Rising Threat of Malware Targeting Cryptocurrency Users
Introduction: A Sophisticated Scam
Cryptocurrency holders are currently facing an escalating social engineering campaign designed to siphon off their digital assets. This scheme involves deceptive startup companies that lure users into downloading malicious software capable of draining funds from both Windows and macOS systems. The complexity and persistence of this attack make it a pressing issue for those in the crypto space.
The Scam Unveiled
According to Tara Gould, a researcher at Darktrace, the deceptive campaign cleverly mimics businesses in the realms of artificial intelligence, gaming, and Web3 sectors. The attackers utilize fake social media profiles and project documentation hosted on recognized platforms like Notion and GitHub. This inconsistency allows victims to trust these fraudulent entities, inadvertently leading them into a trap.
This isn’t the first instance of such deceit. A similar con was observed back in December 2024, where fake video conferencing platforms invited targets to ‘discuss investment opportunities.’ These schemes generally initiated contact via messaging apps such as Telegram, enticing victims to unwittingly download infective software.
Meeten: A Case Study
Cado Security, now part of Darktrace, codenamed this particular operation "Meeten," after one of the vacuous video conferencing applications used in the fraud. Evidence suggests that this malicious activity may have originated as early as March 2024, when Jamf Threat Labs found a domain named "meethub[.]gg," which disseminated the Realst malware.
Current Campaign Dynamics
Recent insights from Darktrace reveal that this threat is not only ongoing but has also expanded its range of deceptive strategies. The attackers now employ themes centered around artificial intelligence, gaming, and social media, continuously adapting their methods to stay relevant.
Moreover, compromised accounts on X (formerly Twitter) belonging to legitimate companies and verified individuals have been exploited to enhance the authenticity of these fictitious firms. Gould emphasized, "They utilize popular sites frequented by software companies, which makes their offerings look professional and reliable."
The Illusion of Legitimacy
One striking example of these fake entities is Eternal Decay (@metaversedecay), which falsely claims to be a game using blockchain technology. The company goes so far as to digitally manipulate photographs to imply that they are presenting at various conferences. This strategy aims to construct a façade of legitimacy that increases the chances of victims engaging and eventually downloading malware.
List of Identified Fraudulent Companies
Several other fictitious companies have emerged in this ongoing scam. They include:
- BeeSync (@BeeSyncAI, @AIBeeSync)
- Buzzu (@BuzzuApp, @AI_Buzzu)
- Cloudsign (@cloudsignapp)
- Dexis (@DexisApp)
- Various others, including NexLoop, Pollens AI, and Swox, each with multiple social media handles.
Attack Mechanism: Step-by-Step
The attack operation typically begins when one of these adversary-controlled accounts contacts a victim via X, Telegram, or Discord, inviting them to try out their software for a cryptocurrency reward. If the target expresses interest, they are redirected to a fake website where they’re prompted to enter a registration code before downloading software.
The Windows Approach
When the target downloads the malicious application for Windows, they encounter a fake Cloudflare verification screen while the malware covertly gathers information about the system. It then deploys an installer, believed to execute an information stealer.
Targeting macOS Systems
For macOS users, the approach is somewhat different. The malicious software installs the Atomic macOS Stealer (AMOS), an established information-stealing malware designed to extract sensitive documents, browser data, and cryptocurrency wallet information, sending it to external servers. The DMG binary also contains a shell script aimed at ensuring the malware persists in the system, launching at user login.
The Bigger Picture
Darktrace’s findings also draw parallels between this ongoing campaign and methods used by a group known as Crazy Evil. This notorious band of attackers is adept at tricking victims into downloading various forms of malware. While it remains unclear if there’s a direct connection, the operational styles show significant similarities.
Gould adds, “This campaign underscores the lengths threat actors will go to fabricate legitimacy for their fake companies to successfully steal cryptocurrency from their victims, utilizing increasingly sophisticated malware strategies.”
Conclusion
As cryptocurrency continues to gain traction, the prevalence of targeted scams highlights the need for heightened security awareness among users. Practicing caution when engaging with unfamiliar platforms and scrutinizing the authenticity of communication can serve as effective preventive measures against these evolving threats.


