A social engineering campaign targeted Web3 job seekers by staging fake job interviews through a malicious meeting app called “GrassCall.” The attackers’ goal was to install info-stealer malware on the targets’ devices to steal crypto wallets .

Hundreds of prospective employees have reportedly been affected by this scam, with some reporting that their wallets were emptied.
A Telegram group has been created , where victims discuss the attack and try to help each other remove the malware from Mac and Windows devices.
GrassCall: New social engineering attack
The malicious campaign was carried out by a Russian-speaking group known as Crazy Evil. This group is known for conducting social engineering attacks to trick users into downloading malware onto their devices. In the past, it has targeted crypto users several times, tricking them with fake games or job opportunities via social media.
See also: Bybit Hack Steals $1.5 Billion from Crypto Markets
Users are tricked into installing seemingly legitimate software, which deploys info-stealer malware on devices to steal passwords, authentication cookies, and crypto wallets.
A web3 professional targeted by the attack reportedly said that the attackers created an elaborate online persona, consisting of a website and profiles on X and LinkedIn. The attackers pretended to be a company called “ChainSeeker.io.”
Then, they displayed jobs on LinkedIn, WellFound, as well as CryptoJobsList, one of the most popular job sites for Web3 and blockchain careers.
Applicants for the supposed jobs received an email containing an invitation to interview with the company's Chief Marketing Officer (CMO). Targets were asked to contact the executive via Telegram to coordinate the meeting.

There, the fake CMO told the target that they needed to download a video conferencing software called “GrassCall,” using the provided website and a code.
Targets downloaded the GrassCall software from “grasscall[.]net.” This provided a Windows or Mac client, depending on the visitor’s browser user agent.
Cybersecurity researcher g0njxa told BleepingComputer that the GrassCall website is a clone of a “Gatherum” website used in a previous campaign. According to him, these websites are used in attacks carried out by a subgroup of the Russian Crazy Evil group known as “kevland.”
See also: Fake CS2 streams steal crypto and Steam accounts
When visitors attempt to download the GrassCall app, they will be asked to enter the code provided by the fake CMO.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Upon entering the correct code, the website will offer either a Windows “GrassCall.exe” client [VirusTotal] or a Mac “GrassCall_v.6.10.dmg” [VirusTotal] client. When executed, both programs will install info-stealer malware or remote access trojans (RATs).
On Windows devices , the fake GrassCall app will install a RAT along with an info-stealer, such as Rhadamanthys. On Macs , it will install the Atomic (AMOS) Stealer malware
The malware steals files based on keywords, crypto wallets, passwords stored in Apple Keychain , and passwords and authentication cookies stored in web browsers. The stolen data then ends up in the hands of attackers.
“If a wallet is found, the passwords are bruteforced to steal the assets and a payment is issued to the user who made the victim download the fake software,” researcher g0njxa told BleepingComputer.
The researcher says that payment information for Crazy Evil members is posted on Telegram, revealing that members of this operation can earn tens, if not hundreds of thousands of dollars for each victim.
In response to the attacks, CryptoJobsList removed the job listings and warned those who applied to scan their devices for malware.
The threat actors appear to have ended this particular campaign, with the website no longer available.
See also: StaryDobry: New malware campaign infects gamers with cryptominer
However, for those who accidentally installed the software, it is imperative that they change their passwords, passphrases, and authentication tokens on all websites they visited and their crypto wallets.

Protection
Web3 job candidates should be especially wary of interview invitations via unknown or untrustworthy apps. Before accepting any invitation, it is important to verify the authenticity of the company and the person approaching them.
It is critical to use strong and unique passwords for their crypto wallets and enable multi-factor authentication where possible. This adds an extra layer of security, making it more difficult for malicious users to gain access.
See also: Two Estonians admitted to their participation in Crypto Ponzi 577
Candidates should also avoid downloading apps or software from untrusted sources. It is preferable to download apps only from official websites or app stores to reduce the risk of malware infection.
Finally, it is important to keep their systems and software up to date with the latest security patches. These patches often include fixes for vulnerabilities that attackers can exploit.
Source: www.bleepingcomputer.com
