Zoom Meeting Scam: Crypto Users Fall Prey to Potential Russian-linked Hackers

Cybercriminals are once again exploiting trusted tools for malicious gains.

This time, a phishing campaign centered around fake Zoom meeting links has left victims counting massive losses in cryptocurrency.

Fake Zoom Invites Mask Malware

A recent report by blockchain security firm SlowMist detailed a sophisticated phishing campaign targeting cryptocurrency users through fake Zoom meeting links. The attack has reportedly resulted in the theft of millions of digital assets.

It involved the use of a fraudulent domain resembling the authentic one. This site mimicked the genuine Zoom interface to trick unassuming victims into downloading a malicious installation package. Once executed, the malware prompted users to enter their system passwords which enabled the collection of sensitive information such as KeyChain data, browser credentials, and cryptocurrency wallet details.

Upon analysis, SlowMist said that it identified the malware’s code as a modified osascript script. The script extracted and encrypted user data before transmitting it to a hacker-controlled server flagged as malicious by threat intelligence platforms.

The server’s IP address was traced to the Netherlands, and the attackers’ monitoring tools, including logs showing Russian script usage, suggest a connection to Russian-speaking operatives.

On-chain tracking through SlowMist’s MistTrack tool revealed that the hackers’ primary wallet amassed over $1 million, converting stolen assets into 296 ETH. Further transfers led to a secondary address which is now linked to transactions across popular crypto exchanges such as Binance, Gate.io, and MEXC. A complex network of smaller wallets and flagged addresses, including those tagged “Angel Drainer” and “Pink Drainer,” facilitated fund dispersal.

“These types of attacks often combine social engineering and Trojan techniques, making users vulnerable to exploitation. The SlowMist Security Team advises users to carefully verify meeting links before clicking, avoid executing unknown software and commands, install antivirus software, and update it regularly.”

Phishing Scams Hit Alarming Highs

There has been a surge in crypto phishing scams lately. Earlier this month, a fraudulent work meeting link sent via KakaoTalk caused a person to lose $300,000 in cryptocurrency. The malware-compromised funds were transferred to a BingX-associated wallet. The link installed malware and compromised Ethereum and Solana wallets.

Another blockchain security expert, Scam Sniffer reported over $9.4 million was lost in phishing attacks in November alone. Malicious blockchain signatures remain a top threat, as scammers exploit fraudulent transaction permissions to drain wallets, including high-profile thefts exceeding $36 million.

The post Zoom Meeting Scam: Crypto Users Fall Prey to Potential Russian-linked Hackers appeared first on CryptoPotato.

HOT news

Related posts

Latest posts

XRP Is Breaking Out With a 5% Surge as Analysts Say Ripple’s Time Has Come: Particulars

The crypto market is on the transfer on Tuesday morning, with bitcoin climbing to a multi-week peak of over $66,000. Many altcoins have adopted...

Bitcoin Has Exited Capitulation Regime as Momentum Rebuilds: Analysts

Bitcoin momentum is rebuilding, however affirmation has not arrived but, stated analytics platform Swissblock on Monday as BTC tapped a five-week excessive of $65,700....

FCC plans to ban corporations promoting DJI merchandise beneath different manufacturers

A number of corporations suspected of promoting DJI merchandise beneath their very own manufacturers may quickly be banned within the US.

Bitcoin Hyper Layer-2 Presale Approaches $33M as BTC and ETH Solidify Weekly Good points

On Monday 20 July 2026, Bitcoin and Ethereum consolidated their weekly beneficial properties regardless of a minor intraday pullback. Bitcoin stabilized close to $64,200,...

Bitcoin and Danger Belongings Underneath Strain as 30-12 months Yields Push Above 5%

A current public sale of 30-year Treasury bonds, bought at a yield of 5.06%, has introduced rising long-term US borrowing prices again into focus....

Want to stay up to date with the latest news?

We would love to hear from you! Please fill in your details and we will stay in touch. It's that simple!