# damus.network — MALICIOUS — Crypto Drainer (Angel Drainer) > damus.network impersonates a Damus crypto airdrop to steal funds. Avoid this site and never share wallet keys or private info if prompted. ## Summary PhishDestroy identifies damus.network as a medium-risk crypto drainer domain impersonating a Damus Airdrop service. This site tricks users into revealing private wallet credentials or signing malicious transactions, risking the theft of cryptocurrency assets. The phishing attack uses a fake airdrop page titled "Damus Airdrop | Phase 1" to lure victims, exploiting interest in crypto giveaways. It uses the Angel Drainer toolkit to harvest wallet keys and drain funds. The domain was taken offline but appeared on multiple blocklists and was flagged by several security vendors. If you visited damus.network, immediately cease any interaction with the site. Do not enter wallet keys or approve transactions. Scan your devices for malware and consider transferring assets to a new wallet with fresh credentials. Stay vigilant and verify any airdrop offers through official channels only. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Angel Drainer) - Site status: dead (HTTP 403) - Drainer type: Angel Drainer - Scam type: Airdrop Scam - Kit: Airdrop Scam - Page title: Damus Airdrop | Phase 1 ## Domain Intelligence - Registered: 2025-12-18 00:00:00 - Expires: 2026-12-18 00:00:00 - Registrar: Name.com, Inc - Country: US - IP: 185.107.74.191 - IP Country: SE - IP City: Stockholm - IP Org: AS200430 WEBO LLC - Nameservers: ns1crv.name.com ns2dqr.name.com ns3gxy.name.com ns4cfn.name.com - SSL Issuer: none ## Detection Status - VirusTotal: 4 vendors flagged Vendors: ["alphaMountain.ai", "Certego", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 4 hits Lists: ["PhishDestroy", "MetaMask", "ScamSniffer", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019b60a0-c03c-754e-9f82-a9d2f0a16635.png - Cloudflare Radar: https://radar.cloudflare.com/scan/2b83b228-9cf8-4341-a54d-83ad8d4a6100 - PhishDestroy: https://phishdestroy.io/domain/damus.network/ - LLM endpoint: https://phishdestroy.io/domain/damus.network/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/damus.network/ Last updated: 2026-03-19