Architectural Concept Design Collection

  • CONTACT
  • MARKETCAP
  • BLOG
Finances Investing and Crypto News
  • BOOKMARKS
  • Finance
  • Investment
  • Crypto
    • Bitcoin
    • Blockchain
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Mining
    • NFT
    • Stocks
Reading: Darktrace warns of social engineering scams deploying crypto-stealing malware
Share
  • bitcoinBitcoin(BTC)$117,321.32
  • ethereumEthereum(ETH)$2,937.77
  • rippleXRP(XRP)$2.73
  • tetherTether USDt(USDT)$1.00
  • binancecoinBNB(BNB)$684.89
  • solanaSolana(SOL)$160.18
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.196430
  • tronTRON(TRX)$0.302436
  • cardanoCardano(ADA)$0.71
Finances Investing and Crypto NewsFinances Investing and Crypto News
0
Font ResizerAa
  • Finance
  • Investment
  • Crypto
  • Market
  • News
Search
  • Finance
  • Investment
  • Crypto
    • Bitcoin
    • Blockchain
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Finances Investing and Crypto News > Blog > Crypto > Blockchain > Darktrace warns of social engineering scams deploying crypto-stealing malware
BlockchainCrypto

Darktrace warns of social engineering scams deploying crypto-stealing malware

admin
Last updated: 11/07/2025 4:13 Chiều
admin
Published 11/07/2025
Share


Researchers at cybersecurity company Darktrace have warned that threat actors are using increasingly sophisticated social engineering tactics to infect victims with crypto-stealing malware.

In its latest blog, Darktrace researchers detailed an elaborate campaign in which scammers were found to be impersonating AI, gaming, and Web3 startups to trick users into downloading malicious software.

The scheme relies on verified and compromised X accounts, as well as project documentation hosted on legitimate platforms, to create an illusion of legitimacy.

According to the report, the campaign usually begins with impersonators reaching out to potential victims on X, Telegram, or Discord. Posing as representatives of emerging startups, they offer incentives such as cryptocurrency payments in exchange for testing software.

Victims are then directed to polished company websites designed to mimic legitimate startups, complete with whitepapers, roadmaps, GitHub entries, and even fake merchandise stores.

Once a target downloads the malicious application, a Cloudflare verification screen appears, during which the malware quietly collects system information such as CPU details, MAC address, and user ID. This information, along with a CAPTCHA token, is sent to the attacker’s server to determine whether the system is a viable target.

If the verification succeeds, a second-stage payload, typically an info-stealer, is stealthily delivered, which then extracts sensitive data, including cryptocurrency wallet credentials.

Both Windows and macOS versions of the malware have been detected, with some Windows variants known to be using code-signing certificates stolen from legitimate companies.

According to Darktrace, the campaign resembles tactics used by “traffer” groups, which are cybercriminal networks that specialize in generating malware installs through deceptive content and social media manipulation.

While the threat actors remain unidentified, researchers believe the methods used are consistent with those seen in campaigns attributed to CrazyEvil, a group known for targeting crypto-related communities.

“CrazyEvil and their sub teams create fake software companies, similar to the ones described in this blog, making use of Twitter and Medium to target victims,” Darktrace wrote, adding that the group is estimated to have made “millions of dollars in revenue from their malicious activity.”

A recurring threat

Similar malware campaigns have been detected on multiple occasions throughout this year, with one North Korea-linked operation found to be using fake Zoom updates to compromise macOS devices at crypto firms.

Attackers were reportedly deploying a new malware strain dubbed “NimDoor,” delivered through a malicious SDK update. The multi-stage payload was designed to extract wallet credentials, browser data, and encrypted Telegram files while maintaining persistence on the system.

In another instance, the infamous North Korean hacking group Lazarus was found to be posing as recruiters to target unsuspecting professionals using a new malware strain called “OtterCookie,” which was deployed during fake interview sessions.

Earlier this year, a separate study by blockchain forensic firm Merkle Science found that social engineering scams were mostly targeting celebrities and tech leaders through hacked X accounts.

You Might Also Like

Connecticut bans state use and investment in crypto under sweeping new law

Bitcoin is deep into its bull run, here’s what comes next: analyst

OpenSeabuys Rally Wallet to expand mobile and token trading

$300,000 Bitcoin calls and a fading $85,000 put wall — is the market preparing for something explosive?

Dow Jones loses 100 points as markets eye Trump’s tariff moves

TAGGED:cryptostealingDarktracedeployingengineeringmalwarescamsSocialwarns

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article BNB edges toward key resistance as 1.59 token burn fuel bullish momentum
Next Article PUMP token perpetual contracts hit $120m in open interests ahead of launch day
Leave a Comment

Để lại một bình luận Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Follow US

Find US on Socials
FacebookLike
- Advertisement -
Ad image
Popular News
Memecoin platform Pump.fun raises $600 million in 12 minutes
Emergency Funds: Importance and How to Build One
Debt Management: Strategies to Pay Off Debt Efficiently
Riot Platforms unloads 475 BTC in its biggest single-month Bitcoin sale to date
Revolut partners with Lightspark to add Bitcoin Lightning for UK and EEA users
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Finances Investing and Crypto News

FICN.net brings you the latest in finance, investment, and crypto. Stay informed with expert insights, market analysis, and beginner guides. Whether you're new or experienced, FICN.net helps you explore opportunities, manage risks, and make smarter financial decisions in a fast-changing world.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© 2024 Finance, Investment, and Crypto News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?