Voted Coins
follow us on twitter . like us on facebook . follow us on instagram . subscribe to our youtube channel . announcements on telegram channel . ask urgent question ONLY . Subscribe to our reddit . Altcoins Talks Shop Shop




Author Topic: Fake Zoom malware steals crypto while it’s ‘stuck’ loading, user warns  (Read 2686 times)

Offline Yamane_Keto

  • Hero Member
  • *
  • *
  • Activity: 728
  • points:
    35364
  • Karma: 57
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 18, 2025, 02:21:20 AM
    • View Profile

  • Total Badges: 13
    Badges: (View All)
    One year Anniversary 500 Posts Search


Once installed, the page will redirect back to the official Zoom platform, making the user believe it worked, but by then, the malware has already infiltrated the target computer and stolen the data and loot, explained Drew.

source https://cointelegraph.com/news/fake-zoom-malware-steals-crypto-while-stuck-loading-user-warns

scammers have become very smart. The phishing link is very similar to the real link, after which you are directed to a page that remains stuck and you are asked to download an application similar to the Zoom application that adds itself to the Windows Defender exceptions list to prevent anti-virus systems from blocking it.

Altcoins Talks - Cryptocurrency Forum


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Offline yhiaali3

  • Legendary
  • *
  • *
  • Activity: 3003
  • points:
    224806
  • Karma: 188
  • Bitcoin Mixer| Since 2019
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 01:53:28 PM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    2500 Posts One year Anniversary Linux User
Apparently we are seeing a growing wave of cryptocurrency scams via social engineering by receiving emails or impersonating influencers and executives. Fraudsters are constantly innovating new methods and improving their fraudulent skills.

I was really intrigued by this type of hacking that relies on a combination of social engineering and camouflage by giving the user the illusion of a normal installation while the suspicious program runs in the background and adds itself to the Windows Firewall.

The best solution is for people to refrain from installing any program from a source that is not 100% reliable, and to avoid clicking on links in emails or social media messages.

Altcoins Talks - Cryptocurrency Forum


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Offline Yamane_Keto

  • Hero Member
  • *
  • *
  • Activity: 728
  • points:
    35364
  • Karma: 57
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 18, 2025, 02:21:20 AM
    • View Profile

  • Total Badges: 13
    Badges: (View All)
    One year Anniversary 500 Posts Search
The best solution is for people to refrain from installing any program from a source that is not 100% reliable, and to avoid clicking on links in emails or social media messages.
These programs have become smart enough to bypass firewalls and anti-virus programs, so you should limit yourself to downloading trusted or open source programs and make sure that you are in the correct domain.

Offline dkbit98

  • Legendary
  • *
  • *
  • Activity: 2638
  • points:
    157552
  • Karma: 235
  • Mixero: Privacy by XMR (Monero) bridge
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: May 02, 2025, 09:50:09 PM
    • View Profile

  • Total Badges: 23
    Badges: (View All)
    2500 Posts 10 Poll Votes Fifth year Anniversary
Let me take a wild guess without reading any details, this malware works only on wind0ws operating system  :P
I have seen similar cases posted in bitcointalk forum and all of them include some kind of .exe file that first needs to be installed.
wind0ws OS is one big malware and closed source spyware black box.
█████████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
██████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████████████████████
█████████████████████████████████████████████████████████████████████████████
.
MixTum.io
.
█████████████████████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
.
▀▄ Premium Bitcoin Mixer ▄▀
█████
██
██
██
██
██
██
██
██
██
██
██
█████
███████████████████████████████████████████████████████████████
.
MIX FREE
Up to 1mBTC
.
███████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
████████████████████████
█████████████▀▀████████
████████████▀▄█████████
██████████▀▌▄██████████
██████████▌███████████
█████████▀▄███▀████████
██████▀▄▄██████▀███████
█████▀▄█▀▄████████████
██████▀▄█▌▐████▐█████
█████▌▐█▀▌▐█████▐█████
██████████████▄██████
███████▄██████▄████████
████████████████████████

Offline KingsDen

  • Legendary
  • *
  • *
  • Activity: 2211
  • points:
    151370
  • Karma: 278
  • Automatic cryptocurrency mixer
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 01:06:29 PM
    • View Profile

  • Total Badges: 21
    Badges: (View All)
    Third year Anniversary Poll Starter Karma Bad

I do not quite understand this infographics. Was it trying to show the fake url being overlapped by the correct URL?

scammers have become very smart. The phishing link is very similar to the real link, after which you are directed to a page that remains stuck and you are asked to download an application similar to the Zoom application that adds itself to the Windows Defender exceptions list to prevent anti-virus systems from blocking it.
Scammers are just negatively smart... I will not be proud to call that smartness, they are innovative in the wrong lane. A developer that can do this type of expensive fishing could also do other better things to earn a living.
▄▄█████████░██████▄▄
████████████░███████
████████████░░███████
████████░░░░░░███████
██████████░░▄░████
█████████░░░█░██████
█████████░░░░░███████
████████░░░██░█████
██████░░░░░▀▀░███████
████████░░▄░░░████
███████████▄▄░████████
████████████░█████████
▀▀██████████░███████▀▀
CoinTor
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

                              ██████████████████████████████████     ██     ████████████████████████
Automatic Cryptocurrency Mixer
██████████████████████████████████     ██████████████████████     ████     

████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████

M I X   N O W
██████
██
██
██
██
██
██
██
██
██
██
██
██████

Offline Yamane_Keto

  • Hero Member
  • *
  • *
  • Activity: 728
  • points:
    35364
  • Karma: 57
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 18, 2025, 02:21:20 AM
    • View Profile

  • Total Badges: 13
    Badges: (View All)
    One year Anniversary 500 Posts Search
I do not quite understand this infographics. Was it trying to show the fake url being overlapped by the correct URL?
phishing link begins with Zoom DOT us50web DOT us, and is sent via chat after starting a real Zoom call. If you are in a hurry, it will be difficult to notice that it is a phishing link.



Offline KingsDen

  • Legendary
  • *
  • *
  • Activity: 2211
  • points:
    151370
  • Karma: 278
  • Automatic cryptocurrency mixer
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 01:06:29 PM
    • View Profile

  • Total Badges: 21
    Badges: (View All)
    Third year Anniversary Poll Starter Karma Bad
I do not quite understand this infographics. Was it trying to show the fake url being overlapped by the correct URL?
phishing link begins with Zoom DOT us50web DOT us, and is sent via chat after starting a real Zoom call. If you are in a hurry, it will be difficult to notice that it is a phishing link.


Oh!
Now I understand better... These guys are just being innovative everyday. We just need to be extremely careful in this space.
▄▄█████████░██████▄▄
████████████░███████
████████████░░███████
████████░░░░░░███████
██████████░░▄░████
█████████░░░█░██████
█████████░░░░░███████
████████░░░██░█████
██████░░░░░▀▀░███████
████████░░▄░░░████
███████████▄▄░████████
████████████░█████████
▀▀██████████░███████▀▀
CoinTor
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

                              ██████████████████████████████████     ██     ████████████████████████
Automatic Cryptocurrency Mixer
██████████████████████████████████     ██████████████████████     ████     

████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████

M I X   N O W
██████
██
██
██
██
██
██
██
██
██
██
██
██████

Altcoins Talks - Cryptocurrency Forum


Offline bitterguy28

  • Legendary
  • *
  • *
  • Activity: 3747
  • points:
    564672
  • Karma: 298
  • Coinomize.biz | Bitcoin Mixer| Since 2019
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 03:58:00 PM
    • View Profile

  • Total Badges: 20
    Badges: (View All)
    One year Anniversary 2500 Posts Search
The best solution is for people to refrain from installing any program from a source that is not 100% reliable, and to avoid clicking on links in emails or social media messages.
these suspicious links are usually sent in fishy websites and emails so make sure that you check from where these messages are coming from and ignore anything suspicious better yet block and report any user who sends you messages and spams make sure to not open anything unreliable

thanks to op for bringing awareness because a lot of scams and hacks can be avoided if we just know the real domains and safe links

Offline yhiaali3

  • Legendary
  • *
  • *
  • Activity: 3003
  • points:
    224806
  • Karma: 188
  • Bitcoin Mixer| Since 2019
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 01:53:28 PM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    2500 Posts One year Anniversary Linux User
The best solution is for people to refrain from installing any program from a source that is not 100% reliable, and to avoid clicking on links in emails or social media messages.
these suspicious links are usually sent in fishy websites and emails so make sure that you check from where these messages are coming from and ignore anything suspicious better yet block and report any user who sends you messages and spams make sure to not open anything unreliable

thanks to op for bringing awareness because a lot of scams and hacks can be avoided if we just know the real domains and safe links
Yes, it is true, but in such cases it is difficult to know the safe links because these new types use social engineering where the user is first deceived through the conversation that the link that was sent is safe, so you must pay close attention to this point and deal with extreme caution with this space full of scammers.

Offline Lucius

  • Legendary
  • *
  • *
  • *
  • Activity: 2776
  • points:
    230889
  • Karma: 530
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: Today at 04:39:20 PM
    • View Profile

  • Total Badges: 18
    Badges: (View All)
    One year Anniversary 2500 Posts Poll Starter
The best solution is for people to refrain from installing any program from a source that is not 100% reliable, and to avoid clicking on links in emails or social media messages.
These programs have become smart enough to bypass firewalls and anti-virus programs, so you should limit yourself to downloading trusted or open source programs and make sure that you are in the correct domain.

It's not that the programs have become smarter, but the thing is that people can never wise up and realize that nothing happens by itself, but that they themselves are mostly to blame for such things. If your AV and firewall warns you that something is wrong and that you should not allow a download or installation, then in most cases you should listen and not give permission for such an action. Of course, false detections can always happen, but if someone already has protection, then it should be allowed to do its job.
█████████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
██████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████████████████████
█████████████████████████████████████████████████████████████████████████████
.
MixTum.io
.
█████████████████████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
.
▀▄ Premium Bitcoin Mixer ▄▀
█████
██
██
██
██
██
██
██
██
██
██
██
█████
███████████████████████████████████████████████████████████████
.
MIX FREE
Up to 1mBTC
.
███████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
████████████████████████
█████████████▀▀████████
████████████▀▄█████████
██████████▀▌▄██████████
██████████▌███████████
█████████▀▄███▀████████
██████▀▄▄██████▀███████
█████▀▄█▀▄████████████
██████▀▄█▌▐████▐█████
█████▌▐█▀▌▐█████▐█████
██████████████▄██████
███████▄██████▄████████
████████████████████████

Offline Yamane_Keto

  • Hero Member
  • *
  • *
  • Activity: 728
  • points:
    35364
  • Karma: 57
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 18, 2025, 02:21:20 AM
    • View Profile

  • Total Badges: 13
    Badges: (View All)
    One year Anniversary 500 Posts Search
these suspicious links are usually sent in fishy websites and emails so make sure that you check from where these messages are coming from and ignore anything suspicious better yet block and report any user who sends you messages and spams make sure to not open anything unreliable
It would be easier to spot this way but what happened is part of a social attack where they make a recruitment call and make up an excuse to hang up and then send you a phishing link, you probably won't pay attention to the URL details and will click on it.

If your AV and firewall warns you that something is wrong and that you should not allow a download or installation, then in most cases you should listen and not give permission for such an action. Of course, false detections can always happen, but if someone already has protection, then it should be allowed to do its job.
Sometimes it gives the impression that the links are safe but the virus database is not up to date.

Offline Cantsay

  • Legendary
  • *
  • *
  • Activity: 1643
  • points:
    114506
  • Karma: 131
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: May 02, 2025, 11:59:18 PM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    One year Anniversary 10 Poll Votes Quick Poster
It would be easier to spot this way but what happened is part of a social attack where they make a recruitment call and make up an excuse to hang up and then send you a phishing link, you probably won't pay attention to the URL details and will click on it.


If this had happened to me I definitely would have fell for it because I actually didn’t know the real url of zoom (before coming across this thread) - so if they had used this method of canceling their google meet and switching to zoom meeting impromptu and then sharing links I won’t have bothered to double check if it was correct or not.

Thanks for sharing.
███████████▄
████████▄▄██
█████████▀█
███████████▄███████▄
█████▄█▄██████████████
████▄█▀▄░█████▄████████
████▄███░████████████▀
████░█████░█████▀▄▄▄▄▄
█████░█
██░█████████▀▀
░▄█▀
███░░▀▀▀██████
▀███████▄█▀▀▀██████▀
░░████▄▀░▀▀▀▀████▀

██
██
██
██
██
██
██
██
██
██
██


██
██
██
██
██
██
██
██
██
██
██

█████████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████████

████████████

CASINO

██████
██
██
██
██
██
██
██
██
██
██████

█████████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████████

████████████

SPORTS

██████
██
██
██
██
██
██
██
██
██
██████
.
SOL   USDT   BTC   TONJOIN NOW
      BTC   TON   SOL   USDT

Offline yhiaali3

  • Legendary
  • *
  • *
  • Activity: 3003
  • points:
    224806
  • Karma: 188
  • Bitcoin Mixer| Since 2019
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 01:53:28 PM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    2500 Posts One year Anniversary Linux User
It's not that the programs have become smarter, but the thing is that people can never wise up and realize that nothing happens by itself, but that they themselves are mostly to blame for such things. If your AV and firewall warns you that something is wrong and that you should not allow a download or installation, then in most cases you should listen and not give permission for such an action. Of course, false detections can always happen, but if someone already has protection, then it should be allowed to do its job.
Unfortunately this is true, most of the cases that happen are due to users allowing the malware to install and give it permissions due to ignorance, greed or haste.

A few days ago I received an email that appeared to be from the PreSearch to distribute an airdrop to old members according to what they have in their wallets, the message claims that each user will get about 43,000 PRE tokens which is worth about $600, everyone who clicked on the link and connected their wallet and gave permission to the malicious site was exposed to hacking their wallet and stealing their assets.

Offline Crwth

  • Legendary
  • *
  • *
  • *
  • Activity: 1959
  • points:
    48448
  • Karma: 149
  • Mixero: Privacy by XMR (Monero) bridge
  • Trade Count: (0)
  • Referrals: 1
  • Last Active: Today at 10:25:28 AM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    Linux User One year Anniversary Quick Poster
It is quite confusing to be honest. If I were to get something like that, I think I would be confused as well, but thank you for this information. I think I would be more careful with the Zoom link.
░░░░░░░░░░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░░░░░░░░░░░░░░░█████████████
░░░░░░█████████░░█████████████
░░░░░░█████████
░░░░░░█████████
░░░░░░█████████░░░░█████████
░░░░░░░░░░░░░░░░░░░█████████
████░░░░░░░░░░░░░░█████████
████░░░░░░░░░░░░░░█████████
██████████████████████████████
█████████▀▀███▀▀░░▀▀▀█████████
███████▀░░█▀░░░░▄▄▄▄▄▄▄███████
██████░░░██░░▄█▀▀░░░░░▀▀██████
█████░░░░█░░███████▄▄▄░░░▀████
███░██░░░█▄████████▄░▀█▄░░░███
███░░██░░░███████████░░▀█▄░███
████░░▀██▄▄████████░██░░░█▄███
█████░░░░░▀▀▀▀▀▀██░░██░░░█████
███████▄▄▄▄▄▄▄█▀░░░▄█░░░██████
████████▀▀▀▀░░░░░░██░░▄███████
██████████▄▄▄▄▄████▄██████████
██████████████████████████████
██████████████████████████████████████████████████████████████████████████████████
.
MIXERO.IO
.
██████████████████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
..
..
..
..
..
..
..
..
██████████████████████████████
███████▀▀██░▀█████████████████
████████░░█░█▀▀░██████████████
████████░░▀░░░▄███████████████
██████▀░░░░░░░░░▀██████░▀█████
████▀░░░░░░░░░░░░░██▀▀█▄░░████
████░░░░░░░░░░░▄████▄░▀██░░███
████░░░░░░░░░▄██▀░▄██░░██░░███
█████░░░░░░▄██▀████▀░░██░░████
███████▄▄▄████▄░░░░▄██▀░░█████
███████████░░▀▀▀██▀▀▀░░▄██████
██████████████▄▄▄▄▄▄██████████
██████████████████████████████
..
..
..
..
████
██
██
██
██
██
██
██
██
██
██
██
████
██████████████████████████████████████████████████████████████████████
.
MIX.NOW
.
██████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
█████████████
█████████████
░░░░░░░░░██████
█████████████░░░░██░░░██████
█████████████░░░░░░░░░██████
█████████████
█████████████░░█████████
░░░░░░░░░░░░░░░█████████
░░░░░░░░░░░░░░░█████████
░░█████████░░░░█████████
░░█████████
░░█████████░░░██░░░░░░░░░░████
░░█████████░░░░░░░░░░░░░░░████

Offline Lucius

  • Legendary
  • *
  • *
  • *
  • Activity: 2776
  • points:
    230889
  • Karma: 530
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: Today at 04:39:20 PM
    • View Profile

  • Total Badges: 18
    Badges: (View All)
    One year Anniversary 2500 Posts Poll Starter
If your AV and firewall warns you that something is wrong and that you should not allow a download or installation, then in most cases you should listen and not give permission for such an action. Of course, false detections can always happen, but if someone already has protection, then it should be allowed to do its job.
Sometimes it gives the impression that the links are safe but the virus database is not up to date.

A good AV will upgrade its database of AV definitions at least once every 24 hours, and even if some definitions are not in the database, a good AV will always protect you through heuristic analysis. Of course, you need to spend a little more money for good AV, and most people use free or cheap AV programs that actually do more harm than good.
█████████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
██████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████████████████████
█████████████████████████████████████████████████████████████████████████████
.
MixTum.io
.
█████████████████████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
.
▀▄ Premium Bitcoin Mixer ▄▀
█████
██
██
██
██
██
██
██
██
██
██
██
█████
███████████████████████████████████████████████████████████████
.
MIX FREE
Up to 1mBTC
.
███████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
████████████████████████
█████████████▀▀████████
████████████▀▄█████████
██████████▀▌▄██████████
██████████▌███████████
█████████▀▄███▀████████
██████▀▄▄██████▀███████
█████▀▄█▀▄████████████
██████▀▄█▌▐████▐█████
█████▌▐█▀▌▐█████▐█████
██████████████▄██████
███████▄██████▄████████
████████████████████████

 

ETH & ERC20 Tokens Donations: 0x2143F7146F0AadC0F9d85ea98F23273Da0e002Ab
BNB & BEP20 Tokens Donations: 0xcbDAB774B5659cB905d4db5487F9e2057b96147F
BTC Donations: bc1qjf99wr3dz9jn9fr43q28x0r50zeyxewcq8swng
BTC Tips for Moderators: 1Pz1S3d4Aiq7QE4m3MmuoUPEvKaAYbZRoG
Powered by SMFPacks Social Login Mod