Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bitcoin’s breakout isn’t about the Fed, it’s about market structure: analysts

    July 11, 2025

    Banana Gun Bot Sniper — How To Easily Snipe Token Launches On ETH, Base or Blast (July 2025)

    July 11, 2025

    BullX Tron — Telegram Trading Bot for TRON (TRX) – Try NOW! (July 2025)

    July 11, 2025
    Facebook X (Twitter) Instagram
    Cryptify Now
    • Home
    • Features
      • Typography
      • Contact
      • View All On Demos
    • Typography
    • Buy Now
    X (Twitter) Instagram YouTube LinkedIn
    Cryptify Now
    You are at:Home » Darktrace warns of social engineering scams deploying crypto-stealing malware
    Crypto

    Darktrace warns of social engineering scams deploying crypto-stealing malware

    James WilsonBy James WilsonJuly 11, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Researchers at cybersecurity company Darktrace have warned that threat actors are using increasingly sophisticated social engineering tactics to infect victims with crypto-stealing malware.

    In its latest blog, Darktrace researchers detailed an elaborate campaign in which scammers were found to be impersonating AI, gaming, and Web3 startups to trick users into downloading malicious software.

    The scheme relies on verified and compromised X accounts, as well as project documentation hosted on legitimate platforms, to create an illusion of legitimacy.

    According to the report, the campaign usually begins with impersonators reaching out to potential victims on X, Telegram, or Discord. Posing as representatives of emerging startups, they offer incentives such as cryptocurrency payments in exchange for testing software.

    Victims are then directed to polished company websites designed to mimic legitimate startups, complete with whitepapers, roadmaps, GitHub entries, and even fake merchandise stores.

    Once a target downloads the malicious application, a Cloudflare verification screen appears, during which the malware quietly collects system information such as CPU details, MAC address, and user ID. This information, along with a CAPTCHA token, is sent to the attacker’s server to determine whether the system is a viable target.

    If the verification succeeds, a second-stage payload, typically an info-stealer, is stealthily delivered, which then extracts sensitive data, including cryptocurrency wallet credentials.

    Both Windows and macOS versions of the malware have been detected, with some Windows variants known to be using code-signing certificates stolen from legitimate companies.

    According to Darktrace, the campaign resembles tactics used by “traffer” groups, which are cybercriminal networks that specialize in generating malware installs through deceptive content and social media manipulation.

    While the threat actors remain unidentified, researchers believe the methods used are consistent with those seen in campaigns attributed to CrazyEvil, a group known for targeting crypto-related communities.

    “CrazyEvil and their sub teams create fake software companies, similar to the ones described in this blog, making use of Twitter and Medium to target victims,” Darktrace wrote, adding that the group is estimated to have made “millions of dollars in revenue from their malicious activity.”

    A recurring threat

    Similar malware campaigns have been detected on multiple occasions throughout this year, with one North Korea-linked operation found to be using fake Zoom updates to compromise macOS devices at crypto firms.

    Attackers were reportedly deploying a new malware strain dubbed “NimDoor,” delivered through a malicious SDK update. The multi-stage payload was designed to extract wallet credentials, browser data, and encrypted Telegram files while maintaining persistence on the system.

    In another instance, the infamous North Korean hacking group Lazarus was found to be posing as recruiters to target unsuspecting professionals using a new malware strain called “OtterCookie,” which was deployed during fake interview sessions.

    Earlier this year, a separate study by blockchain forensic firm Merkle Science found that social engineering scams were mostly targeting celebrities and tech leaders through hacked X accounts.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleJust another day in DeFi: A hack, a rug-pull, and $10M saved
    Next Article Robinhood hit with second probe over misleading crypto marketing
    James Wilson

    Related Posts

    Bitcoin’s breakout isn’t about the Fed, it’s about market structure: analysts

    July 11, 2025

    Banana Gun Bot Sniper — How To Easily Snipe Token Launches On ETH, Base or Blast (July 2025)

    July 11, 2025

    BullX Tron — Telegram Trading Bot for TRON (TRX) – Try NOW! (July 2025)

    July 11, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Remittix (RTX) hits $4m presale as XRP holders take notice

    February 4, 2025

    Here’s why OKB price spiked 20% today

    February 4, 2025

    iDEGEN price prediction: Is this the AI agent token to buy?

    February 4, 2025

    Gate.io to list CYBRO token on Dec 14 after $7M presale success

    February 4, 2025
    Don't Miss

    Bitcoin’s breakout isn’t about the Fed, it’s about market structure: analysts

    By James WilsonJuly 11, 2025

    Bitcoin’s record-breaking climb past $118,000 isn’t tied to Fed policy or equities. Instead, analysts say…

    Banana Gun Bot Sniper — How To Easily Snipe Token Launches On ETH, Base or Blast (July 2025)

    July 11, 2025

    BullX Tron — Telegram Trading Bot for TRON (TRX) – Try NOW! (July 2025)

    July 11, 2025

    NFD Base Trade Bot for BASE chain – Overview – Check NOW! (July 2025)

    July 11, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    CryptifyNow: Your daily source for the latest insights, news, and analysis in the ever-evolving world of cryptocurrency.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Bitcoin’s breakout isn’t about the Fed, it’s about market structure: analysts

    July 11, 2025

    Banana Gun Bot Sniper — How To Easily Snipe Token Launches On ETH, Base or Blast (July 2025)

    July 11, 2025

    BullX Tron — Telegram Trading Bot for TRON (TRX) – Try NOW! (July 2025)

    July 11, 2025
    Lithosphere News Releases

    Colle AI’s iOS App Launch Brings Multichain NFT Creation to Mobile

    February 4, 2025

    AGII Transforms Web3 Infrastructure with AI-Optimized Smart Contracts

    February 4, 2025

    Colle AI (COLLE) Allocates $250M for AI Tool Development and Liquidity Growth on Solana

    February 4, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.