Cointime

Download App
iOS & Android

Scammers are using Telegram verification bots to inject crypto-stealing malware

From cointelegraph by Stephen Katte

Scammers are combining social engineering with phony Telegram verification bots that inject crypto-stealing malware into systems to raid crypto wallets, blockchain security firm Scam Sniffer said. 

In a Dec. 10 X post, the security firm said scammers are creating fake X accounts impersonating popular crypto influencers, then inviting users to Telegram groups with promises of investment insights.

Once in the Telegram group, users are asked to verify through “OfficiaISafeguardBot,” a fake verification bot that “creates artificial urgency” with short verification windows, the firm said.

  Scammers impersonate popular crypto influencers on X and then invite users to malicious Telegram groups. Source: Scam Sniffer

The bot then injects a malicious PowerShell code that downloads and runs malware to compromise computer systems and crypto wallets. Scam Sniffer said it has noted “numerous cases” where similar malware led to the theft of private keys.

Scam Sniffer told Cointelegraph that the recent known cases of this type of scam were all caused by the fake verification bot.

“It’s currently unclear if there are other malicious bots. However, it’s obviously simple for them to impersonate others as well,” the firm said. 

According to Scam Sniffer, malware that targets regular users has “existed for a long time,” but the infrastructure behind such malicious software is “developing rapidly” and becoming “quite sophisticated.”

It explained that when scammers have successful heists and demand grows, they evolve into a scam-as-a-service, similar to crypto wallet-draining software makers hiring out their tools to phishing scammers.

Scam Sniffer added while it had seen malware distributed through Telegram and instances of scammers impersonating others to trick run malicious code, “this is the first time we’re seeing this specific combination of fake X accounts, fake Telegram channels and malicious Telegram bots.”

  The fake Safeguard bot caused all recent and known cases of this scam type. Source: Scam Sniffer

Meanwhile, the security firm said it has noted a surge in scammers impersonating others on X and shilling sham links and tokens. 

On average, Scam Sniffer’s monitoring system has found 300 X impersonators a day so far this month, compared with the November average of 160.

At least two victims have lost over $3 million from clicking malicious links and signing transactions from some of these fake accounts, it added.

Related: Misspelling Soneium on Google could drain your crypto wallet: Scam Sniffer

Cado Security Labs also sounded the alarm that Web3 workers are being targeted by a campaign using fake meeting apps to inject malware and steal credentials to websites, apps and crypto wallets. 

Web3 security platform Cyvers similarly warned this month that phishing attacks may surge in December as hackers attempt to exploit the growth in online transactions ahead of the holiday season.

Comments

All Comments

Recommended for you

  • USD/CNH breaks through 7.3000 yuan mark

    US dollar against the offshore RMB just broke through the 7.3000 yuan mark, with the latest report of 7.2999 yuan, up 0.03% on the day; the US dollar against the onshore RMB is now reported at 7.2990 yuan, up 0.01% on the day.

  • Spot gold breaks through $3,330/ounce, setting a new record high

    spot gold continued to rise, breaking through $3330 per ounce, hitting a new historical high, rebounding about $100 from the daily low, and rising more than 3% within the day.

  • Spot gold breaks through $3,320/ounce, setting a new record high

    spot gold broke through $3320 per ounce, hitting a new all-time high and rising 2.9% intraday.

  • BTC breaks through $85,000

    the market shows BTC breaking through $85,000, now trading at $85,022, with a 24-hour decrease narrowed to 0.41%. The market fluctuates greatly, so please be prepared for risk control.

  • Grayscale transfers 6,576 ETH to Coinbase Prime hot wallet address

    according to Arkham monitoring data, Grayscale transferred a total of 6576 ETH worth $10.38 million to Coinbase Prime's hot wallet address seven minutes ago.

  • Glider completes $4 million financing, led by a16z

    crypto investment startup Glider has completed a $4 million financing round, led by a16z, with participation from Coinbase Ventures, Uniswap Ventures, and GSR. Glider plans to use artificial intelligence to help users adjust their cryptocurrency investments according to their needs, and will join the Andreessen Horowitz cryptocurrency startup accelerator this spring.

  • DWF Labs spends $25 million to buy WLFI tokens

    DWF Labs posted on social media platform that they have established a new office in New York and strategically purchased 25 million US dollars worth of WLFI tokens.

  • Italian Finance Minister Warns US Stablecoin Policy Threat Exceeds Tariffs

    according to Cointelegraph, Italian Finance Minister Giancarlo Giorgetti warned that US stablecoin policy poses a greater threat to European financial stability than Trump's tariffs, potentially weakening the euro's dominant position in cross-border payments. He urged the EU to strengthen the international status of the euro, emphasizing the importance of a digital euro.

  • South Korean Conservatives Promise Trump-Style Crypto Policy in Presidential Campaign

    according to Yonhap News Agency, Hong Joon-pyo, a presidential candidate for the ruling party National Power Party in South Korea, promised to significantly reduce regulations on blockchain and cryptocurrency at a policy forum. This conservative candidate stated that he will emulate the regulatory approach of the Trump administration in the United States. He pledged to implement blockchain technology in government services and promote virtual assets as a separate industry.

  • cointelegraph ·

    CleanSpark to start selling Bitcoin in 'self-funding' pivot

    CleanSpark plans to sell mined Bitcoin each month and has secured a $200M credit line from Coinbase Prime as it shifts toward self-funding operations.