HomeSecurityHackers use fake video conferencing apps to distribute Realst Malware

Hackers use fake video conferencing apps to distribute Realst Malware

Cybersecurity researchers are warning of a new scam campaign that leverages fake video calling apps to spread the Realst malware .

Realst Malware

This malware targets Web3, exploiting sophisticated deception strategies.

Criminals create fake companies, enhancing their credibility with the use of artificial intelligence (AI), and approach their victims via Telegram, pretending to be business meetings. Victims are invited to download applications from websites with seemingly trustworthy names, such as Meeten, Clusee and Meetio, which then install the malware.

Read more: Hackers abuse Google Ads to spread Fakebat malware

For macOS users, the app displays a message asking them to enter their system password, using the “osascript” technique. Realst is designed to steal sensitive data such as cryptocurrencies, Telegram accounts, banking information, and cookies from browsers such as Chrome, Edge, and Brave.

The Windows version includes an NSIS installer, possibly signed with a stolen signature, that installs an Electron application. This, in turn, downloads malware from malicious websites. The software, written in the Rust language, collects data and sends it to remote servers.

See also: Beware! The SmokeLoader malware is back!

Criminals are enhancing the credibility of their fake websites by creating realistic content through AI, making the scam extremely difficult to detect. Similar campaigns in the past, such as “meethub.gg” and “markopolo,” targeted cryptocurrency users with similar methods.

Realst Malware

This activity is also associated with new malware families, such as Fickle Stealer and Celestial Stealer, while older families, such as Banshee Stealer, have now been abandoned. At the same time, users who download pirated software or artificial intelligence tools often fall victim to malware, such as RedLine Stealer.

Read more: Malicious TIDRONE gang targets drone manufacturers in Taiwan

The campaign appears to be primarily targeting Russian-speaking entrepreneurs using automation software, once again demonstrating the increasing sophistication and sophisticated strategy of cybercriminals.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS