New Crypto Scam Uses Fake Influencer Accounts to Lure Victims Into Telegram Malware Trap

A new wave of crypto scams has emerged, with attackers using fake X accounts to impersonate popular influencers and lure unsuspecting users into fraudulent Telegram groups.

Users are then manipulated into installing malware that compromises crypto wallet data.

Scammers Moving Beyond Simple Phishing Scams

According to blockchain security firm Scam Sniffer, the scammers comment on legitimate posts, enticing users with offers of exclusive investment insights and “alpha” tips. Once individuals join these Telegram groups, they are immediately prompted to undergo a verification process via a bot called OfficiaISafeguardBot.

The bot creates a false sense of urgency and pushes users to quickly complete the verification. However, this seemingly harmless step is a trap – by completing the verification, the bot injects malicious PowerShell code into the user’s clipboard. When executed, the code downloads malware designed to compromise the system and steal sensitive data, including crypto wallet information.

Scam Sniffer said that the malware has been flagged by VirusTotal as harmful, and previous instances of similar attacks have resulted in private key theft, leading to significant financial losses.

“This represents a new evolution in crypto scams – moving beyond simple phishing to combine social engineering with malware. Stay vigilant and share this to protect others.”

Rampant Scams

Last month, Casa CEO Nick Neuman shared a harrowing tale of a phishing scam that targeted him. In a post on X, Neuman described a call he received from a scammer pretending to be a Coinbase support agent. The scammer claimed that Neuman’s password change request had been canceled and encouraged him to click on a link in a suspicious email.

When Neuman started questioning the scammer, they dropped the act and revealed the operation’s true nature. The scammer bragged about having recently stolen $35,000 from a victim and made it clear that the scam targets only rich crypto investors.

More recently, a crypto user under the pseudonym “LeftsideEmiri,” reported losing $300,000 due to a social engineering attack. According to the user, the attack began when they received a message containing a link to a KakaoTalk conversation, which was supposedly for a partnership meeting. Although the link seemed broken, the user clicked on it, believing it to be harmless.

In hindsight, they suspect that clicking the link triggered the installation of malware, which compromised their Ethereum and Solana wallets, along with several other wallets. The user made it clear that they had not approved or signed any transactions, indicating that the attack was covert and took advantage of social engineering techniques to steal funds.

The post New Crypto Scam Uses Fake Influencer Accounts to Lure Victims Into Telegram Malware Trap appeared first on CryptoPotato.

HOT news

Related posts

Latest posts

Ripple Whale Deposits to Binance Reach 6-Month High, Over 2.66 Billion XRP Transferred

Whale deposits into Binance have surged to a six-month high, with over 2.66 billion XRP tokens moved to the exchange in the past 30...

US Supreme Court bails on NVIDIA case, allowing a shareholder lawsuit to proceed

The US Supreme Court dismissed an NVIDIA case it previously agreed to hear as “improvidently granted.” In other words: “Oops, we never should’ve taken...

Fireblocks Sets Up Tokyo Office to Strengthen Asia-Pacific Presence

Digital asset infrastructure giant Fireblocks has opened a regional office in Tokyo to tap into Japan’s growing blockchain ecosystem, the firm announced in a...

WhiteBIT Becomes First Exchange to Achieve the Highest Level Cryptocurrency Security Standard

WhiteBIT has reached a significant milestone by becoming the first cryptocurrency exchange globally to obtain Level 3 certification under the Cryptocurrency Security Standard...

Instagram, Threads and WhatsApp are coming back online after widespread ‘technical issues’

Instagram, Facebook, Threads and Messenger are coming back online after widespread "technical issues" took down many of Meta's biggest apps for several hours Wednesday....

Want to stay up to date with the latest news?

We would love to hear from you! Please fill in your details and we will stay in touch. It's that simple!