FreeDrain is a large-scale cryptocurrency phishing operation active since at least 2022 that targets users searching for wallet-related information and services. The operation is focused on stealing wallet seed phrases and rapidly draining victims’ digital assets. It has been assessed with high confidence as a financially motivated cybercriminal campaign, and available timing and metadata evidence indicates the operators likely work from India in the UTC+05:30 timezone during standard weekday business hours. FreeDrain relies on search-engine optimization manipulation and spamdexing to place malicious lure pages prominently in search results for cryptocurrency wallet queries. The operation abuses trusted free-tier and low-friction publishing platforms to host large volumes of lure content, then funnels victims through layered redirect chains to phishing pages that impersonate legitimate wallet interfaces such as Trezor, MetaMask, and Ledger. Researchers identified more than 38,000 distinct lure-page subdomains across numerous platforms, indicating an industrialized and resilient infrastructure with rapid churn and scalable deployment. The campaign uses extensive content variation and appears to leverage generative AI to produce lure-page text at scale, helping evade simple pattern-based detection and accelerate page creation. Some lure pages were observed as initially benign before later being modified to introduce malicious redirects, further complicating detection and takedown. Redirector infrastructure uses algorithmically generated naming patterns and may be shared with or leased to other actors, suggesting a modular operational model. Final phishing stages are commonly hosted on major cloud services and use straightforward web forms or asynchronous requests to capture seed phrases for exfiltration. In some cases, phishing pages included live chat functionality with human operators responding in real time, indicating active victim engagement beyond static credential harvesting. FreeDrain’s tradecraft combines reconnaissance of user search behavior, initial access through search-result poisoning, spoofing of legitimate wallet brands, credential theft in the form of seed-phrase harvesting, and exfiltration of stolen wallet data for subsequent crypto theft. FreeDrain is notable for industrializing cryptocurrency theft through abuse of legitimate infrastructure rather than bespoke malware. Its persistence has been aided by weak abuse-reporting and moderation controls on hosting platforms, and the operation remains an ongoing threat to the cryptocurrency ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Industrial-scale cryptocurrency phishing operation using SEO manipulation and large volumes of subdomains to steal wallet seed phrases.
A criminal operation specializing in industrial-scale cryptocurrency phishing, using SEO manipulation and thousands of malicious subdomains on free-tier publishing platforms to steal digital assets.
Large-scale financially motivated cryptocurrency phishing operation that uses SEO poisoning/spamdexing, lure pages on trusted free-tier publishing platforms, layered redirectors, and cloned wallet phishing pages to steal seed phrases and drain victims' wallets.
FreeDrain is a financially motivated threat actor group operating a large-scale cryptocurrency phishing campaign. They weaponize search engine optimization, free-tier web services, and layered redirection techniques to systematically target and drain cryptocurrency wallets at scale. Their infrastructure leverages thousands of lure pages on reputable platforms, redirectors, and phishing sites to harvest wallet seed phrases and steal digital assets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.