Skip to content

Scam: fake 'server migration' phishing got my credentials

General Discussion by wendy 25 replies 3.9K views
6 #1

Got hit by a fake "server migration" email yesterday morning. Looked identical to real Contabo notices, same headers, same footer links. Clicked the "verify credentials" link, entered my panel login, and within four hours my VPS was mining something and my DNS records were pointed at a phishing clone of my own site. Recovery steps I took, in case this helps anyone:

  • Changed passwords immediately on a clean device (live USB, not my normal workstation)
  • Revoked all API keys and panel sessions, not just the password
  • Filed tickets with Contabo and Vultr (secondary DNS) using their verified support portals
  • Restored from offsite backups to InterServer, not back to the compromised account
  • Enabled TOTP everywhere that supported it; hardware keys where possible
The email came from a lookalike domain with a Cyrillic 'o' in "Contabo." I should have caught that. My mail client font didn't help. I mentioned this in the OVHcloud IRC and three other people recognized the same template. Same attacker, same week. We're coordinating disclosure to the providers now so they can warn other users.

Have you tried restarting it?
#2

That cyrillic trick is ancient haha I saw the same thing back in 2014 with a fake cpanel notice the "verify license" link classic to be fair though Contabo should be signing these emails with dkim or something right in my experience the budget hosts never do I had a client fall for the exact same template last month pointed them at Hetzner instead lost a weekend fixing dns haha you did the live usb thing though that's proper paranoid respect

#3

I believe the same campaign hit two clients on my HostHatch reseller account in Singapore last Tuesday. The timing aligns. I did not connect it until now.

I have forwarded my logs to wendy's coordination thread. The Asia-Pacific delivery was slightly different—claimed "data sovereignty migration" rather than server migration—but the credential harvest page was identical.

Thank you for raising this. I should have reported it myself.

conbini > datacenter snacks
#4

Contabo and Vultr and OVHcloud all got hit? Same attacker? Coordinated disclosure?

This is what I am talking about! Community defense! Nobody trusts the email! Verify through ticket system only! Mark my words! The lookalike domains are getting better! Check the certificate chain! Check the registrar! If it is not HostPeers's Encrypt with a 90-day expiry be suspicious! 💀

Wendy you did the live USB! Proper opsec! I am stealing that checklist! Excellent work!

#5

Same thing happened to my friend on Vultr last month. Awful.

#6

Are we sure it's the same attacker across all three providers?

your margin is my opportunity
#7
RAJ said:
Are we sure it's the same attacker across all three providers?

Not necessarily the same crew but same kit for sure. The credential harvest page kenji3 described is identical down to the CSS class names. You can buy that template. What worries me more is the DKIM alignment—Contabo's legit notices don't pass consistently either, so even if you check headers you're not sure what's real. Budget hosts treat transactional mail as an afterthought.

#8
cpanelliw780 said:
Same kit for sure

I run a small reseller operation in Mumbai. I see three, four of these a month now. The "data sovereignty" angle is smart for APAC because of India's data localization rules. Customers panic and click. I have started adding a footer to all my own client emails saying "we will never ask for your panel password" but I am not sure anyone reads it.

your margin is my opportunity
4 #9
RAJ said:
Are we sure it's the same attacker across all three providers?

I am not sure and I did not mean to imply it. What I know: the domain that got me was contabohosting-migration.com, registered three days before the email, Namecheap, Cloudflare proxy. The phishing site pulled real assets from Contabo's CDN so it looked right. I reported it to Namecheap abuse but it was still up when I last checked.

My InterServer restore went fine by the way. Took six hours from ticket to working VPS. Their Secaucus latency to my Manchester users is worse than Contabo's London but I will take it.

Have you tried restarting it?
#10

The live USB thing is not paranoid, it is baseline. If your normal workstation is compromised, changing passwords from it just gives the attacker the new password. Wendy did it right.

For the backup side: ZFS send to a separate pool on a different host, different provider, different continent. I replicate to Hetzner Helsinki from Denver every six hours. Cost me 4.51 EUR for the storage box. Worth it.

zfs send | zfs receive. repeat.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft