Unmasking GrassCall Campaign: The APT Behind Job Recruitment Cyber Scams

March 6, 2025, 10:59 p.m.

Description

The GrassCall malware campaign is an advanced social engineering attack conducted by a Russian-speaking cybercriminal group called Crazy Evil. Targeting job seekers in the cryptocurrency and Web3 sectors, the campaign uses fake job interviews to compromise victims' systems and steal cryptocurrency assets. The attackers create a fake company, post job advertisements on reputable platforms, and guide candidates through a sophisticated process involving phishing emails, Telegram conversations, and the installation of malicious software disguised as a video conferencing application. The malware deployed includes a Remote Access Trojan (RAT) and information-stealing programs like Rhadamanthys for Windows users, and the Atomic macOS Stealer (AMOS) for Mac users. The campaign has affected hundreds of people, with some victims reporting drained cryptocurrency wallets.

Date

  • Created: March 6, 2025, 7:25 p.m.
  • Published: March 6, 2025, 7:25 p.m.
  • Modified: March 6, 2025, 10:59 p.m.

Indicators

  • d23f79f9b7e1872d4671a18aa85b810c0cec2e0f5ce07c2cf99ed39f8936c8fb
  • b63367bd7da5aad9afef5e7531cac4561c8a671fd2270ade14640cf03849bf52
  • f2e8f1f72abbc42f96c5599b8f27f620d91ae1680aa14b4f0bbf3daabd7bee30
  • 386b61ccdd4b785c835a064179d5fa58dc0d5fe34970a04487968e1ee0189ce6
  • 4b371777c2c638c97b818057ba4b0a2de246479776eaaacebccf41f467bb93c3
  • 0160c14c3d84dcc5802a329a4d4bedcabd23b3a7761c1cd95d16bd0b7a7bb8eb
  • 45.129.185.24
  • https://45.129.185.24:1896/22c0d31ace677b/digpu6k5.xditc
  • http://rustaisolutionnorisk.com/downloads/videosolution_vibecall_b.exe
  • http://rustaisolutionnorisk.com/downloads/soundsolution_vibecall_c.exe
  • http://rustaisolutionnorisk.com/downloads/contry_solution_vibecall_e.exe
  • http://rustaisolutionnorisk.com/downloads/aisolution_vibecall_a.exe
  • grasscall.net
  • rustaisolutionnorisk.com

Attack Patterns

  • Atomic macOS Stealer (AMOS)
  • GrassCall
  • Rhadamanthys
  • Crazy Evil

Additional Informations

  • Technology
  • Finance