logo

Crypto-stealing malware posing as a meeting app targets Web3 pros

ID: 036bc2a9-e950-59db-9c42-db357a0234c3

STIX ID: report--036bc2a9-e950-59db-9c42-db357a0234c3

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Cado Security Labs uncovered the "Meeten" campaign (active since Sept 2024) that lures Web3 professionals to download fraudulent meeting software which installs the Realst infostealer on Windows and macOS; the malware and associated JavaScript steal browser credentials, crypto wallets (Ledger, Trezor, Phantom, Binance), Telegram and banking data, use stolen code-signing, employ obfuscation and persistence, and exfiltrate collected data to remote servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.