CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
Invezz 2024-12-27 11:21:17

Hackers use fake Zoom links to target crypto users, steal $1M: report

A sophisticated phishing scam targeting cryptocurrency users has been uncovered, exploiting fake Zoom meeting links to distribute malware and steal assets. The operation, exposed by blockchain security firm SlowMist , saw hackers mimicking Zoom’s platform to compromise sensitive information, including private keys and wallet credentials. This malicious campaign, active since November 2024, has resulted in significant financial losses, with over $1 million traced to a hacker’s Ethereum wallet. The attackers utilised advanced malware and obfuscation techniques, emphasising the growing risk of cyber threats in the crypto industry. Fake Zoom links deployed to steal cryptocurrency Hackers used a phishing domain, “app[.]us4zoom[.]us,” designed to replicate Zoom’s interface. Victims were deceived into clicking a “Launch Meeting” button that initiated a malicious download instead of launching the application. The fake installer, “ZoomApp_v.3.14.dmg,” executed a script named “ZoomApp.file,” prompting users to enter their system passwords. Upon execution, the script deployed a hidden executable file, “.ZoomApp,” which attempted to access sensitive information, including browser cookies, KeyChain data, and cryptocurrency wallet credentials. This data was compressed and transmitted to a malicious server associated with an IP flagged by multiple threat intelligence services. Further investigation revealed that the malware targeted high-value assets by focusing on users likely to hold significant cryptocurrency balances. The attackers used a combination of social engineering and advanced coding techniques to bypass security protocols, making the scam harder to detect. Their ability to impersonate a trusted platform like Zoom demonstrates the growing sophistication of phishing operations. The malware, identified as a Trojan, underwent static and dynamic analysis. It showed capabilities to decrypt data, extract system credentials, and access private keys and wallet mnemonics. These actions enabled the theft of cryptocurrency from victims, with attackers allegedly utilising Russian-language scripts and a back-end system located in the Netherlands. On-chain tracking reveals stolen Ethereum SlowMist employed its anti-money laundering tool, MistTrack, to trace stolen cryptocurrency. Over $1 million in digital assets, including Ethereum (ETH), USD0++, and MORPHO, was transferred across platforms such as Binance, Gate.io, and Bybit. One hacker’s address consolidated 296 ETH, which was further distributed to multiple platforms. Another wallet linked to the scam executed small ETH transactions to nearly 8,800 addresses, covering transaction fees. These stolen funds were subsequently aggregated and converted into Tether (USDT) and other cryptocurrencies via exchanges like FixedFloat and Binance. How does this affect crypto security? This phishing campaign underscores the increasing sophistication of cyberattacks targeting cryptocurrency users. Exploiting popular platforms like Zoom, attackers leveraged advanced techniques to steal private information and assets. The incident highlights the need for heightened vigilance, robust security protocols, and user education to prevent further exploitation in the rapidly evolving digital asset space. Governments and crypto exchanges are being urged to enhance their fraud detection measures and develop stronger countermeasures to combat such attacks. This includes raising awareness among users about recognising phishing schemes and adopting multi-factor authentication to secure their wallets. The post Hackers use fake Zoom links to target crypto users, steal $1M: report appeared first on Invezz

阅读免责声明 : 此处提供的所有内容我们的网站,超链接网站,相关应用程序,论坛,博客,社交媒体帐户和其他平台(“网站”)仅供您提供一般信息,从第三方采购。 我们不对与我们的内容有任何形式的保证,包括但不限于准确性和更新性。 我们提供的内容中没有任何内容构成财务建议,法律建议或任何其他形式的建议,以满足您对任何目的的特定依赖。 任何使用或依赖我们的内容完全由您自行承担风险和自由裁量权。 在依赖它们之前,您应该进行自己的研究,审查,分析和验证我们的内容。 交易是一项高风险的活动,可能导致重大损失,因此请在做出任何决定之前咨询您的财务顾问。 我们网站上的任何内容均不构成招揽或要约