SEAL Releases Advisory on ELUSIVE COMET
2025-03-24 • Security Alliance •
SEAL tracks ELUSIVE COMET as an active threat to cryptocurrency users, using carefully built personas and entities such as Aureon Capital, Aureon Press, and The OnChain Podcast to appear legitimate. The actor initiates contact through Twitter DMs or email, invites victims onto podcast-style Zoom calls, and creates urgency around meeting details. During the call, the attacker asks the victim to share their screen and then requests remote control, which can let them install an infostealer for immediate secret theft or a RAT for later exfiltration. The campaign matters because the social-engineering setup targets trust and attention rather than a technical exploit, creating a realistic path to cryptocurrency theft.