📈 Get daily crypto insights that make you smarter about your money

Fake Gaming and AI Companies Deploy Sophisticated Malware Targeting Crypto Users on Telegram and Discord

Cryptocurrency users face an increasingly deceptive threat landscape as fake gaming and artificial intelligence companies deploy sophisticated malware campaigns through popular messaging platforms. Security researchers identified a coordinated operation on July 11, 2025, in which threat actors masqueraded as legitimate gaming studios and AI startups to distribute trojanized applications capable of draining crypto wallets and harvesting sensitive credentials.

The Exploit Mechanics

The attack chain begins with professionally crafted social media advertisements and community posts promoting non-existent games and AI-powered trading tools. Victims are lured to download what appears to be game clients or AI-driven portfolio managers from convincing but fraudulent websites. Once installed, the malware operates as a clipper — a tool that monitors the system clipboard for cryptocurrency wallet addresses and automatically replaces them with attacker-controlled addresses. The malware also incorporates keylogging functionality that captures seed phrases and private keys as users type them into wallet applications.

What makes this campaign particularly dangerous is the multi-platform approach. Attackers maintain active Telegram groups and Discord servers with thousands of members, complete with fake customer support teams, fabricated testimonials, and staged gameplay footage. The level of social engineering sophistication represents a significant escalation from previous campaigns, with some fake communities operating for weeks before deploying the malicious payloads through seemingly routine software updates.

Affected Systems

The malware targets Windows and macOS desktop environments, with variants designed to compromise popular browser-extension wallets including MetaMask, Phantom, and Trust Wallet. Researchers identified at least 12 distinct malware strains in circulation, each tailored to intercept transactions across multiple blockchain networks including Ethereum, Solana, and Binance Smart Chain. The clipboard-replacement functionality operates silently, making it nearly impossible for users to detect that their intended transaction destination has been altered before confirming the transfer.

With Bitcoin trading above $117,500 and Ethereum near $2,950 on July 11, the potential for significant individual losses is substantial. A single clipboard swap on a large BTC transaction could redirect over $100,000 to an attacker wallet in seconds.

The Mitigation Strategy

Security experts recommend several defensive measures against these attacks. First, always verify software downloads through official channels and cross-reference project legitimacy through multiple independent sources. Never download applications promoted solely through social media or messaging platforms. Second, use hardware wallets for storing significant cryptocurrency holdings — devices like Ledger and Trezor keep private keys offline and require physical confirmation of transaction details on the device screen, rendering clipboard-based attacks ineffective.

Additionally, enable address whitelisting on exchange accounts and DeFi platforms where available. This feature restricts withdrawals to pre-approved addresses, preventing unauthorized transfers even if credentials are compromised. Regular security audits of browser extensions and installed applications can also help identify suspicious software before it causes damage.

Lessons Learned

This campaign underscores the evolution of crypto-targeted social engineering from simple phishing emails to elaborate, community-driven deception operations. The attackers invested significant resources in building credible-looking organizations with active social presences, demonstrating that surface-level legitimacy is no longer a reliable trust indicator. The crypto community must adopt a zero-trust approach to new projects and software, particularly those promoted primarily through messaging platforms rather than established distribution channels.

User Action Required

If you have recently downloaded any gaming or AI-related software promoted through Telegram or Discord, immediately scan your system with reputable anti-malware tools. Check your wallet extension permissions and review recent transaction history for any unrecognized transfers. Rotate seed phrases for any wallets that may have been exposed, and migrate funds to fresh wallet addresses generated on a secure, uncompromised device. Report any suspicious projects to community moderators and blockchain security tracking platformjnow.researchers investigating the coordinated attack campaign continue to urge heightened vigilance as similar operations are expected to evolve in sophistication throughout 2025.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding your specific situation.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

24 thoughts on “Fake Gaming and AI Companies Deploy Sophisticated Malware Targeting Crypto Users on Telegram and Discord”

    1. clipper_detect_

      hODL_or_die the clipper malware angle is terrifying because it works silently. you copy your wallet address, it swaps in the attackers address, and you send funds to the wrong place without ever noticing

      1. the keylogger part is scarier than the clipper honestly. clipper you can catch if you double check addresses. keylogger grabs your seed phrase and youre done before you even notice

        1. clipper_survivor_

          Nikola J. exactly, the keylogger is the real threat. clippers you can catch by pasting into a text field first. seed phrase gets typed once and they own you forever

          1. seed_paranoia_

            clipper_survivor_ the keylogger part is what keeps me up. you can verify a pasted address but you cant untype a seed phrase. game over the moment it logs

  1. clipper_victim_22

    almost got clipped by one of these fake game downloads last month. url looked legit, site had a whitepaper and everything. only caught it because the installer asked for admin privileges

  2. 12 distinct malware strains targeting MetaMask, Phantom and Trust Wallet. the fake Discord servers with thousands of members and staged testimonials is next level social engineering

    1. wallet_drain_watch

      Boyan Petrov 12 strains is just what kaspersky found. probably 3x that in the wild right now. the fake AI trading tools angle is especially nasty cuz people actually want portfolio managers

      1. malware_watch_ 3x in the wild feels right. kaspersky covers maybe 30 percent of active threats. the rest are on virustotal with zero detections for months

    2. Boyan Petrov 12 strains is just what they found. these fake Discord servers with staged testimonials feel real because the scammers copy actual community patterns. saw one that had 4000 members and daily dev updates

      1. clipboard_inspector_

        Kasumi T. the fake discord servers with 4000 members are the scariest part. social engineering at that scale means the verification systems are broken

  3. fake AI trading tools are the angle nobody talks about. every degen wants a portfolio manager so bad theyll install anything with ‘AI’ in the name

    1. Dimitri V. fake AI trading tools are the new fake exchange apps. same playbook different wrapper. app store reviews mean nothing when the reviews are bought

    2. malware_watch_

      Dimitri V. right, and the fake game downloads target younger users who probably dont even have hardware wallets yet. first crypto experience is getting drained

  4. fake AI portfolio managers are the perfect scam vector. every new crypto trader wants automated yields so they install the first thing they find

    1. Tomer B. the AI portfolio manager angle is genius from the attacker side. every degen wants passive yield and they will install literally anything promising it

  5. fake AI portfolio managers are the perfect honeypot. every new crypto trader wants passive yield so they install whatever promises automated returns

  6. 12 strains targeting metamask phantom and trust wallet. kaspersky found 12 which means the actual number is way higher. open source wallet clients cant move fast enough on this

  7. clipboard_bandit_

    12 strains targeting metamask phantom and trust wallet. kaspersky found 12 which means the real count is probably triple that. open source wallets cant patch fast enough

    1. clipboard_bandit_ the keylogger component is what makes this devastating. you can double check a pasted address but you cant untype a seed phrase

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,871.00-2.0%ETH$1,873.12-2.5%SOL$75.89-1.6%BNB$599.61-1.4%XRP$1.02-2.1%ADA$0.1951-1.4%DOGE$0.0696-1.3%DOT$0.8060-0.1%AVAX$6.48-0.9%LINK$8.25-0.8%UNI$3.93-2.4%ATOM$1.42+2.3%LTC$45.06-2.4%ARB$0.0805+2.6%NEAR$1.61-1.8%FIL$0.6995-1.4%SUI$0.6882-1.5%BTC$63,871.00-2.0%ETH$1,873.12-2.5%SOL$75.89-1.6%BNB$599.61-1.4%XRP$1.02-2.1%ADA$0.1951-1.4%DOGE$0.0696-1.3%DOT$0.8060-0.1%AVAX$6.48-0.9%LINK$8.25-0.8%UNI$3.93-2.4%ATOM$1.42+2.3%LTC$45.06-2.4%ARB$0.0805+2.6%NEAR$1.61-1.8%FIL$0.6995-1.4%SUI$0.6882-1.5%
Scroll to Top