📈 Get daily crypto insights that make you smarter about your money

SlowMist Exposes Fake Zoom Meeting Phishing Campaign That Drained Crypto Wallets

Blockchain security firm SlowMist has uncovered a sophisticated phishing campaign that uses fake Zoom meeting invitations to steal cryptocurrency from unsuspecting users. The attack, which came to light on December 28, 2024, has already resulted in losses exceeding $1 million, with one victim alone losing 1 million USD0++ stablecoins from their wallet.

The discovery adds to a grim year-end tally for cryptocurrency security, with Chainalysis reporting that over $2.2 billion was lost to hacks throughout 2024 — a 21% increase from the previous year.

The Exploit Mechanics

The attack begins with a seemingly innocuous message containing a Zoom meeting link. According to SlowMist’s detailed analysis, the malicious actors craft phishing links designed to mimic legitimate Zoom meeting invitations. When recipients click these links, they are directed to a fraudulent domain — “app[.]us4zoom[.]us” — which closely replicates the genuine Zoom interface.

The deception is remarkably convincing. Users see what appears to be a standard Zoom meeting waiting room, complete with branding elements and interface components that mirror the real application. The critical moment comes when the victim clicks the “Launch Meeting” button. Instead of opening the Zoom application, this action downloads malicious software onto the victim’s computer.

The malware then prompts users to “Reinstall” the Zoom platform, a social engineering trick that convinces victims to execute a malicious script and enter their system password. With administrative access secured, the malware goes to work collecting sensitive data from the compromised device.

Affected Systems

Once installed, the malicious software conducts a comprehensive sweep of the victim’s digital footprint. SlowMist’s investigation reveals that the malware collects system information, browser data, cryptocurrency wallet data, Telegram data, Notes data, and Cookie data. All of this information is then compressed and transmitted to a server controlled by the attackers.

Perhaps most damaging is the malware’s ability to access and attempt to decrypt the macOS KeyChain. By extracting KeyChain data, the attackers can potentially recover stored wallet mnemonic phrases and private keys — the cryptographic equivalent of handing over the keys to a vault.

One victim described how they were manipulated into clicking the fake Zoom link and subsequently installing the malicious program, resulting in the theft of 1 million USD0++ from their crypto wallet. SlowMist traced the stolen funds and found that the attacker had accumulated over $1 million in cryptocurrency, including USD0++, MORPHO tokens, and Ethereum.

The stolen MORPHO and USD0++ tokens were converted to 296 Ethereum on December 23, 2024, before being distributed across several major cryptocurrency platforms including Binance, Bybit, and Gate.io in an apparent attempt to launder the proceeds.

The Mitigation Strategy

SlowMist has recommended several immediate steps for users who may have been exposed to this campaign. First and foremost, anyone who clicked on a suspicious Zoom meeting link in recent weeks should immediately move their cryptocurrency assets to a fresh wallet with new private keys.

The security firm also advises users to change passwords on all accounts that may have been accessible through the compromised device, particularly email accounts and cryptocurrency exchange accounts. Running a thorough malware scan using reputable security software is essential, and in severe cases, a complete system restore may be warranted.

For organizations, the incident highlights the need for enhanced security training around phishing awareness, particularly as attackers become more sophisticated in mimicking legitimate business tools.

Lessons Learned

This campaign demonstrates how threat actors are evolving beyond traditional phishing techniques. By exploiting the trust that users place in widely-adopted platforms like Zoom, attackers can bypass the skepticism that typically protects against more obvious scams.

The use of a fake domain that closely mimics the real Zoom interface represents a significant advancement in social engineering tactics. Users are conditioned to trust meeting invitations from colleagues and business contacts, making this attack vector particularly dangerous for professionals who frequently participate in video conferences.

The timing of the attack — during the holiday season when people may be less vigilant — suggests a calculated approach by the threat actors. Bitcoin trades near $95,000 and Ethereum around $3,400 as of late December 2024, meaning even small wallet compromises can yield significant returns for attackers.

User Action Required

All cryptocurrency users should take immediate precautions: verify Zoom meeting links by checking the domain carefully before clicking, never download software from unexpected prompts, and never enter system passwords in response to unsolicited requests. Enable two-factor authentication on all cryptocurrency accounts and consider using a dedicated device for cryptocurrency transactions that is never used for general web browsing or email. Store large cryptocurrency holdings in hardware wallets rather than software wallets connected to internet-enabled devices.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding cryptocurrency protection.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “SlowMist Exposes Fake Zoom Meeting Phishing Campaign That Drained Crypto Wallets”

      1. app.us4zoom.us looks almost identical to zoom.us in a mobile browser. these phishing kits are getting professionally designed now

        1. the mobile browser angle is key. on desktop you can at least check the URL bar. on your phone the domain is barely visible

  1. 303 hacks and $2.2b stolen in 2024. at some point the industry needs to admit security is a feature not an afterthought

    1. 2.2B stolen and exchanges still dont enforce mandatory hardware 2FA. the industry collectively shrugs at security until its their turn

      1. hardware 2FA should be mandatory for any withdrawal above $100. exchanges wont do it because it adds friction to the user experience

      2. sendit coinbase and binance wont add mandatory 2FA because it increases support tickets and costs. they did the math and decided losing some users is cheaper than friction

  2. 1M USD0++ from a single wallet means these attackers knew exactly what they were targeting. not random phishing

  3. one victim lost 1M USD0++ from a single fake meeting link. stablecoins made exits instant and irreversible. the perfect crime

    1. Liesl W. USD0++ being drainable in one tx is the real issue. stablecoins gave thieves instant settlement with zero recourse

  4. the fake Zoom domain app.us4zoom.us is honestly clever. even tech-literate people would click that without thinking twice

    1. Greta W. the domain is the giveaway if you actually read it but in context of a meeting invite nobody checks. social engineering beats technical awareness every time

  5. 1M USD0++ drained from a single wallet via a fake meeting link. stablecoins gave these attackers instant settlement with zero recourse

  6. app.us4zoom.us vs zoom.us on mobile. one character difference and mobile browsers hide the URL bar completely. hardware wallets are the only real fix

  7. the us4zoom.us domain trick works because mobile browsers truncate the URL bar. google should deindex this stuff automatically but they wont

  8. app.us4zoom.us is a one character difference from zoom.us. on mobile you literally cannot tell the difference without copying the url and checking. phishing is a mobile problem now

    1. us4zoom.us vs zoom.us on mobile. you literally cannot tell the difference on a phone screen. phishing went mobile-first and nobody noticed

    2. phish_spotter_ disabling JS helps but most phishing kits now use legitimate-looking landing pages that work without it. hardware wallet confirmation is the only real defense

  9. phish_spotter_

    the us4zoom.us domain trick is exactly why i disabled javascript on unknown links. one typo and your wallet is drained before the page even finishes loading

  10. $1M from one victim alone. these arent script kiddies anymore, this is organized crime with UX designers on payroll

    1. dr_strange_ UX designers on payroll is the part nobody wants to hear. these phishing kits have custom illustrations, smooth animations, even fake waiting room timers. professional grade social engineering

  11. 2.2B stolen in 2024 and the default wallet UX still lets you sign blind transactions. the industry refuses to add human-readable simulation by default

    1. $2.2B stolen in 2024 and wallet UX still defaults to blind signing. the industry refuses to add human-readable tx simulation

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,788.00-0.1%ETH$1,941.06+0.8%SOL$75.50-0.2%BNB$573.22-0.1%XRP$1.09-1.6%ADA$0.1585-3.9%DOGE$0.0718-1.2%DOT$0.7907-3.5%AVAX$6.56-1.7%LINK$8.58-0.5%UNI$3.78-2.5%ATOM$1.34-4.3%LTC$46.50-2.4%ARB$0.0789-4.4%NEAR$1.73-3.8%FIL$0.7119-3.6%SUI$0.7002-2.2%BTC$64,788.00-0.1%ETH$1,941.06+0.8%SOL$75.50-0.2%BNB$573.22-0.1%XRP$1.09-1.6%ADA$0.1585-3.9%DOGE$0.0718-1.2%DOT$0.7907-3.5%AVAX$6.56-1.7%LINK$8.58-0.5%UNI$3.78-2.5%ATOM$1.34-4.3%LTC$46.50-2.4%ARB$0.0789-4.4%NEAR$1.73-3.8%FIL$0.7119-3.6%SUI$0.7002-2.2%
Scroll to Top