{"id":84726,"date":"2024-07-23T00:42:54","date_gmt":"2024-07-23T04:42:54","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=84726"},"modified":"2024-07-23T00:42:57","modified_gmt":"2024-07-23T04:42:57","slug":"fake-zoom-malware-steals-crypto-while-appearing-to-load-user-warns","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/fake-zoom-malware-steals-crypto-while-appearing-to-load-user-warns\/","title":{"rendered":"Fake Zoom Malware Steals Crypto While Appearing to Load, User Warns"},"content":{"rendered":"\n<p>Crypto scammers use fake Zoom links to install malware and steal crypto, warns <a href=\"https:\/\/coinscreed.com\/staging\/arcade-announces-3-million-arcd-token-airdrop-for-nft-collectors.html\" target=\"_blank\" rel=\"noreferrer noopener\">NFT collector<\/a> &#8220;NFT_Dreww.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"538\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy-1024x538.jpg\" alt=\"Fake Zoom Malware Steals Crypto While Appearing to Load, User Warns\" class=\"wp-image-84732\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy-1024x538.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy-300x158.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy-768x403.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy-860x452.jpg 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Fake Zoom Malware Steals Crypto While Appearing to Load, User Warns<\/figcaption><\/figure>\n\n\n\n<p>The latest weapon of crypto fraudsters is malicious links that redirect users to a webpage resembling the video conferencing platform Zoom. Upon clicking on these links, they prompt users to install malware.<\/p>\n\n\n\n<p>NFT_Dreww, a cybersecurity engineer and collector of non-fungible tokens, informed X users of a new &#8220;extremely sophisticated&#8221; crypto scam on July 22. The scam featured bogus links for Zoom.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" width=\"600\" height=\"831\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/10e7aa25-89a3-4528-9c44-52bdd17ebadc.jpg\" alt=\"\" class=\"wp-image-84729\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/10e7aa25-89a3-4528-9c44-52bdd17ebadc.jpg 600w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/10e7aa25-89a3-4528-9c44-52bdd17ebadc-217x300.jpg 217w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n\n\n\n<p>Drew clarified that, similar to numerous social engineering schemes, scammers frequently approach non-fungible token (NFT) holders or <a href=\"https:\/\/coinscreed.com\/staging\/crypto-whales-are-buying-these-3-altcoins-after-dogecoin-surge.html\" target=\"_blank\" rel=\"noreferrer noopener\">crypto whales<\/a>, inquiring as to whether they would be interested in licensing their intellectual property, inviting them to Twitter Spaces, or inviting them to join a team for a new project.<\/p>\n\n\n\n<p>Scammers will insist on utilizing Zoom and will compel the target to attend a meeting that is currently in progress by utilizing a malicious link that is difficult to detect.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" width=\"600\" height=\"504\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/50dc0e56-723d-4755-b02c-dd5a683a0dac.jpg\" alt=\"\" class=\"wp-image-84730\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/50dc0e56-723d-4755-b02c-dd5a683a0dac.jpg 600w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/50dc0e56-723d-4755-b02c-dd5a683a0dac-300x252.jpg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n\n\n\n<p>The user will be presented with a &#8220;stuck&#8221; page that displays an infinite loading screen upon clicking the link. The user will be prompted to obtain and install ZoomInstallerFull.exe, which is actually malware.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"346\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/d53354c7-732b-4b9a-89e5-b3f99ebbd5c6.jpg\" alt=\"\" class=\"wp-image-84731\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/d53354c7-732b-4b9a-89e5-b3f99ebbd5c6.jpg 600w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/d53354c7-732b-4b9a-89e5-b3f99ebbd5c6-300x173.jpg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n\n\n\n<p>Drew explained that the malware had already infiltrated the target computer and stolen the data and wealth when the page was redirected back to the official\u00a0Zoom platform\u00a0after installation, causing the user to believe that the installation was successful.<\/p>\n\n\n\n<p>To prevent antivirus systems from blocking the malware, it is added to the Windows Defender exclusion list upon its initial execution, per technologist &#8220;Cipher0091,&#8221; whom Drew also attributes to his X thread.<\/p>\n\n\n\n<p>Drew explained that the software will distract you with the &#8220;spinning loading page&#8221; and the process of accepting terms and conditions while it will then begin executing and extracting all of your information.<\/p>\n\n\n\n<p>He also stated that the scammers will continue to alter their domain names to avoid being flagged, and this was their fifth domain for this scheme thus far.<\/p>\n\n\n\n<p>Social engineering Cryptocurrency frauds are not novel; however, they are constantly changing. This week, numerous <a href=\"https:\/\/www.linkedin.com\/pulse\/best-10-crypto-communities-worth-joining-2024-leon-schmidt-odcpe\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">crypto community<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> members have reported receiving malicious emails from fraudsters impersonating other <a href=\"https:\/\/coinscreed.com\/staging\/due-to-the-ftx-lawsuits-crypto-influencers-are-rejecting-lucrative-endorsement-offers-over-concerns-about-the-companys-future.html\" target=\"_blank\" rel=\"noreferrer noopener\">crypto influencers<\/a> and executives.<\/p>\n\n\n\n<p>The email contains a pernicious attachment that, upon execution, is likely to install crypto-stealing malware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crypto scammers use fake Zoom links to install malware and steal crypto, warns NFT collector &#8220;NFT_Dreww.&#8221; The latest weapon of crypto fraudsters is malicious links that redirect users to a webpage resembling the video conferencing platform Zoom. Upon clicking on these links, they prompt users to install malware. NFT_Dreww, a cybersecurity engineer and collector of [&hellip;]<\/p>\n","protected":false},"author":36,"featured_media":84732,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[132,20731,20730],"class_list":["post-84726","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-crypto","tag-fake-zoom-malware","tag-user-warns"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/07\/Phishing_Andrea_Danti_Alamy.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/84726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/36"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=84726"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/84726\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/84732"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=84726"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=84726"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=84726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}