{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:43.722Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders","date":"2025-03","date_precision":"month","victim_org":"Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully","sector":"Cryptocurrency","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"The campaign used roughly 30 sock-puppet social media accounts and fabricated company websites; no confirmed use of AI-generated media was reported in the analyses reviewed.","outcomes":["Cryptocurrency Theft","Credential Theft"],"loss_usd":null,"loss_note":"Security Alliance's incident log attributes millions of dollars of stolen funds to the group. No single confirmed per-victim figure was published in the reporting reviewed.","records_affected":null,"threat_actor":"Elusive Comet, tracked by the Security Alliance and assessed as North Korea-linked","summary":"From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.","how_it_worked":"The lure was flattery with a business rationale: an investment conversation or an invitation onto a podcast, backed by around thirty sock-puppet accounts and fabricated corporate websites so that a quick check appeared to confirm the entity. On the call the attacker asked to screen share, then requested remote control. The critical trick was renaming their Zoom display name to 'Zoom' so that the permission prompt read as though it came from the application itself rather than from another participant. A victim clicking approve on what looked like a system dialog handed over interactive control of their machine, at which point infostealers or remote access trojans were installed and wallet material harvested. Tell-tale signs included consumer Zoom accounts used by supposed Bloomberg staff.","lessons":"Disabling Zoom remote control at the account level, and treating any unsolicited investor or media approach that moves to screen control as hostile, removes the single click this campaign depends on.","confidence":"Reported","sources":[{"title":"'Elusive Comet' Attackers Use Zoom to Swindle Victims","url":"https://www.darkreading.com/remote-workforce/elusive-comet-zoom-victims","publisher":"Dark Reading"},{"title":"North Korean Cryptocurrency Thieves Caught Hijacking Zoom 'Remote Control' Feature","url":"https://www.securityweek.com/north-korean-cryptocurrency-thieves-caught-hijacking-zoom-remote-control-feature/","publisher":"SecurityWeek"}],"entry_type":"campaign","slug":"2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders"}]}