• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Upcoming Events
    • Blockchain Futurist Conference, Toronto (July 21-22, 2026)
    • Wiki Finance Expo, Hong Kong (July 23-24, 2026)
    • CFO StraTech, Mumbai (August 2, 2026)
    • CFO StraTech, Bengaluru (August 20, 2026)
    • PROFX Expo, Cape Town (August 20-21, 2026)
    • CFO StraTech, Dubai (September 2, 2026)
    • PROFINEXPO, Bangkok (September 3-4, 2026)
    • Web3 Warsaw (September 9-10, 2026)
    • Digital Assets Week in London (October 6-7, 2026)
    • 5th Fintech Week & Expo, Frankfurt (October 7-8, 2026)
    • iCrypto Awards: People’s Choice, Dubai (December, 2026)
  • Past Events

Crypto Reporter

Online magazine about cryptocurrencies, NFTs, DeFi, GameFi and other blockchain technologies

Join us on Telegram: https://t.me/crypto_reporter
  • News
    • News Feed
    • Cryptocurrencies
      • Bitcoin
      • Altcoins
    • Payment solutions
    • Exchanges
      • Binance
      • bitFlyer
      • Bitfinex
      • CBOE
      • CME
      • Coinbase
      • Coincheck
      • Coinfloor
      • Nasdaq
      • Poloniex
    • Regulations
      • Australia
      • Belarus
      • China
      • Europe
      • India
      • Iran
      • Israel
      • Japan
      • North Korea
      • Philippines
      • Portugal
      • Russia
      • South Korea
      • Thailand
      • Turkey
      • Venezuela
      • Vietnam
      • United States
    • Blockchain platforms
    • Crypto news in brief
    • Stats & trends
    • Reviews
      • Ambrosus
      • ATN
      • Dash
      • Green Power Exchange
      • Power Ledger
      • ShapeShift
      • Waltonchain
      • Cryptocurrency market capitalization can top 4 trillion USD, under conservative estimates
    • Opinion
    • Sponsored
  • Press Releases

Lookout Discovers Advanced Phishing Kit Targeting U.S. Federal Agency and Cryptocurrency Exchange Organizations

February 29, 2024 By Business Wire

Threat Actor Emulates Scattered Spider Group and Takes Unique Approach to Collect Login Credentials

BOSTON--(BUSINESS WIRE)--Lookout, Inc., the data-centric cloud security company, today announced the discovery of an advanced phishing kit, CryptoChameleon, which exhibits tactics that target cryptocurrency platforms as well as the Federal Communications Commission (FCC) via mobile devices. The intended targets, mostly users of cryptocurrency and single sign-on (SSO) services in the United States, also include Binance and Coinbase employees. Leveraging the CryptoChameleon phishing kit, bad actors utilize text messages and voice calls where they personally reach out to the victim to build a sense of trust while encouraging them to follow the steps of the attack. This has resulted in a high success rate, leading to the collection of quality data, including usernames, passwords, password reset URLs and even photo IDs. Lookout customers who have Phishing Content Protection (PCP) were protected against CryptoChameleon.



This new phishing kit emulates techniques that have been used by the Scattered Spider cybercriminal group. Operators behind the kit have successfully duplicated pages for solutions like Okta, Outlook and Google, which means it could be used to target any organization that uses these solutions as their SSO provider. Based on conversations that the Lookout security research team had with several victims, CryptoChameleon uses phone numbers and websites that appear legitimate and reflect a real company’s support team. While CryptoChameleon follows similar tactics, there are enough differences to indicate that this is likely not Scattered Spider operating the kit and could be a different criminal group or several individual actors.

This style of attack is one that Lookout has been observing and analyzing closely as it continues to increase in frequency and become more prevalent. With more corporate data residing in the cloud and a change in how users interact with that data, an increasing number of bad actors are now leveraging social engineering, targeting a user’s mobile phone to steal credentials that provide legitimate and immediate access to critical corporate data as part of the modern cyber kill chain. Lookout data shows that every quarter, between 23% and 26% of mobile users tapped on at least one phishing link in 2023. And the discovery of CryptoChameleon represents another significant shift in the continued evolution of this kill chain.

“We’re seeing a trend of financially motivated threat actors – who typically target cryptocurrency and direct financial fraud – move into breaching enterprise and government organizations for ransom,” said David Richardson, Vice President of Endpoint and Threat Intelligence, Lookout. “We urge cryptocurrency and single-sign-on users and organizations to take steps to protect their devices, work and personal data.”

CryptoChameleon highlights:

  • The phishing kit first asks the victim to complete a captcha using hCaptcha. This is a tactic that prevents automated analysis tools from crawling and identifying the phishing site.
  • Unlike typical phishing kits, which attempt to harvest credentials as quickly as possible, CryptoChameleon is aware of modern security controls organizations have put in place such as multi-factor authentication and allows bad actors to respond accordingly.
  • While the version of CryptoChameleon targeted at the FCC impersonates the FCC’s specific Okta page by default, the kit can impersonate many different companies’ brands and authentication processes.
  • Lookout also found Okta impersonation pages that target employees of Binance and Coinbase, but the majority of the sites seemed to target users of cryptocurrency and SSO services.
  • Based on the phishing site characteristics, Lookout researchers have identified over 250 phishing sites using this kit with more being found every day.
  • Since initially discovering the phishing kit, Lookout has seen evidence that hundreds of victims have been impacted by the attack.

Lookout Mobile Endpoint Security customers have been protected against these phishing sites since before the February 2024 discovery, based on insights from parallels and similar infrastructure of previous attacks. Lookout will continue to track the general behaviors and techniques used by this and other criminal groups to ensure protection against additional sites that use this kit and will continue to update protections for customers through automated means as necessary.

Additional Resources:

  • Learn more about the Lookout Mobile Endpoint Security and the Lookout Threat Lab.
  • Listen and subscribe to Security Soapbox, the Lookout podcast covering privacy, security, and everything in between.

About Lookout

Lookout, Inc. is the data-centric cloud security company that uses a defense-in-depth strategy to address the different stages of a modern cybersecurity attack. Data is at the core of every organization, and our approach to cybersecurity is designed to protect that data within today’s evolving threat landscape no matter where or how it moves. People — and human behavior — are central to the challenge of protecting data, which is why organizations need total visibility into threats in real time. The Lookout Cloud Security Platform is purpose-built to stop modern breaches as swiftly as they unfold, from the first phishing text to the final cloud data extraction. We are trusted by enterprises and government agencies of all sizes to protect the sensitive data they care about most, enabling them to work and connect freely and securely. To learn more, visit www.lookout.com and follow Lookout on our blog, LinkedIn and X.

© 2024 Lookout, Inc. LOOKOUT®, the Lookout Shield Design®, LOOKOUT with Shield Design® and the Lookout multi-color/multi-shaded Wingspan Design® are registered trademarks of Lookout, Inc. in the United States and other countries. DAY OF SHECURITY®, LOOKOUT MOBILE SECURITY®, and POWERED BY LOOKOUT® are registered trademarks of Lookout, Inc. in the United States. Lookout, Inc. maintains common law trademark rights in EVERYTHING IS OK, PROTECTED BY LOOKOUT, CIPHERCLOUD, and the 4 Bar Shield Design.


Contacts

Lookout PR: press@lookout.com

Filed Under: News Feed

Primary Sidebar

Press Releases

How to Copy a Crypto Wallet On-Chain Without a Social Trading App

June 24, 2026

SideShift.ai Launches U.S. Platform as Demand for Faster Crypto Swaps Accelerates

June 24, 2026

30th Edition Connected Banking Summit – Innovation & Excellence Awards 2026 Returns to Riyadh to Accelerate the Kingdom’s Banking Transformation

June 24, 2026

Franklin Templeton Completes Acquisition of 250 Digital

June 24, 2026

Minds by Animoca Brands and HKSTP extend Build East application deadline and expand eligibility to international teams

June 24, 2026

Follow Us

Blockchain Futurist Conference

Wiki Finance Expo

Web3 Warsaw

5th Fintech Week & Expo 2026

iCrypto Awards

Footer

Crypto Reporter is an online magazine about cryptocurrencies, NFTs, DeFi, GameFi and other blockchain technologies
About us
Contact us
Submit press-release

Search

2017-2026 Crypto Reporter