Emergence of Malicious Crypto Scam Targeting Zoom Users
A new cryptographic malware is targeting users of the cloud-based video conferencing platform Zoom. The malware redirects users to malicious websites to steal their crypto assets. On July 22, network security engineer “NFT_Dreww” discovered that the malicious website closely imitated the original Zoom video call link.
Sophisticated Social Engineering Tactics
The attack begins with the scammer approaching the victim and tricking them into joining a video call. Common strategies include offering angel investment opportunities or asking victims to join the X space as a guest. Scammers use fake Zoom URLs that closely resemble legitimate ones, including real meeting IDs and passwords to appear authentic.
Scammers create a facade of legitimacy by decorating NFT profile pictures and claiming association with various projects. However, users should be cautious as subtle differences in URLs can lead to malicious websites.
Operation and Impact of the Malware
After clicking the link, users are redirected to a fake Zoom page where they are prompted to download a file named “ZoomInstallerFull.exe.” Once installed, the malware extracts user information and bypasses security software, stealing funds from victims.
This sophisticated scam has already stolen over $300,000 from multiple users. It is vital for individuals to exercise caution when clicking on links from social media and avoid downloading any suspicious software to protect their assets.
As the crypto industry grows, social engineering scams are becoming more prevalent. Recent incidents, such as phishing emails sent to Ethereum Foundation users, highlight the need for heightened awareness and vigilance in safeguarding cryptocurrency assets.
In the first half of 2024, more than $300 million worth of cryptocurrency assets were stolen through similar scams on the EVM chain, underscoring the importance of cybersecurity in the digital asset space.
The post Crypto scammers use fake Zoom malware to steal funds appeared first on Invezz.