
{"id":26864,"date":"2024-12-09T09:50:34","date_gmt":"2024-12-09T09:50:34","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=26864"},"modified":"2024-12-09T09:50:34","modified_gmt":"2024-12-09T09:50:34","slug":"web3-workers-targeted-by-malware-campaign-using-fake-meeting-apps-cado-security-labs","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=26864","title":{"rendered":"Web3 Workers Targeted by Malware Campaign Using Fake Meeting Apps: Cado Security Labs"},"content":{"rendered":"<p><span>According to cybersecurity firm Cado Security Labs, Web3 professionals are the latest victims of a sophisticated malware campaign that employs fake meeting apps to steal sensitive credentials and crypto assets.<\/span><\/p>\n<p><span>In a <\/span><a class=\"editor-rtfLink\" href=\"https:\/\/www.cadosecurity.com\/blog\/meeten-malware-threat\" target=\"_blank\" rel=\"noopener\"><span>report released on December 6<\/span><\/a><span>, Cado\u2019s threat research lead, Tara Gould, detailed how scammers <\/span><span>are leveraging<\/span><span> artificial intelligence (AI) to craft convincing websites and social media profiles that mimic legitimate companies.<\/span><\/p>\n<p><span>The malicious app, initially called \u201cMeeten,\u201d has undergone several rebrands, now operating as \u201cMeetio\u201d and previously using domains such as Clusee.com, Cuesee, Meeten<\/span><span>.gg<\/span><span>, and Meetone<\/span><span>.gg<\/span><span>. <\/span><\/p>\n<p><strong><span>EXPLORE:\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/99bitcoins.com\/education\/crypto-tax-guide\/\" target=\"_blank\" rel=\"noopener\"><span>Crypto Tax Guide 2024<\/span><\/a><\/strong><\/p>\n<h2><span>Malicious App Deploys Information Stealer Once Downloaded<\/span><\/h2>\n<p><span>Once downloaded, the app deploys a Realst information stealer <\/span><span>to extract sensitive data, including Telegram logins, banking information, and cryptocurrency wallet credentials. <\/span><\/p>\n<p><span>The malware also targets browser cookies, autofill data from applications like Google Chrome and Microsoft Edge, and<\/span><span>\u00a0information from crypto wallets such as Ledger, Trezor, and Binance Wallet.<\/span><\/p>\n<p><span>The attackers employ a combination of social engineering and spoofing tactics. Gould highlighted a case where a victim was approached on Telegram by someone impersonating a known contact. <\/span><\/p>\n<p><span>The scammer shared an investment presentation from the victim\u2019s company<\/span><span>..<\/span><span> Other reports include incidents where individuals participated in Web3-related calls, downloaded <\/span><span>the fraudulent<\/span><span> software, and subsequently lost cryptocurrency holdings.<\/span><\/p>\n<p><span>To bolster their credibility, the scammers utilize AI to generate blogs, product descriptions, and social media content for their fake company websites. <\/span><\/p>\n<p>Cado Security Labs has discovered a new malware campaign targeting Web3 workers with a sophisticated scam using AI-generated content to appear legitimate. <\/p>\n<p>Read more in our latest blog post: <a href=\"https:\/\/t.co\/Pj8Y82kaKY\" target=\"_blank\" rel=\"noopener\">https:\/\/t.co\/Pj8Y82kaKY<\/a><\/p>\n<p>\u2014 Cado (@CadoSecurity) <a href=\"https:\/\/twitter.com\/CadoSecurity\/status\/1865026404762460318?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 6, 2024<\/a><\/p>\n\n<p><span>These websites, often hosted on platforms like X (formerly Twitter) and Medium, add an air of legitimacy to the campaign, making it harder for users to detect malicious intent. <\/span><\/p>\n<p><span>\u201cWhile much of the recent focus has been on the potential of AI to create malware, threat actors are increasingly using AI to generate content for their campaigns,\u201d Gould said.<\/span><\/p>\n<p><span>\u201cUsing AI enables threat actors to quickly create realistic website content that adds legitimacy to their scams and makes it more difficult to detect suspicious websites.\u201d\u00a0<\/span><\/p>\n<p><strong><span>EXPLORE:\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/99bitcoins.com\/cryptocurrency\/best-crypto-to-buy\/\" target=\"_blank\" rel=\"noopener\"><span>17 Best Crypto to Buy Now in 2024<\/span><\/a><\/strong><\/p>\n<h2><span>Fake Websites Include Code Capable of Stealing Crypto<\/span><\/h2>\n<p><span>In some cases, the fake websites include JavaScript code that is <\/span><span>capable<\/span><span> of stealing crypto directly from web browsers before any malware <\/span><span>is installed<\/span><span>. <\/span><\/p>\n<p><span>Both macOS and Windows versions of the malware have <\/span><span>been identified<\/span><span>, and the campaign has reportedly been active for around four months.<\/span><\/p>\n<p><span>Similar schemes have surfaced recently. In August, on-chain investigator ZackXBT identified 21 developers, likely linked to North Korea, using fake identities to infiltrate crypto projects. <\/span><\/p>\n<p><span>Additionally, in September, the FBI warned of North Korean hackers targeting crypto firms and decentralized finance (DeFi) projects with malware disguised as job offers.<\/span><\/p>\n<p><span>Last week, Japanese cryptocurrency exchange DMM Bitcoin announced its closure following a massive security breach in May that resulted in over $300 million losses.<\/span><\/p>\n<p><span>The exchange confirmed that its assets will be acquired by SBI VC Trade, the crypto arm of Japan\u2019s SBI Group, as part of a planned transition.<\/span><\/p>\n<p><strong><span>EXPLORE:\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/99bitcoins.com\/news\/300-million-exploit-japans-dmm-bitcoin-exchange-suffers-largest-hack-of-2024\/\" target=\"_blank\" rel=\"noopener\"><span>$300 Million Exploit: Japan\u2019s DMM Bitcoin Exchange Suffers Largest Hack Of 2024<\/span><\/a><\/strong><\/p>\n<p><a href=\"https:\/\/discord.gg\/QneEHUjm\" target=\"_blank\" rel=\"noopener\">Join The 99Bitcoins News Discord Here For The Latest Market Updates<\/a><\/p>\n<p>The post <a href=\"https:\/\/99bitcoins.com\/news\/web3-workers-targeted-by-malware-campaign-using-fake-meeting-apps-cado-security-labs\/\">Web3 Workers Targeted by Malware Campaign Using Fake Meeting Apps: Cado Security Labs<\/a> appeared first on <a href=\"https:\/\/99bitcoins.com\/\">99Bitcoins<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>According to cybersecurity firm Cado Security Labs, Web3 professionals are the latest victims of a sophisticated malware campaign that employs fake meeting apps to steal sensitive credentials and crypto assets. In a report released on December 6, Cado\u2019s threat research lead, Tara Gould, detailed how scammers are leveraging artificial intelligence (AI) to craft convincing websites [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":26865,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-26864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-discovery"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/26864"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26864"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/26864\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/26865"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}