On-chain investigator Taylor Monahan exposed a scheme where scammers pose as recruiters from top crypto firms.
They use platforms like LinkedIn, Telegram, and freelancing sites to lure targets with high-paying job offers.
Victims interested in an online scheme are directed to a seemingly legitimate video interview platform called “Willo | Video Interviewing.” Although the platform is not harmful, it creates an illusion of credibility in the fraudulent operation. Initially, victims face standard questions about crypto trends, which aim to establish trust and authenticity.
The scam takes a turn with the final question, requiring victims to record a video response. During this process, they encounter a fake technical issue with their microphone or camera. The attackers then provide misleading troubleshooting steps that, if followed, can grant them unauthorized access to the victims’ devices through system-level commands.
“It allows them to do anything on your device. It’s not really general purpose stealer, it’s general purpose access. Ultimately they’ll rekt you via whatever means are required,”
Monahan wrote.
This access enables attackers to bypass security measures, install malware, monitor activities, steal sensitive data, or drain cryptocurrency wallets, often without the victim’s awareness, as seen in similar attacks. Monahan advised crypto users to refrain from running unfamiliar code and recommended that anyone who may have been exposed to such attacks wipe their devices completely to prevent further security breaches.
This report follows recent warnings from blockchain security firm SlowMist about a phishing scam targeting cryptocurrency users through fake Zoom meeting links. Active since November 14, 2024, the fraud has led to millions in losses. Attackers created a counterfeit Zoom domain, “app[.]us4zoom[.]us,” tricking users into downloading a malicious file. Once installed, the file extracts sensitive data, including browser cookies, cryptocurrency wallet credentials, and Telegram login details, after executing a script that asks for system passwords.
If you want to read more news articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.
“Take control of your crypto portfolio with Markets PRO, DeFi Planet’s suite of analytics tools.”