Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Threat actors steal over $1M using social engineering scams

Threat actors steal over $1M using social engineering scams

GrafaGrafa2025/07/11 07:40
By:Mahathir Bayena

Cybersecurity firm Darktrace reported that threat actors are employing an elaborate social engineering scheme to target cryptocurrency users and drain their wallets.

The scheme involves impersonating employees of fake startups in sectors such as AI, gaming, Web3, and social media to gain victims’ trust.

Compromised accounts on platforms like X are used to support the fraud, along with fabricated Medium articles and GitHub entries.

The fake representatives ask victims to test software in exchange for cryptocurrency payments.

Once the user downloads the software, a Cloudflare verification bubble appears, which begins extracting information from the victim’s computer.

This verification process is crafted to mimic legitimate security checks, making it difficult for users to recognise the threat until their data is compromised. The attackers often use convincing communication tactics and technical subterfuge to bypass common suspicions.

At a certain stage, credentials from cryptocurrency wallets are stolen.

Both Windows and Mac users have been targeted in these attacks.

Darktrace noted similarities between this scheme and the December 2024 Meeten campaign attacks.

Other social engineering attacks targeting crypto users have also been linked to groups allegedly associated with North Korea.

These scams highlight ongoing risks in the cryptocurrency space where threat actors use sophisticated methods to exploit users.

The report underscores the importance of vigilance when approached with unsolicited offers involving software downloads and cryptocurrency transactions.

Users are advised to verify identities carefully and avoid downloading software from untrusted sources.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

GameStop Eyes Crypto Payments for Trading Cards as Part of Collectibles Push

GameStop is considering accepting cryptocurrencies as payment for trading cards, as the American video game retailer looks to diversify beyond gaming hardware into higher-margin collectibles.

DeFi Planet2025/07/16 18:35
GameStop Eyes Crypto Payments for Trading Cards as Part of Collectibles Push