Davide pfp
Davide
@0xdavide
💼👔🤝🏽Beware of social engineering attacks with fake job offers because they are spreading a lot. Which sites are used? X, CryptoJobsList, LinkedIn, WellFound. These sites are obviously legit. The scam is based on posting a job offer and waiting for the victim to contact the criminals. ⚠️Similar scams can also occur through sponsorships on Youtube or job offers on X by trying/reviewing games. What is the goal? To make you download malware. In all cases the scam is carried out like this: 1) Scammers say they are interested in your profile, contact you and offer you an interview. 2) They could move the conversation to Telegram. 3) They propose a video call, where instead of Zoom or Google Meet, they tell you that it is better to use another software (for example GrassCall) because a manager is Asian and does not understand English (the nationality is adapted based on the person to be scammed). GrassCall would translate in real time from English to XXX language via AI.
1 reply
0 recast
0 reaction

Davide pfp
Davide
@0xdavide
4) In reality GrassCall is a fake software that contains RAT (Trojan), Keylogger and InfoStealer. 5) Through Keylogger and InfoStealer functions, passwords and data typed on the keyboard are stolen. In addition, scanning functions are started for crypto wallets (Phantom, Metamask, Exodus, Keplr, etc) that save locally. 6) If you are already logged in to the wallet, the funds are moved (because they have remote control). If you are not logged in and there is a password, a BruteForce attack is performed or the password is stolen when it is typed (via Keylogger). Keep in mind that both the people who contact you, the company website and the software that contains malware are absolutely well-groomed. The staff also has profiles on X and LinkedIn. When the website is blocked, they create another malicious software (GrassCall's predecessor was Gathereum). 🎮The gaming variant involves having you test a game and getting paid (again, the goal is to get you to install an .exe file).
0 reply
0 recast
0 reaction