A new hack in town – Crypto users warned of phishing attacks disguised as Zoom meeting links

Source Cryptopolitan

SlowMist has brought attention to a new phishing scam targeting cryptocurrency users. The scam disguises itself as fake Zoom meetings to distribute malware that steals sensitive data. It involves counterfeit Zoom links that trick victims into downloading malicious files aimed at extracting cryptocurrency assets.

According to blockchain security platform SlowMist, the attackers behind the scam used a sophisticated phishing technique involving a domain that mimicked the legitimate Zoom domain. The phishing website, “app[.]us4zoom[.]us,” looks very similar to the genuine Zoom website interface. 

Victims are prompted to click a “Launch Meeting” button, which they expect to take them to a Zoom session. However, instead of opening the Zoom application, the button initiates the download of a malicious file titled “ZoomApp_v.3.14.dmg.”

Malware execution and data theft ploy uncovered 

Once downloaded, the malicious file triggers a script that requests the user’s system password. The script executes a hidden executable named “.ZoomApp,” which is designed to access and collect sensitive system information, including browser cookies, KeyChain data, and cryptocurrency wallet credentials. 

Per security experts, the malware is specifically tailored to target cryptocurrency users, with the intention of stealing private keys and other crucial wallet data. The downloaded package, once installed, will run a script called “ZoomApp.file.”

Upon execution, the script prompts users to enter their system password, unknowingly giving hackers access to sensitive data. 

Crypto hacks through Zoom links – Source: SlowMist

After decrypting the data, SlowMist revealed that the script ultimately executes an osascript, which transfers collected information to the attackers’ backend systems.

SlowMist also traced the phishing site’s creation to 27 days ago, suspecting the involvement of Russian hackers. These hackers have been using Telegram’s API to monitor activity on the phishing site, tracking whether anyone clicked the download link. According to the security company’s analysis, the hackers began targeting victims as early as November 14.

Stolen funds moved through several exchanges 

SlowMist used the on-chain tracking tool MistTrack to investigate the movements of stolen funds. The hacker’s address, identified as 0x9fd15727f43ebffd0af6fecf6e01a810348ee6ac, has reportedly profited more than $1 million in cryptocurrency, including USD0++, MORPHO, and ETH.

In a detailed analysis, MistTrack revealed that the hacker address had exchanged USD0++ and MORPHO for 296 ETH.

Stolen crypto movements tracked by MistTrack. Source: MistTrack

Further investigation showed that the hacker’s address received small ETH transfers from another address, 0xb01caea8c6c47bbf4f4b4c5080ca642043359c2e, which appeared to be responsible for providing transaction fees for the hacker’s scheme. 

The address has been found to transfer small amounts of ETH to nearly 8,800 other addresses, suggesting it may be part of a larger platform dedicated to funding transaction fees for illicit activities.

ETH transfers between addresses linked to the Zoom link scam – Source: SlowMist

Once the stolen funds were gathered, they were funneled through various platforms. Binance, Gate.io, Bybit, and MEXC were among the exchanges that received the stolen cryptocurrency. The funds were then consolidated into a different address, with transactions flowing into several exchanges, including FixedFloat and Binance. There, the stolen funds were converted into Tether (USDT) and other cryptocurrencies.

The criminals behind this scheme have managed to evade direct capture by using complex methods to launder and convert their illicit gains into widely-used cryptocurrencies. SlowMist warned crypto enthusiaststhat the phishing site and associated addresses may continue to target unsuspecting cryptocurrency users.

From Zero to Web3 Pro: Your 90-Day Career Launch Plan

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
【Daily Brief】10-year Treasury yield briefly tops 5%, S&P 500 slips to 7,602 and the dollar firms at 99.3 as the Fed's decision eve beginsThe 10-year Treasury yield touched 5.014% on Monday — its first print above 5% since October 2023 — while the S&P 500 closed 0.48% lower at 7,619.98 and the dollar index firmed to 99.3. Here is the full market wrap ahead of Wednesday's FOMC decision, the dot plot and the August retail sales report, plus today's CLARITY Act Senate vote.
Author  Irene Q.
Sep 15, Tue
The 10-year Treasury yield touched 5.014% on Monday — its first print above 5% since October 2023 — while the S&P 500 closed 0.48% lower at 7,619.98 and the dollar index firmed to 99.3. Here is the full market wrap ahead of Wednesday's FOMC decision, the dot plot and the August retail sales report, plus today's CLARITY Act Senate vote.
placeholder
October hike odds climb toward 60% as Goldman and BofA both flip — what Warsh's "dose of accommodation" really changedRate futures now price roughly 55% to 62% for a 25bp hike at the October 27-28 FOMC, up from about 30% before Chair Warsh's post-meeting framing that the Fed is merely "removing some accommodation." Goldman Sachs has added an October hike to its forecast and Bank of America now sees moves in both October and December. Here is the repricing, the language behind it, and the two data points that decide it.
Author  Irene Q.
Sep 23, Wed
Rate futures now price roughly 55% to 62% for a 25bp hike at the October 27-28 FOMC, up from about 30% before Chair Warsh's post-meeting framing that the Fed is merely "removing some accommodation." Goldman Sachs has added an October hike to its forecast and Bank of America now sees moves in both October and December. Here is the repricing, the language behind it, and the two data points that decide it.
placeholder
Memory chips surge, Nasdaq notches a second straight record close — why the Dow fell 185 points anywayMicron gained 5%, SanDisk 6.8%, Seagate 4% and Western Digital 3% as the memory complex led the Nasdaq Composite to a second consecutive record close of 27,244.28. But the Dow fell 185 points as JPMorgan, Wells Fargo and Schwab slid more than 3% each — a split tape that says more about positioning than about the economy.
Author  Irene Q.
Sep 23, Wed
Micron gained 5%, SanDisk 6.8%, Seagate 4% and Western Digital 3% as the memory complex led the Nasdaq Composite to a second consecutive record close of 27,244.28. But the Dow fell 185 points as JPMorgan, Wells Fargo and Schwab slid more than 3% each — a split tape that says more about positioning than about the economy.
placeholder
US input costs rose at the fastest pace in four years — the September flash PMI beat is an inflation story, not a growth storyUS September flash PMIs came in far above expectations, with the composite at 58.4, a five-year high. But the detail that moved markets was input cost inflation at its fastest since October 2022, driven by fuel, transport and supply shortages. Brent is back above $100 and the 10-year Treasury yield has hit its highest since 2007.
Author  Suzie
Sep 24, Thu
US September flash PMIs came in far above expectations, with the composite at 58.4, a five-year high. But the detail that moved markets was input cost inflation at its fastest since October 2022, driven by fuel, transport and supply shortages. Brent is back above $100 and the 10-year Treasury yield has hit its highest since 2007.
placeholder
WTI (USOIL) Is down 2.03% on Sep 25: Here Is WhyWTI (USOIL) is down 2.03% at Sep 24 22:20(UTC+0), now at $92.517, with a 7-day down of 3.63%.What is driving WTI (USOIL)’s stock price down today?The drop in WTI crude oil prices was primarily driven by
Author  TradingKey
Sep 25, Fri
WTI (USOIL) is down 2.03% at Sep 24 22:20(UTC+0), now at $92.517, with a 7-day down of 3.63%.What is driving WTI (USOIL)’s stock price down today?The drop in WTI crude oil prices was primarily driven by
goTop
quote