Close Menu
  • Crypto News
  • Markets
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Technology
  • More
    • Crypto Prices – Latest from BTC, ETH & XRP
    • NFT
    • DeFi

Subscribe to Updates

Get the latest crypto news and updates directly to your inbox.

Trending

Pundit Reveals The Two Things That Will Drive XRP Price To All-Time Highs

July 11, 2025

First-ever pro-crypto U.S. administration: bummer or slowburner?

July 11, 2025
How to Day Trade Crypto Using ChatGPT and Grok

How to Day Trade Crypto Using ChatGPT and Grok

July 11, 2025

Trump crypto holdings edge higher as WLFI pushes for open trading

July 11, 2025

Does Hester Peirce’s statement help to advance the stocks’ tokenization trend?

July 11, 2025
Facebook X (Twitter) Instagram
  • Advertise
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianoru Русскийes Españolzh-CN 简体中文hi हिन्दीja 日本語
Crypto Observer
  • Crypto News

    Pundit Reveals The Two Things That Will Drive XRP Price To All-Time Highs

    July 11, 2025

    XRP Breaks Free With Double-Digit Gains — Flips USDT in Market Shake-Up

    July 11, 2025

    Analyst Sounds The Alarm: Shiba Inu Primed For Over 1,500% Breakout

    July 11, 2025

    Bitcoin Breaks ATH, Hayes Flips Bullish: ‘Maelstrom Is Backing Up the Truck’

    July 11, 2025

    SUI Explodes Higher, Climbing Above 20-Day MA — But Can The Rally Hold?

    July 11, 2025
  • Markets
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Technology
  • More
    • Crypto Prices – Latest from BTC, ETH & XRP
    • NFT
    • DeFi
Facebook X (Twitter) Instagram
Crypto Observer
Home » Bitcoin » Darktrace warns of social engineering scams deploying crypto-stealing malware
Bitcoin

Darktrace warns of social engineering scams deploying crypto-stealing malware

Crypto Observer StaffBy Crypto Observer StaffJuly 11, 2025No Comments3 Mins Read
Facebook Twitter Pinterest Reddit Telegram Email LinkedIn Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers at cybersecurity company Darktrace have warned that threat actors are using increasingly sophisticated social engineering tactics to infect victims with crypto-stealing malware.

In its latest blog, Darktrace researchers detailed an elaborate campaign in which scammers were found to be impersonating AI, gaming, and Web3 startups to trick users into downloading malicious software.

The scheme relies on verified and compromised X accounts, as well as project documentation hosted on legitimate platforms, to create an illusion of legitimacy.

According to the report, the campaign usually begins with impersonators reaching out to potential victims on X, Telegram, or Discord. Posing as representatives of emerging startups, they offer incentives such as cryptocurrency payments in exchange for testing software.

Victims are then directed to polished company websites designed to mimic legitimate startups, complete with whitepapers, roadmaps, GitHub entries, and even fake merchandise stores.

Once a target downloads the malicious application, a Cloudflare verification screen appears, during which the malware quietly collects system information such as CPU details, MAC address, and user ID. This information, along with a CAPTCHA token, is sent to the attacker’s server to determine whether the system is a viable target.

If the verification succeeds, a second-stage payload, typically an info-stealer, is stealthily delivered, which then extracts sensitive data, including cryptocurrency wallet credentials.

Both Windows and macOS versions of the malware have been detected, with some Windows variants known to be using code-signing certificates stolen from legitimate companies.

According to Darktrace, the campaign resembles tactics used by “traffer” groups, which are cybercriminal networks that specialize in generating malware installs through deceptive content and social media manipulation.

While the threat actors remain unidentified, researchers believe the methods used are consistent with those seen in campaigns attributed to CrazyEvil, a group known for targeting crypto-related communities.

“CrazyEvil and their sub teams create fake software companies, similar to the ones described in this blog, making use of Twitter and Medium to target victims,” Darktrace wrote, adding that the group is estimated to have made “millions of dollars in revenue from their malicious activity.”

A recurring threat

Similar malware campaigns have been detected on multiple occasions throughout this year, with one North Korea-linked operation found to be using fake Zoom updates to compromise macOS devices at crypto firms.

Attackers were reportedly deploying a new malware strain dubbed “NimDoor,” delivered through a malicious SDK update. The multi-stage payload was designed to extract wallet credentials, browser data, and encrypted Telegram files while maintaining persistence on the system.

In another instance, the infamous North Korean hacking group Lazarus was found to be posing as recruiters to target unsuspecting professionals using a new malware strain called “OtterCookie,” which was deployed during fake interview sessions.

Earlier this year, a separate study by blockchain forensic firm Merkle Science found that social engineering scams were mostly targeting celebrities and tech leaders through hacked X accounts.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

First-ever pro-crypto U.S. administration: bummer or slowburner?

July 11, 2025

Ripple CTO Debunks Satoshi Hack Theories After $8.6B BTC Transfer

July 11, 2025

‘This Could Very Well Be the Ultimate Bull Trap’ – Trader Issues Urgent Crypto Warning As Bitcoin Blasts Past $118,000

July 11, 2025

GMX hacker returns stolen funds after bounty negotiation 

July 11, 2025
Add A Comment

Leave A Reply Cancel Reply

Subscribe to Updates

Get the latest crypto news and updates directly to your inbox.

Top Posts

Pundit Reveals The Two Things That Will Drive XRP Price To All-Time Highs

July 11, 2025

First-ever pro-crypto U.S. administration: bummer or slowburner?

July 11, 2025
How to Day Trade Crypto Using ChatGPT and Grok

How to Day Trade Crypto Using ChatGPT and Grok

July 11, 2025
Advertisement
Demo

Crypto Observer is your one-stop website for the latest crypto news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Instagram
Crypto News

XRP Breaks Free With Double-Digit Gains — Flips USDT in Market Shake-Up

July 11, 2025

Analyst Sounds The Alarm: Shiba Inu Primed For Over 1,500% Breakout

July 11, 2025

Bitcoin Breaks ATH, Hayes Flips Bullish: ‘Maelstrom Is Backing Up the Truck’

July 11, 2025
Get Informed

Subscribe to Updates

Get the latest crypto news and updates directly to your inbox.

Facebook X (Twitter)
  • Privacy Policy
  • Terms of use
  • Advertise with us | Publishing
  • Contact us
  • Crypto News – Press release
  • Newsletter sign up
  • Markets
  • Altcoins
  • Bitcoin
  • Crypto News
  • DeFi
  • Ethereum
  • Technology
  • Blockchain
  • AI
  • NFT
  • Thanks for joining us
© 2025 Crypto Observer. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.