Crypto scammers have launched a new phishing attack using fake Zoom links to install malware on victims' computers.
On July 22, cybersecurity expert “NFT_Dreww” alerted the community about this sophisticated scam on X (formerly Twitter), revealing that it has already led to $300,000 in stolen cryptocurrency.
Here’s how it works: Scammers target NFT holders or crypto investors by pretending to be interested in their intellectual property or proposing collaborations. They insist on using Zoom for communication and send a link to join a meeting.
The link leads to a fake Zoom page with a loading screen that prompts users to download “ZoomInstallerFull.exe,” which is actually malware.
Once the malware is installed, it infiltrates the victim’s computer and redirects them to the real Zoom platform, making the scam less noticeable. The malware adds itself to the Windows Defender exclusion list to avoid detection and begins extracting information while the user is distracted by the fake loading process.
To stay under the radar, scammers frequently change their domain names. This is their fifth domain for this scam. Recently, there have also been reports of malicious emails from scammers posing as crypto influencers, containing attachments designed to install malware.
An international arrest warrant has been requested for Hayden Davis, co-creator of the LIBRA token, which became the center of a major political scandal in Argentina.
Chris Larsen, the co-founder of Ripple, suffered a significant financial blow in 2024 when he lost over $661 million worth of XRP due to a security breach in the password management system LastPass.
Venture capitalist and Mission Gate founder George Bachiashvili is now facing imprisonment in Georgia after a court revoked his bail.
Hackers have exploited a vulnerability in DeFi aggregator 1inch’s resolver smart contract, leading to losses of over $5 million, according to blockchain security firm SlowMist.