SlowMist researcher Cos has warned that bookmark-based phishing attacks aimed at FOMO’s web interface are now being observed, according to a newsflash published by Odaily. The attack uses a fake human-verification prompt to trick users into dragging malicious JavaScript code into their browser bookmarks and saving it as a bookmark. Once the victim clicks that bookmark two to three times, an attacker can hijack a previously logged-in FOMO account. The warning says crypto assets held in the compromised account can then be stolen immediately. The alert focuses on a browser-side attack path rather than a direct wallet exploit, with the malicious code delivered through a deceptive webpage and activated through repeated bookmark clicks. Users of the FOMO web version are being urged to stay alert to this type of phishing setup.
Odaily reported that SlowMist researcher Cos has detected bookmark phishing attacks targeting FOMO’s web interface.
In this attack, a phishing page tricks users with a fake human-verification step, then prompts them to drag malicious JavaScript code into the browser’s bookmarks bar and save it as a bookmark. After the user clicks that bookmark two to three times, a previously logged-in FOMO account can be hijacked by the attacker, and the crypto assets in the account can be stolen immediately.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.