Fake Gaming and AI Startups Target Cryptocurrency Users with Malware on Telegram and Discord

Cryptocurrency users are currently facing a social engineering campaign where fake startup companies trick them into downloading malware that can drain digital assets from both Windows and mac OS systems.
According to Darktrace researcher Tara Gould, these malicious operations impersonate AI, gaming, and Web3 firms, using spoofed social media accounts and legitimate project documentation hosted on platforms like Notion and GitHub.


This elaborate scam has been ongoing, with a previous iteration in December 2024 involving bogus videoconferencing platforms to lure victims into downloading malicious software.
The latest findings indicate that the campaign, codenamed "Meeten" by Cado Security, has expanded its themes to include artificial intelligence, gaming, and social media. Attackers have been observed using compromised verified X accounts to approach potential targets, creating an illusion of legitimacy for their fake companies.


One example is Eternal Decay, a non-existent blockchain game that shares digitally altered images to appear credible. The attack begins when adversary-controlled accounts message victims, offering cryptocurrency payments in exchange for testing their software. Victims are then redirected to fictitious websites to download malicious applications.
On Windows, the malware masquerades as a Cloudflare verification screen while it profiles the machine and executes an installer. For macOS, the Atomic macOS Stealer (AMOS) is deployed, capable of siphoning documents and data from web browsers and crypto wallets.
"NPAV recommends home users and organizations to maintain strong, up-to-date cybersecurity measures. Install NPAV on your desktop, laptop, and mobile devices to ensure world-class protection against fraud, malware, and ransomware attacks.
Choose NPAV and be a part of our mission to make the digital world safer for everyone."
- Other (43)
- Ransomware (155)
- Events and News (27)
- Features (45)
- Security (487)
- Tips (79)
- Google (30)
- Achievements (11)
- Products (36)
- Activation (7)
- Dealers (1)
- Bank Phishing (53)
- Malware Alerts (236)
- Cyber Attack (305)
- Data Backup (13)
- Data Breach (132)
- Phishing (165)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (71)
- Android Security (79)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (71)
- Social Media (8)
- vulnerability (76)
- Hacker (38)
- Spyware (13)
- Windows (8)
- Microsoft (26)
- Uber (1)
- YouTube (1)
- Trojan (5)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (11)
- Mozilla (2)
- COVID-19 (5)
- Instagram (4)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (6)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (54)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (43)