216.73.216.226

Unmasking the FreeDrain Network

· Published 08/05/2025 21:45 · Modified 09/05/2025 17:25

Export JSON

Essential information

Published
08/05/2025 21:45
Modified
09/05/2025 17:25
Tags
2025-05-08 cryptocurrency free hosting abuse infrastructure analysis phishing redirectors seo manipulation wallet draining
Related entities
1 intrusion sets (apt), 14 techniques (mitre)

Description

A collaborative investigation by Validin and SentinelLABS exposes the FreeDrain Network, a large-scale operation. The campaign exploits search engine optimization, free web services, and redirection techniques to target and drain wallets. The attackers use lure pages hosted on trusted platforms, which redirect victims to sites mimicking legitimate wallet interfaces. The operation is believed to be run by individuals in the IST timezone, working standard business hours. The campaign has been active since at least 2022, with a notable acceleration in mid-2024. The research highlights the need for stronger safeguards on free publishing platforms to prevent such large-scale abuse.

External references