Researchers at cybersecurity company Darktrace have warned that threat actors are using increasingly sophisticated social engineering tactics to infect victims with crypto-stealing malware. In its latest blog, Darktrace researchers detailed an elaborate campaign in which scammers were found to be…Researchers at cybersecurity company Darktrace have warned that threat actors are using increasingly sophisticated social engineering tactics to infect victims with crypto-stealing malware. In its latest blog, Darktrace researchers detailed an elaborate campaign in which scammers were found to be…

Darktrace warns of social engineering scams deploying crypto-stealing malware

2025/07/11 15:56
3 min read

Researchers at cybersecurity company Darktrace have warned that threat actors are using increasingly sophisticated social engineering tactics to infect victims with crypto-stealing malware.

In its latest blog, Darktrace researchers detailed an elaborate campaign in which scammers were found to be impersonating AI, gaming, and Web3 startups to trick users into downloading malicious software.

The scheme relies on verified and compromised X accounts, as well as project documentation hosted on legitimate platforms, to create an illusion of legitimacy.

According to the report, the campaign usually begins with impersonators reaching out to potential victims on X, Telegram, or Discord. Posing as representatives of emerging startups, they offer incentives such as cryptocurrency payments in exchange for testing software.

Victims are then directed to polished company websites designed to mimic legitimate startups, complete with whitepapers, roadmaps, GitHub entries, and even fake merchandise stores.

Once a target downloads the malicious application, a Cloudflare verification screen appears, during which the malware quietly collects system information such as CPU details, MAC address, and user ID. This information, along with a CAPTCHA token, is sent to the attacker’s server to determine whether the system is a viable target.

If the verification succeeds, a second-stage payload, typically an info-stealer, is stealthily delivered, which then extracts sensitive data, including cryptocurrency wallet credentials.

Both Windows and macOS versions of the malware have been detected, with some Windows variants known to be using code-signing certificates stolen from legitimate companies.

According to Darktrace, the campaign resembles tactics used by “traffer” groups, which are cybercriminal networks that specialize in generating malware installs through deceptive content and social media manipulation.

While the threat actors remain unidentified, researchers believe the methods used are consistent with those seen in campaigns attributed to CrazyEvil, a group known for targeting crypto-related communities.

“CrazyEvil and their sub teams create fake software companies, similar to the ones described in this blog, making use of Twitter and Medium to target victims,” Darktrace wrote, adding that the group is estimated to have made “millions of dollars in revenue from their malicious activity.”

A recurring threat

Similar malware campaigns have been detected on multiple occasions throughout this year, with one North Korea-linked operation found to be using fake Zoom updates to compromise macOS devices at crypto firms.

Attackers were reportedly deploying a new malware strain dubbed “NimDoor,” delivered through a malicious SDK update. The multi-stage payload was designed to extract wallet credentials, browser data, and encrypted Telegram files while maintaining persistence on the system.

In another instance, the infamous North Korean hacking group Lazarus was found to be posing as recruiters to target unsuspecting professionals using a new malware strain called “OtterCookie,” which was deployed during fake interview sessions.

Earlier this year, a separate study by blockchain forensic firm Merkle Science found that social engineering scams were mostly targeting celebrities and tech leaders through hacked X accounts.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Source7 and Oyster Data Announce Strategic Partnership to Advance Property Asset Intelligence and Data Infrastructure

Source7 and Oyster Data Announce Strategic Partnership to Advance Property Asset Intelligence and Data Infrastructure

LOUISVILLE, Ky.–(BUSINESS WIRE)–Source7, a leading provider of home appliance and systems asset intelligence, today announced a strategic data infrastructure partnership
Share
AI Journal2026/02/25 03:16
Forward Industries zet $4 miljard in om Solana bezit uit te breiden

Forward Industries zet $4 miljard in om Solana bezit uit te breiden

Forward Industries gooit het roer om met een flinke financiële zet: het bedrijf lanceert een zogeheten “At The Market” aandelenprogramma van maar liefst $4 miljard. Het programma geeft het bedrijf flexibiliteit om op elk gewenst moment aandelen te verkopen, wat vooral handig is voor het uitbreiden van hun Solana treasury... Het bericht Forward Industries zet $4 miljard in om Solana bezit uit te breiden verscheen het eerst op Blockchain Stories.
Share
Coinstats2025/09/18 01:31
China Launches Cross-Border QR Code Payment Trial

China Launches Cross-Border QR Code Payment Trial

The post China Launches Cross-Border QR Code Payment Trial appeared on BitcoinEthereumNews.com. Key Points: Main event involves China initiating a cross-border QR code payment trial. Alipay and Ant International are key participants. Impact on financial security and regulatory focus on illicit finance. China’s central bank, led by Deputy Governor Lu Lei, initiated a trial of a unified cross-border QR code payment gateway with Alipay and Ant International as participants. This pilot addresses cross-border fund risks, aiming to enhance financial security amid rising money laundering through digital channels, despite muted crypto market reactions. China’s Cross-Border Payment Gateway Trial with Alipay The trial operation of a unified cross-border QR code payment gateway marks a milestone in China’s financial landscape. Prominent entities such as Alipay and Ant International are at the forefront, participating as the initial institutions in this venture. Lu Lei, Deputy Governor of the People’s Bank of China, highlighted the systemic risks posed by increased cross-border fund flows. Changes are expected in the dynamics of digital transactions, potentially enhancing transaction efficiency while tightening regulations around illicit finance. The initiative underscores China’s commitment to bolstering financial security amidst growing global fund movements. “The scale of cross-border fund flows is expanding, and the frequency is accelerating, providing opportunities for risks such as cross-border money laundering and terrorist financing. Some overseas illegal platforms transfer funds through channels such as virtual currencies and underground banks, creating a ‘resonance’ of risks at home and abroad, posing a challenge to China’s foreign exchange management and financial security.” — Lu Lei, Deputy Governor, People’s Bank of China Bitcoin and Impact of China’s Financial Initiatives Did you know? China’s latest initiative echoes the Payment Connect project of June 2025, furthering real-time cross-boundary remittances and expanding its influence on global financial systems. As of September 17, 2025, Bitcoin (BTC) stands at $115,748.72 with a market cap of $2.31 trillion, showing a 0.97%…
Share
BitcoinEthereumNews2025/09/18 05:28