt discovered components of the Go-based macOS stealer during a retrospective threat hunt on a monitored endpoint, identifying the March 2026 infection approximately three months after the fact.(2026-06-01:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
↯c536ad4d
AppleInsider reported on a separate but related macOS ClickFix CAPTCHA campaign using Terminal-paste delivery already active in the wild, documenting the social engineering technique broadly.(2026-03-10:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
↯df9db0eb
Approximate date of initial infection: A macOS endpoint monitored by Huntress MDR was compromised via a ClickFix social engineering attack, installing the Go-based infostealer. The infection remained undetected for approximately three months.(2026-03-01:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
Data refreshes every 5 minutes · All metrics derived from Supabase