The “JobStealer” Trojan Hijacking Crypto Wallets via Fake Meetings
ID: 41fe554b-0d88-5c49-b762-a1bfe0c5bfd6
STIX ID: report--41fe554b-0d88-5c49-b762-a1bfe0c5bfd6
Feed Name: securityonline.info
Doctor Web reports a targeted JobStealer campaign that lures job-seekers into downloading fake video-conferencing software (macOS .dmg or terminal install) which actually installs a trojan that prompts for credentials and steals data—focusing on ~300 Chromium-based wallet extensions, Telegram files, macOS Notes, and evidence of Ledger/Trezor apps—then compresses and exfiltrates the data to attacker C2; variants and infrastructure indicate Windows support and potential future expansion to Linux/iOS/Android.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
