• bitcoinBitcoin (BTC) $ 111,963.00
  • ethereumEthereum (ETH) $ 3,830.54
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,143.18
  • xrpXRP (XRP) $ 2.48
  • solanaSolana (SOL) $ 183.74
  • usd-coinUSDC (USDC) $ 0.999894
  • staked-etherLido Staked Ether (STETH) $ 3,828.81
  • tronTRON (TRX) $ 0.319865
  • dogecoinDogecoin (DOGE) $ 0.192365
  • cardanoCardano (ADA) $ 0.655499
  • wrapped-stethWrapped stETH (WSTETH) $ 4,658.27
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 112,170.00
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,102.41
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • chainlinkChainlink (LINK) $ 18.01
  • stellarStellar (XLM) $ 0.329978
  • bitcoin-cashBitcoin Cash (BCH) $ 525.34
  • hyperliquidHyperliquid (HYPE) $ 38.18
  • wrapped-eethWrapped eETH (WEETH) $ 4,130.76
  • avalanche-2Avalanche (AVAX) $ 22.84
  • suiSui (SUI) $ 2.66
  • wethWETH (WETH) $ 3,831.27
  • leo-tokenLEO Token (LEO) $ 9.64
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999549
  • usdsUSDS (USDS) $ 0.999115
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 112,171.00
  • hedera-hashgraphHedera (HBAR) $ 0.175198
  • usdt0USDT0 (USDT0) $ 1.00
  • litecoinLitecoin (LTC) $ 96.19
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • whitebitWhiteBIT Coin (WBT) $ 42.02
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • moneroMonero (XMR) $ 309.48
  • mantleMantle (MNT) $ 1.72
  • the-open-networkToncoin (TON) $ 2.19
  • crypto-com-chainCronos (CRO) $ 0.157792
  • polkadotPolkadot (DOT) $ 3.15
  • daiDai (DAI) $ 0.999444
  • zcashZcash (ZEC) $ 265.70
  • memecoreMemeCore (M) $ 2.25
  • okbOKB (OKB) $ 178.27
  • uniswapUniswap (UNI) $ 6.09
  • aaveAave (AAVE) $ 239.24
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.131018
  • bitget-tokenBitget Token (BGB) $ 4.86
  • nearNEAR Protocol (NEAR) $ 2.40
  • pepePepe (PEPE) $ 0.000007
  • bittensorBittensor (TAO) $ 308.34
  • ethenaEthena (ENA) $ 0.402065
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 227.00
  • usd1-wlfiUSD1 (USD1) $ 0.999640
  • aptosAptos (APT) $ 3.84
  • c1usdCurrency One USD (C1USD) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999943
  • ondo-financeOndo (ONDO) $ 0.752731
  • ethereum-classicEthereum Classic (ETC) $ 15.35
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,822.93
  • aster-2Aster (ASTER) $ 1.29
  • susdssUSDS (SUSDS) $ 1.07
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.34
  • binance-staked-solBinance Staked SOL (BNSOL) $ 196.11
  • worldcoin-wldWorldcoin (WLD) $ 0.951105
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.194103
  • htx-daoHTX DAO (HTX) $ 0.000002
  • story-2Story (IP) $ 6.04
  • gatechain-tokenGate (GT) $ 15.75
  • hash-2Provenance Blockchain (HASH) $ 0.037394
  • kucoin-sharesKuCoin (KCS) $ 14.39
  • usdtbUSDtb (USDTB) $ 0.999801
  • internet-computerInternet Computer (ICP) $ 3.31
  • arbitrumArbitrum (ARB) $ 0.320639
  • pi-networkPi Network (PI) $ 0.210574
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,375.05
  • bfusdBFUSD (BFUSD) $ 1.00
  • algorandAlgorand (ALGO) $ 0.190734
  • kaspaKaspa (KAS) $ 0.059194
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,042.44
  • flare-networksFlare (FLR) $ 0.019916
  • cosmosCosmos Hub (ATOM) $ 3.20
  • falcon-financeFalcon USD (USDF) $ 0.994454
  • tether-goldTether Gold (XAUT) $ 4,009.42
  • vechainVeChain (VET) $ 0.017414
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 38.10
  • wbnbWrapped BNB (WBNB) $ 1,142.75
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.023260
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,040.12
  • pump-funPump.fun (PUMP) $ 0.004074
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,123.52
  • skySky (SKY) $ 0.058705
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 112,121.00
  • sei-networkSei (SEI) $ 0.219095
  • quant-networkQuant (QNT) $ 89.96
  • render-tokenRender (RENDER) $ 2.50
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,060.89
  • official-trumpOfficial Trump (TRUMP) $ 6.16
  • pax-goldPAX Gold (PAXG) $ 3,992.42
  • nexoNEXO (NEXO) $ 1.18
  • filecoinFilecoin (FIL) $ 1.65
  • xdce-crowd-saleXDC Network (XDC) $ 0.065214
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.998647
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,184.00
  • bonkBonk (BONK) $ 0.000015
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998862
  • jupiter-exchange-solanaJupiter (JUP) $ 0.339570
  • spx6900SPX6900 (SPX) $ 1.11
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.398330
  • immutable-xImmutable (IMX) $ 0.506229
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,124.81
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.77
  • doublezeroDoubleZero (2Z) $ 0.269286
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 208.74
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 111,921.00
  • chainopera-aiChainOpera AI (COAI) $ 4.56
  • injective-protocolInjective (INJ) $ 9.00
  • clbtcclBTC (CLBTC) $ 113,557.00
  • morphoMorpho (MORPHO) $ 1.66
  • optimismOptimism (OP) $ 0.485297
  • fasttokenFasttoken (FTN) $ 1.98
  • ripple-usdRipple USD (RLUSD) $ 0.999912
  • celestiaCelestia (TIA) $ 0.994325
  • blockstackStacks (STX) $ 0.444865
  • myx-financeMYX Finance (MYX) $ 4.26
  • solmevSolMev (SN116) $ 2,398.72
  • msolMarinade Staked SOL (MSOL) $ 243.32
  • ousgOUSG (OUSG) $ 112.89
  • aerodrome-financeAerodrome Finance (AERO) $ 0.858771
  • lido-daoLido DAO (LDO) $ 0.853180
  • global-dollarGlobal Dollar (USDG) $ 0.999877
  • plasmaPlasma (XPL) $ 0.420467
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,672.64
  • curve-dao-tokenCurve DAO (CRV) $ 0.515615
  • sonic-3Sonic (S) $ 0.189559
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.85
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,830.54
  • the-graphThe Graph (GRT) $ 0.066457
  • tbtctBTC (TBTC) $ 111,651.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • saros-financeSaros (SAROS) $ 0.260061
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997387
  • flokiFLOKI (FLOKI) $ 0.000070
  • pyth-networkPyth Network (PYTH) $ 0.111654
  • tezosTezos (XTZ) $ 0.597197
  • kaiaKaia (KAIA) $ 0.107927
  • newton-projectAB (AB) $ 0.007657
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,831.36
  • ether-fiEther.fi (ETHFI) $ 1.18
  • pendlePendle (PENDLE) $ 3.57
  • beldexBeldex (BDX) $ 0.080227
  • usdaiUSDai (USDAI) $ 1.03
  • stader-ethxStader ETHx (ETHX) $ 4,104.92
  • iotaIOTA (IOTA) $ 0.145061
  • gtethGTETH (GTETH) $ 3,823.64
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.37
  • usual-usdUsual USD (USD0) $ 0.997982
  • aethirAethir (ATH) $ 0.044840
  • conflux-tokenConflux (CFX) $ 0.103953
  • raydiumRaydium (RAY) $ 1.98
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.83
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,137.27
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 111,901.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,213.05
  • galaGALA (GALA) $ 0.011115
  • swethSwell Ethereum (SWETH) $ 4,219.76
  • dogwifcoindogwifhat (WIF) $ 0.510537
  • theta-tokenTheta Network (THETA) $ 0.506988
  • jasmycoinJasmyCoin (JASMY) $ 0.010476
  • starknetStarknet (STRK) $ 0.116474
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.983662
  • bittorrentBitTorrent (BTT) $ 0.00000051
  • the-sandboxThe Sandbox (SAND) $ 0.203358
  • true-usdTrueUSD (TUSD) $ 0.999944
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.191944
  • zero-gravity0G (0G) $ 2.30
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.743629
  • swissborgSwissBorg (BORG) $ 0.494900
  • dashDash (DASH) $ 38.93
  • decentralandDecentraland (MANA) $ 0.246757
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.22
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999810
  • sun-tokenSun Token (SUN) $ 0.024315
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 1.00
  • usddUSDD (USDD) $ 0.999830
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,126.16
  • ai-companionsAI Companions (AIC) $ 0.449392
  • vaultaVaulta (A) $ 0.281060
  • flowFlow (FLOW) $ 0.278367
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,205.35
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 28.00
  • jito-governance-tokenJito (JTO) $ 1.11
  • bitcoin-svBitcoin SV (BSV) $ 21.37
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 38.22
  • heliumHelium (HNT) $ 2.26
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,830.20
  • apenftAPENFT (NFT) $ 0.00000042
  • frax-etherFrax Ether (FRXETH) $ 3,791.56

Fake startups target crypto users, infiltrating their wallets

0 33

Fake startups target crypto users, infiltrating their wallets

Darktrace research reveals ongoing social engineering campaign targeting crypto users through fake startup companies. Scammers impersonate AI, gaming, and Web3 firms using spoofed social media accounts.

Project documentation gets hosted on legitimate platforms like Notion and GitHub. The campaign continues changing since December 2024 targeting Web3 employees globally.

Fake companies use legitimate platforms to build credible presence

Threat actors create fake startup companies with AI, gaming, video meeting software themes. Web3 and social media company facades help target cryptocurrency users specifically. These operations use compromised X accounts typically with verification to contact victims.

The attackers use legitimate platforms including Notion, Medium, and GitHub for documentation. Professional-looking websites include employee profiles, product blogs, whitepapers, and development roadmaps. X accounts appear compromised with higher follower counts adding to the appearance of legitimacy.

The scammers remain active on social media accounts posting software development updates. Product marketing content gets shared regularly while campaigns operate across platforms. Eternal Decay blockchain game created fake conference presentation photos for credibility.

The attackers even altered Italian exhibition photos making them appear as company presentations. Medium hosts blog posts about fake software products and company developments. Notion contains detailed product roadmaps and comprehensive employee listing information.

Fake startups target crypto users, infiltrating their wallets

Scammers altering photo from Italian exhibition: Source

GitHub repositories feature technical software aspects using stolen open-source projects. Code names get changed to make repositories appear unique and original. Company registration information from Companies House gets linked to similar-named companies.

Gitbook details company information and lists fake investor partnerships for credibility. Gameplay images stolen from Zombie Within game appear as Eternal Decay content. Some fake companies establish merchandise stores to complete business facades.

These combined elements create convincing startup company appearances increasing infection success rates. Victims receive contact through X messages, Telegram, or Discord from employees. Fake workers offer cryptocurrency payments for software testing participation.

Malware targeting both Windows and macOS crypto wallet users

Windows versions are distributed via Electron apps that demand registration codes from impersonated employees. Bins are downloaded by users after codes are entered given via social media messaging. CloudFlare verification screens are presented prior to malware execution on target systems.

The malware gathers system profiles in username, CPU details, RAM, and graphics. MAC addresses and system UUIDs are gathered in preliminary reconnaissance phases. Token-based authentication mechanisms use tokens which are derived from application launcher URLs.

Stolen code signing certificates increase software legitimacy and evade security detection. Companies like Jiangyin Fengyuan Electronics Co. and Paperbucketmdb ApS certificates were used. Python gets retrieved and stored in temporary directories for command execution.

macOS distributions are released as DMG files containing bash scripts and binaries. Scripts use obfuscation techniques like base64 encoding and XOR encryption. AppleScript mounts malware and runs executables from temporary directories automatically.

The macOS malware performs anti-analysis checks for QEMU, VMWare, and Docker environments. Atomic Stealer targets browser data, crypto wallets, cookies, and document files. Stolen data gets compressed and sent via POST requests to servers.

Additional bash scripts establish persistence through Launch Agent configurations at login. The malware logs active application usage and window information continuously. User interaction timestamps get recorded and transmitted to collection servers periodically.

Both versions target cryptocurrency wallet data specifically for theft operations. Multiple fake companies distribute identical malware with different branding and themes.

Extensive list of fake companies identified across multiple platforms

Darktrace revealed several phony companies running through this social engineering campaign. Pollens AI impersonates collaborative creation tools using X accounts and other websites. Buzzu employs the same logos and code as Pollens but runs under different branding.

Cloudsign is reported to provide document signing platform services to business consumers. Swox is a Web3 space next-generation social network. KlastAI is closely linked to Pollens accounts and sites bearing the same branding.

Wasper uses the same logos and GitHub code as Pollens across various areas. Lunelior operates through various websites serving various groups of users in specific. BeeSync previously operated as Buzzu alias before its rebranding in January 2025.

Slax hosts social media and AI-centric sites on multiple websites. Solune reaches users through social media platform activity and messaging app usage. Eternal Decay is a blockchain gaming firm with synthetic conference presentations.

Dexis is branded the same as Swox and shared the same user base. NexVoo has multiple domains and social media platform management. NexLoop rebranded to NexoraCore by renaming GitHub repositories.

YondaAI targets social media site users and various website domain users. Every business has professional fronts through real platform integration procedures. The CrazyEvil traffer group has been operating such campaigns since 2021.

Recorded Future approximates CrazyEvil’s millions of revenue from malicious activities. The group is said to be behind attacks on crypto users, influencers, and DeFi professionals. The campaigns show extensive efforts in making legitimate business appearances.

Source

Leave A Reply

Your email address will not be published.