Security Alert: Crypto Scammers Infiltrate Telegram with Malware, Beware!

January 15, 2025 — Security firm Scam Sniffer has issued a shocking warning about a dramatic rise in malware scams on Telegram, which have now surpassed traditional phishing in volume, skyrocketing by 2,000% since November. This shift in scammers’ tactics poses a serious threat to cryptocurrency users.
A New Approach to Scams
Unlike typical scams that involve connecting digital wallets to fraudulent sites, scammers are now deploying fake verification bots in trading groups, airdrops, and alpha groups. According to Scam Sniffer, once users execute the code or install the verification software, attackers can:
- Access passwords.
- Scan wallet files.
- Monitor the clipboard.
- Steal browser data.
Scam Sniffer has identified at least two fraudulent verification bots: OfficiaISafeguardRobot and SafeguardsAuthenticationBot. These bots are part of a broader strategy that scammers have adopted as users become more aware of signature scams.
Deceptive Strategies
The security firm first raised the alarm about these scams in December after noticing scammers creating fake accounts on X impersonating popular crypto influencers. They then invited users to Telegram groups with promises of investment ideas. Once inside, users were asked to verify their identity through a fake bot, resulting in the theft of private keys and the raiding of their wallets.
Another tactic involves using fake Cloudflare verification pages, where users are prompted to copy and paste a verification text that is secretly injected into their clipboard, facilitating malware access.
In a recent update, Scam Sniffer warned that scammers have begun targeting communities of legitimate projects with seemingly harmless invitations, further increasing the risk for unsuspecting users.
Conclusion
The cryptocurrency community must remain vigilant against these new scam tactics. Stay informed and always verify the authenticity of bots and groups before engaging. The security of your digital assets depends on it.
