• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Analysis of Phishing Attack Using Fake Zoom Links

user avatar

by Giorgi Kostiuk

a year ago


Recently, users reported phishing attacks using fake Zoom links, resulting in stolen crypto assets worth millions. SlowMist conducted an analysis of the incident, examining the attack methods and fund movements.

Phishing Link Analysis

Attackers used a domain similar to the legitimate Zoom domain to disguise their attack. Clicking the 'Launch Meeting' button initiated the download of malicious software instead of launching the Zoom client. The analysis revealed that attackers were using the Telegram API to monitor who clicked the download button.

Malware Analysis

The malware file was named 'ZoomApp_v.3.14.dmg' and tricked users into entering their system password. It executed a script that collected and sent data to attackers, allowing access to sensitive information like passwords and crypto wallet data.

Malicious Behavior Analysis

The analysis showed that the malicious code collected system, browser, and crypto wallet data, sending it to an attacker-controlled server in the Netherlands. Using MistTrack, it was discovered that hacker addresses received over $1 million, including ETH and other cryptocurrencies, later moved to various platforms.

Phishing attacks using Zoom links pose a significant security threat, combining social engineering and trojans. SlowMist Security Team advises users to verify meeting links carefully and use antivirus software to protect their data.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Polymarket Expands Language Options to Enhance Global Accessibility

chest

Polymarket is testing a multilingual adaptation of its website to enhance global accessibility.

user avatarMaria Gutierrez

Polymarket Faces Market Uncertainty Amid Lack of Updates

chest

Polymarket faces market uncertainty due to a lack of updates, leaving users and investors with questions about the platform's strategic direction.

user avatarAndrew Smith

Polymarket's Multilingual Platform Tests Remain Unconfirmed

chest

Polymarket is rumored to have initiated tests for a multilingual platform aimed at global users, yet no official confirmation has verified these claims.

user avatarDavid Robinson

Grayscale's Cardano ETF Application Under Review by SEC

chest

Grayscale's application for a Cardano ETF is currently under review by the US Securities and Exchange Commission, with a decision anticipated in early 2026.

user avatarZainab Kamara

Progress on Cardano Improvement Proposal Leios

chest

The Cardano Improvement Proposal Leios is progressing well, with the proposal now 67% complete.

user avatarJacob Williams

Ethereum Price Stagnates Despite High Network Activity

chest

Ethereum's price remains below $3,000 despite processing over 22 million transactions daily.

user avatarSon Min-ho

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.