Russian Hackers Use Malicious ‘GrassCall’ Meeting App to Drain Crypto Wallets: Report

crypto scams Russia
The GrassCall app prompts to enter a code that installs Atomic Stealer malware.
Author
Last updated: 

Reports find that a new crypto malware has targeted hundreds of web3 job seekers through a malicious “GrassCall” meeting app.

Per Bleeping Computer, Russian team of hackers known as “Crazy Evil,” carried out a social engineering campaign that lured job seekers with fake interviews. The attackers used a malicious meeting app “that installs information-stealing malware to steal cryptocurrency wallets.”

The attack was initially flagged by several impacted users on Telegram, helping affected users to navigate through the loss. The malware is designed to infect both Mac and Windows devices.

GrassCall’s Social Engineering Tactics

Choy Kwok, a web3 professional, posted on X early this week, warning followers about the scam. He cautioned users not to download any meeting app that was asked by recruiters pretending to be from Chain Seeker.

Crypto Jobs List, a web3 job portal, carried several job listings for a blockchain-based platform ‘ChainSeeker.io’. However, little did the applicants know that perpetrators were behind the job scam. The jobs were also listed on LinkedIn and X, from legitimate-looking fake profiles.

“Setting up time to speak with them will take you to GrassCall. Do not download anything,” Kwok wrote.

Aspirants who applied for jobs via the portal, were reportedly asked to reach out to the company’s Chief Marketing Officer via Telegram to coordinate the meeting.

Source: Choy, via Bleeping Computer

They were then asked to download a video meeting software GrassCall, with a website link and call code. The website “grasscall[.]net” led to a download link that described GrassCall as a “revolutionary AI solution in the field of communications.”

Source: Bleeping Computer

Atomic Stealer Malware Drains Cryptos From Victim Wallets

According to a cybersecurity researcher g0njxa, GrassCall website is a clone of a “Gatherum” website, which was used by the same Russian group in previous campaigns.

The GrassCall app prompts to enter a code shared by the fake CMO, and installs remote access trojans (RATs). The RAT then installs the Atomic (AMOS) Stealer malware on Macs.

“The rat is used to create persistence in the machine, add a keylogger for password too and deploying seed phishing for the hard wallets,” G0njxa told Bleeping Computer.

Once the malware takes control of the computer, it attempts to steal files based on keywords, cryptocurrency wallets, and passwords.

If a crypto wallet is found with the extracted password, the assets in the wallet are drained, he explained.

This comes parallelly with the recent widespread malware campaign targeting users on GitHub, flagged by cybersecurity firm Kaspersky.

In the Article
Bitcoin
BTC
$87,464
2.23 %
Ethereum
ETH
$2,929
2.00 %
XRP
XRP
$1.8487
1.73 %
Litecoin
LTC
$77.31
0.80 %
Cardano
ADA
$0.3536
0.68 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,087,314,546,650
-1.27
Trending Crypto

More Articles

Price Analysis
XRP Price Prediction: Billionaire Who Once Mocked XRP Now Praises It – Big Announcement Coming?
Alejandro Arrieche
Alejandro Arrieche
2025-12-26 23:46:00
Price Analysis
Dogecoin Price Prediction: Bearish Chart Meets Bullish On-Chain Moves – Which Side Wins Next?
Anas Hassan
Anas Hassan
2025-12-26 22:50:00
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors