Menu
Browse

Cyber Incident Victim: Bibox

Date:

Nov 2020

Location:

United States of America

Summary

A social engineering attack targeting GoDaddy employees enabled fraudsters to gain unauthorized control over domain names, including those of multiple cryptocurrency platforms. The attackers manipulated DNS records to redirect email and web traffic, compromising internal email accounts and partially accessing infrastructure. This led to attempts to reset passwords on third-party services like Slack and GitHub. GoDaddy confirmed the breach stemmed from employee deception, locking affected accounts and reverting changes. The incident mirrored prior vishing scams exploiting remote work conditions, with attackers using fraudulent login pages and compiling employee information from public sources to facilitate unauthorized access. Other impacted services included Liquid and NiceHash.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The incident involving Bibox.com occurred within a broader campaign targeting multiple cryptocurrency platforms through compromised GoDaddy domain management accounts between November 13 and November 18, 2020. Attackers socially engineered a limited number of GoDaddy employees, tricking them into transferring control of customer domains. This allowed unauthorized modifications to DNS records, redirecting email and web traffic to attacker-controlled infrastructure. The campaign initially impacted Liquid.com on November 13, where malicious actors gained partial infrastructure access through hijacked email accounts after GoDaddy incorrectly transferred domain control. On November 17-18, NiceHash experienced similar unauthorized DNS changes that briefly redirected traffic, prompting temporary freezing of customer funds while investigating potential compromises to third-party services like Slack and GitHub.

Cyber Incident Image

Analysis of DNS record alterations revealed Bibox.com, Celsius.network, and Wirex.app as additional cryptocurrency platforms potentially targeted through identical redirection patterns to Namecheap's PrivateEmail service. GoDaddy confirmed unauthorized changes to a small number of customer domains during routine audits, attributing the breach to employee social engineering rather than technical vulnerabilities. The registrar locked affected accounts, reverted malicious modifications, and assisted customers in regaining access. While NiceHash reported no confirmed data theft due to rapid detection and mitigation, Liquid disclosed partial infrastructure compromise through hijacked email accounts. No operational or financial impact specifics were publicly confirmed for Bibox.com, as the company did not respond to inquiries about the incident. The attack methodology mirrored previous March 2020 GoDaddy compromises involving fraudulent login pages and employee credential harvesting through vishing scams.

Sources
Sources available to members
1 source