logo

The “JobStealer” Trojan Hijacking Crypto Wallets via Fake Meetings

ID: 41fe554b-0d88-5c49-b762-a1bfe0c5bfd6

STIX ID: report--41fe554b-0d88-5c49-b762-a1bfe0c5bfd6

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

Doctor Web reports a targeted JobStealer campaign that lures job-seekers into downloading fake video-conferencing software (macOS .dmg or terminal install) which actually installs a trojan that prompts for credentials and steals data—focusing on ~300 Chromium-based wallet extensions, Telegram files, macOS Notes, and evidence of Ledger/Trezor apps—then compresses and exfiltrates the data to attacker C2; variants and infrastructure indicate Windows support and potential future expansion to Linux/iOS/Android.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.