A threat actor targeting cryptocurrency scam websites by piggybacking on other scams to steal wallet assets via permissions.
Analyst brief
Water Labbu is a unique threat actor that targets cryptocurrency scam websites. Rather than using social engineering directly, it piggybacks on other scammers' campaigns and steals assets by obtaining access permissions and token allowances from already-deceived victims' wallets. Defenders should monitor for malicious smart contract interactions and unauthorized wallet permission requests on crypto-related platforms.
Water Labbu
unknown
Trend Micro discovered a threat actor they named Water Labbu that was targeting cryptocurrency scam websites. Typically, cryptocurrency scammers use social engineering techniques, interacting with victims to gain their trust and then manipulating them into providing the permissions needed to transfer cryptocurrency assets. While Water Labbu managed to steal cryptocurrencies via a similar method by obtaining access permissions and token allowances from their victim’s wallets, unlike other similar campaigns, they did not use any kind of social engineering — at least not directly. Instead, Water Labbu lets other scammers use their social engineering tricks to scam unsuspecting victims.
What is the main characteristic that distinguishes the Water Labbu threat actor from other cryptocurrency scammers?+
Water Labbu is distinguished by not using social engineering directly. It steals assets by obtaining access permissions and token allowances from wallets of victims already deceived by other scammers.