Cybersecurity firm JUMPSEC uncovered the operation after analyzing source code exposed on the group’s live infrastructure. The campaign relies on a sophisticated pipeline: hackers hijack Telegram accounts to send Calendly invitations, guiding victims to lookalike meeting domains. Once a user joins the fake call, the site automatically scans the browser for Ethereum and Solana wallet connections. This data is fed to an operator panel, allowing attackers to prioritize victims holding significant assets.
The attackers enhance credibility by using AI-generated avatars and recorded footage to simulate live participants, often prompting targets to install a fake "Zoom SDK Update." On Windows, this trigger executes a PowerShell loader that modifies Microsoft Defender settings to maintain persistence. The macOS variant focuses on exfiltrating Chrome master keys and system information via the Apple Keychain. Researchers identified four distinct macOS malware versions deployed between April and July, signaling a rapid, iterative development process.

Comments (0)
No comments yet. Be the first!