Fake VCs target crypto talent
2026-03-02 • Moonlock •
https://moonlock.com/fake-vcs-target-crypto-talent-clickfix-campaign
Moonlock Lab tracks a campaign targeting cryptocurrency and Web3 professionals through LinkedIn outreach, fabricated venture capital firms, and fake Zoom or Google Meet links. The attack flow uses recruiter or investor personas tied to fronts such as SolidBit Capital, MegaBit, and Lumax Capital, then redirects victims through Calendly-style scheduling into spoofed meeting pages. Delivery relies on ClickFix-style fake CAPTCHA prompts that poison the clipboard and instruct victims to paste and run malicious commands in Terminal, with cross-platform payload handling for macOS and Windows. Moonlock reports overlaps with DPRK-aligned cryptocurrency targeting and Mandiant-attributed UNC1069 activity, including similar fake Zoom domain conventions, Calendly-to-fake-Zoom social engineering, and cross-platform ClickFix delivery, while noting that definitive attribution remains open. The infrastructure pivots through shared WHOIS details, rotating fake company identities, AI-generated staff profiles, typosquatted event or media branding, and a newly registered lumax[.]capital front.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 755cc133ae0519accbcfdd5f8f0d9fe… | 2026-03-02 | 2026-04-14 |
| HASH | 2fbd34eed9dbf57a44cf1540941fb43… | 2026-03-02 | 2026-03-02 |
| HASH | 9a778d2b7919717e95072e4dec01c81… | 2026-03-02 | 2026-03-02 |
| URL | https://zoom.us05-web.us/ft?top… | 2026-03-02 | 2026-03-02 |
| URL | https://hedgeweeks.online/ft?id= | 2026-03-02 | 2026-03-02 |
| DOMAIN | zoom.us05-web.us | 2026-03-02 | 2026-03-02 |
| DOMAIN | hedgeweeks.online | 2026-03-02 | 2026-03-02 |
| DOMAIN | goog1e.us-meet.com | 2026-03-02 | 2026-03-02 |
| DOMAIN | hedgeweek.com | 2026-03-02 | 2026-03-02 |
| DOMAIN | thedigitalassetconference.com | 2026-03-02 | 2026-03-02 |
| DOMAIN | mylingocoin.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | zmsupport.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | dreamdie.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | breakdream.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | supportzm.com | 2026-01-29 | 2026-03-02 |
| DOMAIN | calendly.com | 2024-10-29 | 2026-03-02 |