Fake VCs target crypto talent

2026-03-02 Moonlock

https://moonlock.com/fake-vcs-target-crypto-talent-clickfix-campaign

Thumbnail for Fake VCs target crypto talent

Moonlock Lab tracks a campaign targeting cryptocurrency and Web3 professionals through LinkedIn outreach, fabricated venture capital firms, and fake Zoom or Google Meet links. The attack flow uses recruiter or investor personas tied to fronts such as SolidBit Capital, MegaBit, and Lumax Capital, then redirects victims through Calendly-style scheduling into spoofed meeting pages. Delivery relies on ClickFix-style fake CAPTCHA prompts that poison the clipboard and instruct victims to paste and run malicious commands in Terminal, with cross-platform payload handling for macOS and Windows. Moonlock reports overlaps with DPRK-aligned cryptocurrency targeting and Mandiant-attributed UNC1069 activity, including similar fake Zoom domain conventions, Calendly-to-fake-Zoom social engineering, and cross-platform ClickFix delivery, while noting that definitive attribution remains open. The infrastructure pivots through shared WHOIS details, rotating fake company identities, AI-generated staff profiles, typosquatted event or media branding, and a newly registered lumax[.]capital front.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 755cc133ae0519accbcfdd5f8f0d9fe… 2026-03-02 2026-04-14
HASH 2fbd34eed9dbf57a44cf1540941fb43… 2026-03-02 2026-03-02
HASH 9a778d2b7919717e95072e4dec01c81… 2026-03-02 2026-03-02
URL https://zoom.us05-web.us/ft?top… 2026-03-02 2026-03-02
URL https://hedgeweeks.online/ft?id= 2026-03-02 2026-03-02
DOMAIN zoom.us05-web.us 2026-03-02 2026-03-02
DOMAIN hedgeweeks.online 2026-03-02 2026-03-02
DOMAIN goog1e.us-meet.com 2026-03-02 2026-03-02
DOMAIN hedgeweek.com 2026-03-02 2026-03-02
DOMAIN thedigitalassetconference.com 2026-03-02 2026-03-02
DOMAIN mylingocoin.com 2026-02-10 2026-03-02
DOMAIN zmsupport.com 2026-02-10 2026-03-02
DOMAIN dreamdie.com 2026-02-10 2026-03-02
DOMAIN breakdream.com 2026-02-10 2026-03-02
DOMAIN supportzm.com 2026-01-29 2026-03-02
DOMAIN calendly.com 2024-10-29 2026-03-02

Related Actors

Related Reports

« Back