Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Threat actors steal over $1M using social engineering scams

Threat actors steal over $1M using social engineering scams

GrafaGrafa2025/07/11 07:40
By:Mahathir Bayena

Cybersecurity firm Darktrace reported that threat actors are employing an elaborate social engineering scheme to target cryptocurrency users and drain their wallets.

The scheme involves impersonating employees of fake startups in sectors such as AI, gaming, Web3, and social media to gain victims’ trust.

Compromised accounts on platforms like X are used to support the fraud, along with fabricated Medium articles and GitHub entries.

The fake representatives ask victims to test software in exchange for cryptocurrency payments.

Once the user downloads the software, a Cloudflare verification bubble appears, which begins extracting information from the victim’s computer.

This verification process is crafted to mimic legitimate security checks, making it difficult for users to recognise the threat until their data is compromised. The attackers often use convincing communication tactics and technical subterfuge to bypass common suspicions.

At a certain stage, credentials from cryptocurrency wallets are stolen.

Both Windows and Mac users have been targeted in these attacks.

Darktrace noted similarities between this scheme and the December 2024 Meeten campaign attacks.

Other social engineering attacks targeting crypto users have also been linked to groups allegedly associated with North Korea.

These scams highlight ongoing risks in the cryptocurrency space where threat actors use sophisticated methods to exploit users.

The report underscores the importance of vigilance when approached with unsolicited offers involving software downloads and cryptocurrency transactions.

Users are advised to verify identities carefully and avoid downloading software from untrusted sources.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

MEET48: From Star-Making Factory to On-Chain Netflix — How AIUGC and Web3 Are Reshaping the Entertainment Economy

Web3 entertainment is moving from the retreat of the bubble to a moment of restart. Projects represented by MEET48 are reshaping content production and value distribution paradigms through the integration of AI, Web3, and UGC technologies. They are building sustainable token economies, evolving from applications to infrastructure, aiming to become the "Netflix on-chain" and driving large-scale adoption of Web3 entertainment.

深潮2025/11/09 20:09
MEET48: From Star-Making Factory to On-Chain Netflix — How AIUGC and Web3 Are Reshaping the Entertainment Economy