• bitcoinBitcoin (BTC) $ 72,191.00
  • ethereumEthereum (ETH) $ 2,224.83
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 605.93
  • xrpXRP (XRP) $ 1.34
  • usd-coinUSDC (USDC) $ 0.999731
  • solanaSolana (SOL) $ 83.33
  • tronTRON (TRX) $ 0.319627
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.091923
  • usdsUSDS (USDS) $ 0.999825
  • whitebitWhiteBIT Coin (WBT) $ 52.93
  • hyperliquidHyperliquid (HYPE) $ 43.09
  • leo-tokenLEO Token (LEO) $ 10.14
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.239383
  • bitcoin-cashBitcoin Cash (BCH) $ 426.68
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 8.88
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 345.26
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • zcashZcash (ZEC) $ 351.04
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • canton-networkCanton (CC) $ 0.151819
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.152982
  • memecoreMemeCore (M) $ 2.75
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999860
  • usd1-wlfiUSD1 (USD1) $ 0.999224
  • litecoinLitecoin (LTC) $ 53.12
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999951
  • avalanche-2Avalanche (AVAX) $ 9.28
  • rainRain (RAIN) $ 0.007888
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.085088
  • suiSui (SUI) $ 0.919198
  • the-open-networkToncoin (TON) $ 1.43
  • usdt0USDT0 (USDT0) $ 0.998824
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • crypto-com-chainCronos (CRO) $ 0.068418
  • ravedaoRaveDAO (RAVE) $ 11.60
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,708.96
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.079531
  • bittensorBittensor (TAO) $ 254.99
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pax-goldPAX Gold (PAXG) $ 4,720.56
  • mantleMantle (MNT) $ 0.669902
  • global-dollarGlobal Dollar (USDG) $ 0.999936
  • uniswapUniswap (UNI) $ 3.12
  • polkadotPolkadot (DOT) $ 1.17
  • nearNEAR Protocol (NEAR) $ 1.39
  • falcon-financeFalcon USD (USDF) $ 0.998453
  • okbOKB (OKB) $ 83.20
  • skySky (SKY) $ 0.074006
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • pi-networkPi Network (PI) $ 0.164735
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • aster-2Aster (ASTER) $ 0.660287
  • usddUSDD (USDD) $ 1.00
  • pepePepe (PEPE) $ 0.000004
  • aaveAave (AAVE) $ 94.85
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • internet-computerInternet Computer (ICP) $ 2.45
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bitget-tokenBitget Token (BGB) $ 1.90
  • bfusdBFUSD (BFUSD) $ 0.999697
  • ethereum-classicEthereum Classic (ETC) $ 8.18
  • ondo-financeOndo (ONDO) $ 0.248614
  • kucoin-sharesKuCoin (KCS) $ 8.46
  • gatechain-tokenGate (GT) $ 6.70
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 74.73
  • pump-funPump.fun (PUMP) $ 0.001813
  • worldcoin-wldWorldcoin (WLD) $ 0.297193
  • render-tokenRender (RENDER) $ 1.87
  • morphoMorpho (MORPHO) $ 1.71
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • algorandAlgorand (ALGO) $ 0.102978
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.083264
  • nexoNEXO (NEXO) $ 0.883744
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.032186
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • cosmosCosmos Hub (ATOM) $ 1.73
  • usdtbUSDtb (USDTB) $ 0.999683
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.094677
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.05
  • wbnbWrapped BNB (WBNB) $ 759.61
  • blockchain-capitalBlockchain Capital (BCAP) $ 83.06
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.857826
  • justJUST (JST) $ 0.077573
  • ousgOUSG (OUSG) $ 114.87
  • filecoinFilecoin (FIL) $ 0.874350
  • arbitrumArbitrum (ARB) $ 0.111420
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007845
  • hash-2Provenance Blockchain (HASH) $ 0.011794
  • official-trumpOfficial Trump (TRUMP) $ 2.82
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • midnight-3Midnight (NIGHT) $ 0.038462
  • beldexBeldex (BDX) $ 0.080456
  • xdce-crowd-saleXDC Network (XDC) $ 0.030588
  • yldsYLDS (YLDS) $ 0.999745
  • vechainVeChain (VET) $ 0.006794
  • ghoGHO (GHO) $ 0.999746
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • jupiter-exchange-solanaJupiter (JUP) $ 0.164081
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • siren-2Siren (SIREN) $ 0.788885
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • stable-2​​Stable (STABLE) $ 0.025810
  • usual-usdUsual USD (USD0) $ 0.998369
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.232822
  • clbtcclBTC (CLBTC) $ 76,920.00
  • dashDash (DASH) $ 41.04
  • bonkBonk (BONK) $ 0.000006
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.52
  • a7a5A7A5 (A7A5) $ 0.012460
  • layerzeroLayerZero (ZRO) $ 1.96
  • true-usdTrueUSD (TUSD) $ 0.999628
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • dexeDeXe (DEXE) $ 10.01
  • adi-tokenADI (ADI) $ 4.31
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.662071
  • euro-coinEURC (EURC) $ 1.17
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006628
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999207
  • monadMonad (MON) $ 0.033762
  • blockstackStacks (STX) $ 0.215154
  • venice-tokenVenice Token (VVV) $ 8.63
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • decredDecred (DCR) $ 21.76
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • chilizChiliz (CHZ) $ 0.036654
  • sei-networkSei (SEI) $ 0.054828
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • tezosTezos (XTZ) $ 0.339926
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • kinesis-goldKinesis Gold (KAU) $ 152.93
  • cocaCOCA (COCA) $ 1.30
  • usxUSX (USX) $ 0.999352
  • hastra-primePRIME (PRIME) $ 1.03
  • sun-tokenSun Token (SUN) $ 0.017971
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • aerodrome-financeAerodrome Finance (AERO) $ 0.368253
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • apenftAINFT (NFT) $ 0.00000033
  • ether-fiEther.fi (ETHFI) $ 0.410951
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • curve-dao-tokenCurve DAO (CRV) $ 0.212498
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • gnosisGnosis (GNO) $ 118.61
  • plasmaPlasma (XPL) $ 0.128015
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • bitcoin-svBitcoin SV (BSV) $ 15.18
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • injective-protocolInjective (INJ) $ 2.94
  • edgexedgeX (EDGE) $ 0.835486
  • usdaiUSDai (USDAI) $ 0.999544
  • kinesis-silverKinesis Silver (KAG) $ 75.15
  • spx6900SPX6900 (SPX) $ 0.306071
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • conflux-tokenConflux (CFX) $ 0.053675
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • fraxLegacy Frax Dollar (FRAX) $ 0.994205
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • kaiaKaia (KAIA) $ 0.046378
  • flokiFLOKI (FLOKI) $ 0.000028
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • doublezeroDoubleZero (2Z) $ 0.078097
  • lighterLighter (LIT) $ 1.08
  • celestiaCelestia (TIA) $ 0.296834
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • lido-daoLido DAO (LDO) $ 0.315802
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • syrupMaple Finance (SYRUP) $ 0.229823
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • official-foOfficial FO (FO) $ 0.263321
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • jasmycoinJasmyCoin (JASMY) $ 0.005306
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

How to Spot Fake Zoom Links Scammers Are Using to Steal Your Crypto

0 157

How to Spot Fake Zoom Links Scammers Are Using to Steal Your Crypto

Hackers are attempting to steal the cryptocurrency holdings of Zoom users through a complex phishing-based malware distribution scheme, according to a cybersecurity engineer.

In a Twitter thread earlier this week, a pseudonymous cybersecurity engineer and NFT collector NFT_Dreww.eth drew attention to the new scheme. “Scammers are getting extremely sophisticated, and have evolved their tactics to impersonate zoom which, if downloaded, takes everything from your device… Over $300K stolen so far…” he wrote.

Drew explained that criminals usually approach would-be victims with some made up opportunity. The examples given are claiming to want to license their intellectual property, bring them in as guests to a Twitter space, asking them to be angel investors or join their project’s team.

They then insist on discussing the opportunity via Zoom, which gives the scammers an opportunity to share the malicious link. The attackers also use high-pressure tactics, like sending a screenshot of a Zoom call full of people waiting for the victim.

1/ This scam is one of the more sophisticated scams, where if you really aren’t paying attention to the tiny details, then its game over.

Of course, this scam starts out just like any other scam asking you typically one of the three below, wearing an Ape PFP, etc:

– “I would… pic.twitter.com/jEdGdkHDjv

— NFT_Dreww.eth (@nft_dreww) July 22, 2024

Even if the victim has Zoom installed, the legitimate-looking page will show a loading screen as it downloads ZoomInstallerFull.exe. But it’s really the malware masquerading as a Zoom installer that will then prompt the victim to accept terms and conditions that Windows users are accustomed to seeing when they install new software.

Once the “installation” is complete, the call loading page keeps spinning until at some point it redirects the victim to the legitimate Zoom website. Drew concluded that this is aimed at making “it seem like it was just a glitch or taking forever to load.” When this takes place, the malware has already been executed and has completed its function.

When the file is executed, the malware immediately executes and lodges itself into the Windows Defender exclusion list—which leads to Windows being unable to block it. At this point, the malware begins executing its payload and extracting user information while the victim is busy staring at the spinning loading video call screen and accepting pretend terms and conditions.

Drew highlighted that in this case, virus detection software might fail to catch this type of malware.

“When you are dealing with malware to this degree, often times tools fail to catch this, such as Virus Total,” he wrote. “All of these tools are meant as a check and should not be meant as a source of truth, Virus Total is great but if you are not specific in what you are searching, it can end up hurting you.”

Artem Irgebaev, Smart Contract Triager at Immunefi, told Decrypt that “antivirus effectiveness depends on whether that malware was encrypted before being sent to the target. I would say that in most cases, it is not effective at all since Threat Actors prepare their attacks on high-value targets and encrypt their malware before engaging with the potential victim.”

Sudipan Sinha, Core Contributor at RiskLayer and CEO at Chainrisk Labs further highlighted that “relying solely on antivirus software has its shortcomings.” He explained that “zero-day exploits, which are entirely new and unknown to antivirus databases, pose a significant challenge.

Moreover, antivirus software cannot safeguard against social engineering tactics that deceive users into unwittingly downloading malware. Therefore, while antivirus software is a vital component of cybersecurity defense, comprehensive protection against sophisticated attacks often requires additional layers of security measures and user awareness.”

Realistic zoom links

The format of the links involved in this phishing campaign closely resembles legitimate Zoom links. As explained by Drew, Zoom uses the zoom.us domain with subdomains based on location, with a U.S.-based user potentially being redirected to us02web.zoom.us.

The malicious links, on the other hand, use the zoom subdomain of the us50web.us domain. At a glance, the resulting zoom.us50web.us may appear legitimate—thanks in no small part to the confusing naming scheme of Zoom domains and subdomains. Alternatively, Drew also cites the us50web-zoom.us domain as an example.

3/ Hold on, lets take a step back. That was a legit zoom link though right? Is zoom hacked? Answer: Nope….

*.zoom[.]us is the legit domain, it uses the sub-domain usXXweb.zoom[.]us when in the US and XX being a number based on your geo-location for you to download and install… pic.twitter.com/yUSmk1MkAQ

— NFT_Dreww.eth (@nft_dreww) July 22, 2024

“Its super important to know that a “-” does not make something a sub-domain, that’s a part of a top-level domain, which tricks a lot of people,” he explained.

Drew highlighted that it takes a lot of attention not to fall for a social engineering attack like this one.

“It’s extremely easy to fall for this… I doubt 80% of people verify each character in a link that’s sent, especially a Zoom link,” Drew concluded. Similarly, Irgebaev noted that “using a fake Zoom domain is very creative, which increases the number of people likely to be tricked into downloading malware.”

Crypto crime is nothing new

As reported earlier this week, Europol’s latest Internet Organized Crime Threat Assessment showed that crypto crime continues to evolve. Furthermore, researchers suggest that it is going to only get worse since encryption and decentralization make privacy increasingly well-protected:

“Decentralization, blockchain technology, and P2P networks will continue to provide opportunities for cyber offenders as they make it easier to carry out transactions anonymously and out of sight of the authorities,” the authors wrote.

Edited by Stacy Elliott.

Source

Leave A Reply

Your email address will not be published.