2 Sources
[1]
Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
Cryptocurrency users are the target of an ongoing social engineering campaign that employs fake startup companies to trick users into downloading malware that can drain digital assets from both Windows and macOS systems. "These malicious operations impersonate AI, gaming, and Web3 firms using
[2]
Threat actors using 'elaborate social engineering scheme' to target crypto users -- Report
Social engineering scams, from the Meeten campaign to fake crypto support scams, have become a troubling occurrence in crypto. Threat actors are using an elaborate social engineering scheme to target crypto users and drain their wallets, according to a Thursday report from cybersecurity company
Share
Copy Link
A complex social engineering scheme is targeting cryptocurrency users by impersonating AI, gaming, and Web3 startups, using compromised social media accounts and malware to steal digital assets.
Cybersecurity researchers have uncovered an ongoing sophisticated social engineering campaign targeting cryptocurrency users. The scheme, which impersonates AI, gaming, and Web3 firms, aims to trick victims into downloading malware that can drain digital assets from both Windows and macOS systems
1
.
Source: Hacker News
The attackers employ a range of deceptive tactics to lend credibility to their fake startups:
One such fictitious company, Eternal Decay (@metaversedecay), claims to be a blockchain-powered game and has shared digitally altered images on X to create the illusion of conference presentations
1
.The attack chain typically begins with the threat actors contacting potential victims through X messages, Telegram, or Discord. They offer cryptocurrency payments in exchange for testing their software
2
.Upon agreement, victims are directed to a fake website where they're prompted to enter a registration code to download either a Windows Electron application or an Apple disk image (DMG) file
1
.On Windows systems, the malicious application displays a Cloudflare verification screen while covertly profiling the machine and downloading an MSI installer. The exact nature of the payload remains unclear, but it's suspected to be an information stealer
1
.For macOS, the attack deploys the Atomic macOS Stealer (AMOS), which can exfiltrate documents, web browser data, and crypto wallet information. The malware also establishes persistence using a Launch Agent and monitors user activity
1
.Related Stories
This campaign shares similarities with the Meeten campaign observed in December 2024, which used fake videoconferencing platforms to infect victims with stealer malware like Realst
1
.Darktrace researchers have noted tactical similarities with campaigns orchestrated by a traffers group called Crazy Evil, known for distributing malware such as StealC, AMOS, and Angel Drainer
1
.The cryptocurrency industry continues to grapple with various scams and frauds, including "pig butchering" scams and "four-dollar wrench attacks." The sophistication of these attacks has increased, often leveraging social engineering, hacked social media accounts, and insider fraud
2
.As the threat landscape evolves, users are advised to remain vigilant and skeptical of unsolicited offers or requests to test new software, especially when cryptocurrency payments are involved. The incident underscores the need for robust security measures and user education in the rapidly changing world of digital assets and blockchain technology.
Summarized by
Navi
[1]
10 Dec 2024•Technology

10 Feb 2026•Technology

10 Jun 2025•Technology
