Cryptocurrency users are the new target of a sophisticated social engineering campaign that uses fake companies to deceive them into downloading malware capable of draining their digital assets on both Windows and macOS systems. This malicious operation has impersonated artificial intelligence, gaming, and Web3 companies, using fake accounts on social media and project documentation stored on legitimate platforms like Notion and GitHub.
Did you trust? Bad move
Darktrace’s investigations have revealed that attackers have used fake X accounts (formerly Twitter), mainly from verified companies and employees, to approach victims, offering software trials in exchange for cryptocurrency payments. The goal is to create an illusion of legitimacy, using websites that appear professional and include product blogs and technical documents.
An example of this is Eternal Decay, a supposed blockchain-powered game that has shared digitally altered images on X, giving the impression of being presented at conferences. This strategy has proven to be effective, increasing the likelihood that users fall into the trap.

Victims who agree to participate are directed to a fake website, where they must enter a registration code to download a malicious application, either for Windows or macOS. On Windows, a Cloudflare verification screen is displayed while system information is collected and an MSI installer is installed to run malware that steals information. For macOS users, the Atomic macOS Stealer (AMOS) is used, which can steal documents and cryptocurrency exchange data, and is also configured to run automatically upon login.
This campaign highlights the efforts of threat actors to make these fictitious companies appear real, with the aim of stealing cryptocurrencies from their victims. Furthermore, the use of more evasive versions of malware suggests an advancement in the tactics employed by these cybercriminals.