BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Crypto Startups Use Social Media to Spread Wallet-Stealing Malware

Fake Tech Startups Target Crypto Users With Sophisticated Malware Scam Across Social Media Platforms

  • Cybercriminals are targeting cryptocurrency users with fake startup companies to distribute Malware.
  • The campaign uses realistic websites, social media accounts, and professional-looking documentation to appear legitimate.
  • Attackers impersonate AI, gaming, and Web3 companies on platforms such as X, Telegram, and Discord.
  • The malware affects both Windows and macOS, stealing crypto wallet data and personal information.
  • Victims are lured by offers to test new software for cryptocurrency payment, resulting in their assets being stolen.

A sophisticated cybercrime campaign is targeting cryptocurrency users by impersonating new technology companies and tricking them into downloading malware disguised as legitimate software. The fraudulent scheme affects users on Windows and macOS and aims to steal digital assets by convincing victims to interact with fake companies across various social media platforms.

- Advertisement -

The operation, detailed by Darktrace researcher Tara Gould, uses spoofed accounts and project materials hosted on trusted sites such as Notion and GitHub. Attackers particularly focus on Artificial Intelligence, gaming, and Web3 themes. “These malicious operations impersonate AI, gaming, and Web3 firms using spoofed social media accounts and project documentation hosted on legitimate platforms like Notion and GitHub,” Gould reported. The campaign has been active since at least March 2024, with notable activity continuing through July 2025.

The attackers frequently use verified and compromised X accounts linked to actual companies or employees, making their fake brands appear more credible to potential victims. Gould noted, “They make use of sites that are used frequently with software companies such as X, Medium, GitHub, and Notion. Each company has a professional looking website that includes employees, product blogs, whitepapers and roadmaps.”

Some of the fictitious companies involved include Eternal Decay, BeeSync, Buzzu, Cloudsign, Dexis, KlastAI, Lunelior, NexLoop, NexoraCore, NexVoo, Pollens AI, Slax, Solune, Swox, Wasper, and YondaAI. Attackers approach targets via direct messages, offering payment in cryptocurrency to test out products. If victims comply, they are sent to crafted websites to download harmful applications.

On Windows, the fake app profiles the user’s machine and runs an installer believed to act as an information thief. On macOS, the malware known as Atomic macOS Stealer (AMOS) collects documents, browser data, and crypto wallet information. The installer also sets up persistence, meaning the malicious application restarts each time the computer is rebooted.

- Advertisement -

According to Darktrace, the tactic is similar to previous scams identified under the name “Meeten” and is linked to threat groups like “Crazy Evil,” who use similar malware. The campaign demonstrates a continued evolution in the complexity of tactics used to target and defraud cryptocurrency investors.

For more details on the campaign and its methods, visit the full Darktrace report. A technical overview on persistence can be found through Apple’s Launch Agent documentation.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SHIB: How a $13 Investment Could Have Made Millions

Shiba Inu (SHIB) price remains down approximately 94% from its 2021 all-time high of...

U.S. seizes $1B in Iranian crypto assets in economic crackdown

The U.S. Treasury has seized roughly $1 billion in Iranian cryptocurrency assets, doubling a...

Bipartisan Crypto Tax Bill Introduced in House

A bipartisan bill, the PARITY Act, was introduced to modernize digital asset tax rules...

Space Force Awards SpaceX $4.16B for Target-Tracking Satellites

SpaceX secured a $4.16 billion Space Force contract for a satellite-based target tracking network.This...

U.S. Approves First Bitcoin Perpetual Futures

The U.S. Commodity Futures Trading Commission (CFTC) approved the nation's first regulated Bitcoin perpetual...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading