Crypto-stealing scam targets Web3 workers with fake meeting apps

Web3 workers are being targeted by a campaign that uses fake meeting apps to inject malware and steal credentials to websites, apps and crypto wallets, Cado Security Labs warned.

Scammers have been using artificial intelligence to generate and fill out websites and social media accounts to appear as legitimate companies before contacting potential targets to prompt them to download a meeting app, Cado’s threat research lead Tara Gould wrote in a Dec. 6 report.

The app is called “Meeten” but it’s currently going by the name “Meetio” and regularly changes names. In the past, it has used Clusee.com, Cuesee, Meeten.gg, Meeten.us and Meetone.gg.

The app contains a Realst info stealer and, once downloaded, will hunt for sensitive items such as a Telegram login, banking card details and information on crypto wallets to send back to the attackers.

Security, Malware, Hackers, Cybercrime, Cybersecurity, Web3

Source: Cado Security Labs 

The stealer can also search for browser cookies and autofill credentials from applications like Google Chrome and Mircosoft Edge, along with info on Ledger, Trezor and Binance Wallets.

The scheme can involve social engineering and spoofing. One user reported being contacted on Telegram by someone they knew who wanted to discuss a business opportunity, which was later outed as an impersonator.

“Even more interestingly, the scammer sent an investment presentation from the target’s company to him, indicating a sophisticated and targeted scam,” Gould said.  

Others had reported “being on calls related to Web3 work, downloading the software and having their cryptocurrency stolen,” Gould added.

Security, Malware, Hackers, Cybercrime, Cybersecurity, Web3

The fake meeting app cycles through names alongside a site filled with AI-generated content to appear more legitimate. Source: Cado Security Labs

To help gain credibility, the scammers set up a company website with AI-generated blogs, product content and accompanying social media accounts, including X and Medium.

“While much of the recent focus has been on the potential of AI to create malware, threat actors are increasingly using AI to generate content for their campaigns,” Gould said.

“Using AI enables threat actors to quickly create realistic website content that adds legitimacy to their scams and makes it more difficult to detect suspicious websites.” 

The fake websites where users are prompted to download the malware-riddled software also contain Javascript to steal crypto stored in web browsers, even before installing any malware.

Related: Crypto phishing scams to rise during holiday shopping season — Cyvers

The scammers created both a macOS and Windows variant. Gould says the scheme has been active for about four months.

Other scammers have also been actively using these tactics. In August, onchain sleuth ZackXBT said he found 21 developers, alleged to be North Koreans, working on various crypto projects using fake identities.

In September, the FBI issued a warning about North Korean hackers targeting crypto companies and decentralized finance projects with malware disguised as an employment offer. 

Magazine: BTC hits $100K, Trump taps Paul Atkins for SEC chair, and more: Hodler’s  Digest, Dec. 1 – 7

Related Posts

Decentralization democratizes access to AI computing — Theta Labs exec

The artificial intelligence sector has exploded and seems to show no signs of slowing down. However, most companies and projects utilize centralized services such as Amazon Web Services (AWS) for…

Microsoft touts next-gen data centers that don’t consume water for cooling

Microsoft Corp. has unveiled a new data center design that consumes no water to cool the chips and servers at a facility, which could save millions of liters of water…

Leave a Reply

Your email address will not be published. Required fields are marked *