By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Using Fake Video Conferencing Apps to Steal Web3 Professionals’ Data
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Using Fake Video Conferencing Apps to Steal Web3 Professionals’ Data
Tech News

Hackers Using Fake Video Conferencing Apps to Steal Web3 Professionals’ Data

By Viral Trending Content 5 Min Read
Share
SHARE

Dec 07, 2024Ravie LakshmananMalware / Web3 Security

Fake Video Conferencing Apps

Cybersecurity researchers have warned of a new scam campaign that leverages fake video conferencing apps to deliver an information stealer called Realst targeting people working in Web3 under the guise of fake business meetings.

“The threat actors behind the malware have set up fake companies using AI to make them increase legitimacy,” Cado Security researcher Tara Gould said. “The company reaches out to targets to set up a video call, prompting the user to download the meeting application from the website, which is Realst infostealer.”

The activity has been codenamed Meeten by the security company, owing to the use of names such as Clusee, Cuesee, Meeten, Meetone, and Meetio for the bogus sites.

Cybersecurity

The attacks entail approaching prospective targets on Telegram to discuss a potential investment opportunity, urging them to join a video call hosted on one of the dubious platforms. Users who end up on the site are prompted to download a Windows or macOS version depending on the operating system used.

Once installed and launched on macOS, users are greeted with a message that claims “The current version of the app is not fully compatible with your version of macOS” and that they need to enter their system password in order for the app to work as expected.

This is accomplished by means of an osascript technique that has been adopted by several macOS stealer families such as Atomic macOS Stealer, Cuckoo, MacStealer, Banshee Stealer, and Cthulhu Stealer. The end goal of the attack is to steal various kinds of sensitive data, including from cryptocurrency wallets, and export them to a remote server.

The malware is also equipped to steal Telegram credentials, banking information, iCloud Keychain data, and browser cookies from Google Chrome, Microsoft Edge, Opera, Brave, Arc, Cốc Cốc, and Vivaldi.

Fake Video Conferencing Apps

The Windows version of the app Nullsoft Scriptable Installer System (NSIS) file that’s signed with a likely stolen legitimate signature from Brys Software Ltd. Embedded within the installer is an Electron application that’s configured to retrieve the stealer executable, a Rust-based binary, from an attacker-controlled domain.

“Threat actors are increasingly using AI to generate content for their campaigns,” Gould said. “Using AI enables threat actors to quickly create realistic website content that adds legitimacy to their scams, and makes it more difficult to detect suspicious websites.”

This is not the first time fake meeting software brands have been leveraged to deliver malware. Earlier this March, Jamf Threat Labs revealed that it detected a counterfeit website called meethub[.]gg to propagate a stealer malware that shares overlaps with Realst.

Then in June, Recorded Future detailed a campaign dubbed markopolo that targeted cryptocurrency users with bogus virtual meeting software to drain their wallets by using stealers like Rhadamanthys, Stealc, and Atomic.

Cybersecurity

The development comes as the threat actors behind the Banshee Stealer macOS malware shut down their operations after the leak of their source code. It’s unclear what prompted the leak. The malware was advertised on cybercrime forums for a monthly subscription of $3,000.

It also follows the emergence of new stealer malware families like Fickle Stealer, Wish Stealer, Hexon Stealer, and Celestial Stealer, even as users and businesses searching for pirated software and AI tools are being targeted with RedLine Stealer and Poseidon Stealer, respectively.

“The attackers behind this campaign are clearly interested in gaining access to organizations of Russian-speaking entrepreneurs who use software to automate business processes,” Kaspersky said of the RedLine Stealer campaign.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

20% Off Brooks Promo Code & Deals for November 2025

Nexperia confident of ‘de-escalation’ but can’t guarantee Chinese chips quality

Bag A Sky Glass Air 4K TV For Just £3pm In Huge Early Black Friday Sale

DJI Zenmuse L3 LiDAR Specs & Performance : 950M Range & Dual 100 MP Cameras

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

TAGGED: artificial intelligence, cryptocurrency, Cyber Security, Cybercrime, Cybersecurity, data theft, Internet, MacOS, Malware, phishing, web3, Windows
Share This Article
Facebook Twitter Copy Link
Previous Article Speaker Johnson Confident in Hegseth’s Confirmation: ‘Momentum’s Moving the Right Way’
Next Article Pepe memecoin flips Uniswap token in market cap, hits all-time high
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

20% Off Brooks Promo Code & Deals for November 2025
Tech News
Seahawks WR Rashid Shaheed Eyes Extension After Trade: 'I'm Here to Stay'
Sports
Bitcoin shaken by long-term holders dumping $45 billion
Business
Rain launches its decentralized prediction markets protocol, where anyone can create their own market – private or public
Crypto
Bitcoin Finally Recovers — Why Bitcoin Hyper Becomes One of the Best Crypto to Buy
Crypto
Nexperia confident of ‘de-escalation’ but can’t guarantee Chinese chips quality
Tech News
Is France going to link its digital ID to your social media accounts?
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

20% Off Brooks Promo Code & Deals for November 2025

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
20% Off Brooks Promo Code & Deals for November 2025
November 6, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?