HomeSecurityFake gaming and AI companies distribute malware to crypto users

Fake gaming and AI companies are distributing malware to crypto users

Crypto users are being targeted by a new, well-designed social engineering campaign that uses fake startups in the fields of artificial intelligence, Web 3, and gaming to spread malware aimed at stealing digital assets.

Fake gaming and AI companies are distributing malware to crypto users

According to a report by Darktrace, attackers are creating fake companies. Using fake social media accounts, storefront websites, and project documentation on legitimate platforms like GitHub and Notion, they attempt to convince unsuspecting users to install applications that hide sophisticated malware for Windows and macOS.

From Telegram to Crypto Wallets: The Timeline of Fraud

The method is not new. A similar campaign was recorded in December 2024, with fake video conferencing platforms inviting victims to participate in “investment presentations.” The malware at that time was called Realst and was installed via fake software installations.

See also: Charges against two men for the “OmegaPro” crypto scam

Now, the campaign seems to have evolved, focusing on topics that are popular and appealing to the crypto community, such as artificial intelligence, blockchain games, and Web3. Fictitious companies like Eternal Decay (@metaversedecay) appear with fake conference images on social media accounts and entire websites, with information about supposed products in development, whitepapers, and employees. The ultimate goal is to create an online presence that makes these companies seem as real as possible, increasing the likelihood of infection.

Some of the other companies that have been recognized are listed below:

  • BeeSync (X accounts: @BeeSyncAI, @AIBeeSync)
  • Buzzu (X accounts: @BuzzuApp, @AI_Buzzu, @AppBuzzu, @BuzzuApp)
  • Cloudsign (X account: @cloudsignapp)
  • Dexis (X account: @DexisApp)
  • KlastAI (X account: Links to Pollens AI's X account)
  • Lunelior
  • NexLoop (X account: @nexloopspace)
  • NexoraCore
  • NexVoo (X account: @Nexvoospace)
  • Pollens AI (X accounts: @pollensapp, @Pollens_app)
  • Slax (X accounts: @SlaxApp, @Slax_app, @slaxproject)
  • Solune (X account: @soluneapp)
  • Swox (X accounts: @SwoxApp, @Swox_AI, @swox_app, @App_Swox, @AppSwox, @SwoxProject, @ProjectSwox)
  • Wasper (X accounts: @wasperAI, @WasperSpace)
  • YondaAI (X account: @yondaspace)

See also: Exposed JDWP interfaces lead to crypto mining and DDoS

Fake gaming and AI companies are distributing malware to crypto users

The Method of Attack: From Social Media to Stealer Malware

The attacks begin when cybercriminals contact potential victims via X (Twitter), Telegram or Discord, offering them to try out the alleged product in exchange for a crypto reward. Targets are taken to legitimate-looking websites and asked to download either a Windows Electron application or a DMG (macOS), depending on the operating system.

  • In the Windows environment, the program displays a fake Cloudflare verification, while in the background it installs identity-stealing.
  • On macOS, Atomic macOS Stealer (AMOS) — a malicious program that steals browsing data, documents, and crypto wallets.

The DMG binary also includes a shell script to persist on the system. The script also retrieves and executes an Objective-C/Swift binary that records application usage and user interaction timestamps and transmits them to a remote server.

Who is behind the campaign?

Darktrace reports similarities between this campaign and the tactics of the Crazy Evil, which has previously used similar methods to spread malware such as StealC and Angel Drainer. While a direct connection has not been confirmed, the deception tactics and technical means remain similar.

See also: 2025 hacks: Crypto losses have already surpassed 2024 losses

Fake gaming and AI companies are distributing malware to crypto users

What Users Can Do

  • Social media vigilance: Fake accounts often appear professional and may even be verified.
  • Avoid unknown applications: Do not download software from unverified sources or unknown links.
  • Update operating system and antivirus: The latest patches and detection mechanisms can significantly limit exposure.
  • Checking application permissions and activity: Especially on macOS, DMG files and launch agents should be examined carefully.

This new social engineering campaign highlights the growing convergence of digital deception, technological persuasion and cybercrime. With threats evolving daily, protecting digital assets requires awareness, vigilance and strategic response.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS