Cybersecurity researchers are warning of a new scam campaign that leverages fake video calling apps to spread the Realst malware .

This malware targets Web3, exploiting sophisticated deception strategies.
Criminals create fake companies, enhancing their credibility with the use of artificial intelligence (AI), and approach their victims via Telegram, pretending to be business meetings. Victims are invited to download applications from websites with seemingly trustworthy names, such as Meeten, Clusee and Meetio, which then install the malware.
Read more: Hackers abuse Google Ads to spread Fakebat malware
For macOS users, the app displays a message asking them to enter their system password, using the “osascript” technique. Realst is designed to steal sensitive data such as cryptocurrencies, Telegram accounts, banking information, and cookies from browsers such as Chrome, Edge, and Brave.
The Windows version includes an NSIS installer, possibly signed with a stolen signature, that installs an Electron application. This, in turn, downloads malware from malicious websites. The software, written in the Rust language, collects data and sends it to remote servers.
See also: Beware! The SmokeLoader malware is back!
Criminals are enhancing the credibility of their fake websites by creating realistic content through AI, making the scam extremely difficult to detect. Similar campaigns in the past, such as “meethub.gg” and “markopolo,” targeted cryptocurrency users with similar methods.

This activity is also associated with new malware families, such as Fickle Stealer and Celestial Stealer, while older families, such as Banshee Stealer, have now been abandoned. At the same time, users who download pirated software or artificial intelligence tools often fall victim to malware, such as RedLine Stealer.
Read more: Malicious TIDRONE gang targets drone manufacturers in Taiwan
The campaign appears to be primarily targeting Russian-speaking entrepreneurs using automation software, once again demonstrating the increasing sophistication and sophisticated strategy of cybercriminals.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
