📈 Get daily crypto insights that make you smarter about your money

Why Social Engineering Now Beats Code Exploits in Crypto Theft — Lessons from the Elusive Comet Campaign

The cryptocurrency industry has entered a dangerous new era where sophisticated social engineering attacks now pose greater financial risk than traditional software vulnerabilities. The Elusive Comet campaign, uncovered by the Security Alliance and Trail of Bits in April 2025, reveals how North Korean state-sponsored hackers are repurposing legitimate collaboration tools like Zoom to steal millions from crypto traders and venture investors. Understanding these threats and building robust defenses is no longer optional — it is survival.

The Threat Landscape

The Elusive Comet campaign represents a significant evolution in cryptocurrency-targeted attacks. Rather than exploiting buffer overflows or smart contract flaws, the attackers weaponize trust itself. Posing as venture capital investors and media producers, they initiate contact through professional channels — LinkedIn messages, X direct messages, and email pitches — inviting targets to appear on podcasts or discuss investment opportunities through a fictitious entity called Aureon Capital.

Once the target accepts, the attack unfolds through a carefully orchestrated sequence: the hackers schedule a Zoom call via Calendly, sometimes withholding meeting details until the last minute to create urgency. During the call, they request screen sharing and then remote control access. The critical deception involves changing their Zoom display name to “Zoom,” making the remote access permission dialog appear as an innocuous system notification rather than a request from another participant. One hasty click grants the attacker full mouse and keyboard control.

The Security Alliance attributes millions of dollars in losses to this operation and has identified nearly thirty sock-puppet social media accounts and multiple polished corporate websites used to establish the fake Aureon Capital persona. Trail of Bits encountered the ruse firsthand when two profiles posing as Bloomberg producers attempted to book their CEO for a crypto segment, complete with late-breaking Zoom links that belonged to consumer-grade accounts rather than Bloomberg enterprise tenants.

Core Principles

Defending against these attacks requires a fundamental shift in security mindset. The traditional perimeter-based approach — firewalls, intrusion detection, vulnerability scanning — is necessary but insufficient when the attack vector is a legitimate video conferencing tool operated by a willing participant. The core principles for defense are verification, compartmentalization, and minimal privilege.

Verification means independently confirming the identity of every counterparty before engaging. A LinkedIn profile and a polished website are not sufficient proof of legitimacy. Cross-reference claims through multiple independent channels. If someone claims to be from Bloomberg, verify through Bloomberg official channels directly. If an investment firm contacts you, check their registration with financial authorities and verify team members through independent sources.

Compartmentalization means never mixing high-value crypto operations with general-purpose computing. The workstation where you manage seed phrases and sign transactions should be physically and logically separate from the device you use for video calls, email, and web browsing. Hardware wallets should never be connected to a machine that has granted remote access to anyone.

Minimal privilege means disabling unnecessary features in every tool you use. Zoom Remote Control is enabled by default in many corporate configurations, but it is almost never needed for legitimate business calls. Disable it at the account level.

Tooling and Setup

Implementing these principles requires specific technical controls. Start with Zoom itself: administrators should disable the Remote Control feature at the account, group, or user level, and lock the setting to prevent users from re-enabling it. The clipboard sharing option, which attackers exploit to copy seed phrases and private keys between applications, should also be disabled. Trail of Bits has gone further by blocking the macOS accessibility permissions that enable remote control entirely on their corporate systems, closing the attack vector without disrupting legitimate video conferencing.

For cryptocurrency-specific protection, maintain a dedicated air-gapped or nearly air-gapped machine for all wallet operations. Use hardware wallets exclusively for signing transactions, and never enter seed phrases on a device that has any remote desktop, screen sharing, or remote control software installed. Consider using a dedicated tablet or smartphone with minimal app installations as your crypto management device.

Email and identity verification tools should be part of your standard workflow. Services that verify email domain ownership, check for domain age, and flag newly registered domains can help identify fraudulent entities before engagement. Browser extensions that alert you to suspicious Zoom domains or mismatched meeting hosts add another layer of defense.

Ongoing Vigilance

The cryptocurrency industry is particularly vulnerable to these attacks because of its culture of rapid deal-making and informal communication. When Bitcoin trades at approximately $76,350 and Ethereum at $2,327, the stakes of a single compromised machine are enormous. The Elusive Comet methodology mirrors the techniques behind the $1.5 billion Bybit hack in February 2025, where attackers manipulated legitimate workflows rather than exploiting code vulnerabilities.

Security awareness training must evolve beyond recognizing phishing emails to include video conferencing security, social media impersonation, and multi-channel verification. Regular red team exercises that simulate these social engineering scenarios can help teams build the reflexes needed to resist sophisticated pretexts.

Industry-wide information sharing is also critical. The Security Alliance maintains an incident log and attribution database that tracks these campaigns. Organizations should contribute to and consume this intelligence to stay ahead of evolving tactics.

Final Takeaway

The era of operational security failures has arrived in cryptocurrency. The most dangerous attackers are no longer finding zero-day vulnerabilities — they are finding zero-trust humans. Every interaction with an unknown party, every hastily granted permission, every shared screen is a potential entry point. The defense is not more firewalls or better code audits; it is building a culture where verification is automatic, access is minimal, and the default answer to any unexpected request is a polite but firm “let me verify that through another channel.”

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified security professionals for risk assessment.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Why Social Engineering Now Beats Code Exploits in Crypto Theft — Lessons from the Elusive Comet Campaign”

  1. changing zoom display name to Zoom to make remote access look like a system dialog. that is next level social engineering. always verify who is asking for control

    1. opsec_daily and they used calendly to schedule it. the whole toolchain is legit infrastructure weaponized against crypto users

      1. calendly_nightmare

        Raj M. scheduling through calendly makes it look even more legit. the whole OSINT to Zoom pipeline is industrialized at this point

        1. calendly_nightmare calendly links are public by default too. anyone with the URL can see your schedule and availability windows. perfect recon tool for timing attacks

          1. calendly_revoke_

            calendly_nightmare Calendly default settings leak your availability windows. combine that with LinkedIn OSINT and attackers can map your entire week

        2. scheduling through calendly makes it look even more legit. the whole OSINT to Zoom pipeline is industrialized at this point

  2. opsec_mustard_

    the North Korean threat actors have better opsec than most crypto startups. fake VC firms with proper domains, Calendly scheduling, LinkedIn histories. the tradecraft is professional grade

    1. opsec_mustard_ the fake LinkedIn histories are what get me. weeks of building a persona before the first contact. most crypto teams dont vet who they are talking to for that long

  3. Jelena Vukmirovic

    Aureon Capital was the fake VC firm they used. Did nobody think to verify the domain registration before hopping on a Zoom call

    1. Aureon Capital had a website that looked more professional than half the real VCs I have pitched to. verified domain registration would have caught it but who checks that before a meeting

      1. domain_verify_

        martin_h Aureon Capital domain check should be step one. every crypto team needs a verification protocol for external calls, not just for smart contracts

        1. domain_verify_ Aureon Capital domain check should be step one. every crypto team needs a verification protocol for external calls

  4. North Korean state actors running fake VC firms to compromise crypto wallets is surreal. the attack surface moved from code to humans and most teams are not ready

    1. Anya V. agree, the human vector is the soft spot now. smart contract audits dont help when your co-founder installs malware from a Zoom link

  5. blue_screen_42

    the zoom display name trick is so simple it hurts. rename yourself to Zoom and people think the app is asking for permissions not a random attacker

  6. North Korean hackers using fake VC meetings to steal crypto wallets is next level social engineering. the Aureon Capital front was apparently convincing enough to fool experienced founders

    1. opsec_or_die_

      Soren V. the crazy part is they used real Zoom. not a phishing domain, actual zoom.us. your endpoint security doesnt help when the user voluntarily installs the malware during a meeting

      1. opsec_lifeline_

        the crazy part is they used real Zoom. not a phishing domain, actual zoom.us. endpoint security does not help when the user voluntarily installs the malware during a meeting

        1. opsec_lifeline_ using real zoom.us was the smartest part. no domain spoofing, no suspicious URL. your firewall cant help when you invite the attacker in

  7. the industry spent billions on smart contract audits and zero on social engineering training for founders. Lazarus noticed and pivoted accordingly

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,815.00+0.8%ETH$1,910.30+2.1%SOL$74.070.0%BNB$597.28-0.7%XRP$1.05-1.9%ADA$0.1880-1.4%DOGE$0.0699-0.1%DOT$0.8354-1.3%AVAX$6.660.0%LINK$8.18+0.2%UNI$4.07+3.3%ATOM$1.33-2.1%LTC$45.01+0.2%ARB$0.0801-0.9%NEAR$1.72+0.5%FIL$0.7136-0.2%SUI$0.6873-0.7%BTC$64,815.00+0.8%ETH$1,910.30+2.1%SOL$74.070.0%BNB$597.28-0.7%XRP$1.05-1.9%ADA$0.1880-1.4%DOGE$0.0699-0.1%DOT$0.8354-1.3%AVAX$6.660.0%LINK$8.18+0.2%UNI$4.07+3.3%ATOM$1.33-2.1%LTC$45.01+0.2%ARB$0.0801-0.9%NEAR$1.72+0.5%FIL$0.7136-0.2%SUI$0.6873-0.7%
Scroll to Top