Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownReportedCampaign

'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders

Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully · Cryptocurrency · Multiple · March 2025

What happened

From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.

How the deception worked

The lure was flattery with a business rationale: an investment conversation or an invitation onto a podcast, backed by around thirty sock-puppet accounts and fabricated corporate websites so that a quick check appeared to confirm the entity. On the call the attacker asked to screen share, then requested remote control. The critical trick was renaming their Zoom display name to 'Zoom' so that the permission prompt read as though it came from the application itself rather than from another participant. A victim clicking approve on what looked like a system dialog handed over interactive control of their machine, at which point infostealers or remote access trojans were installed and wallet material harvested. Tell-tale signs included consumer Zoom accounts used by supposed Bloomberg staff.

AI involvement · Unknown

The campaign used roughly 30 sock-puppet social media accounts and fabricated company websites; no confirmed use of AI-generated media was reported in the analyses reviewed.

The control that would have caught it· our reading, not a claim from the sources

Disabling Zoom remote control at the account level, and treating any unsolicited investor or media approach that moves to screen control as hostile, removes the single click this campaign depends on.

Sources (2)

  1. 'Elusive Comet' Attackers Use Zoom to Swindle Victims
    Dark Reading·darkreading.comOpen ↗
  2. North Korean Cryptocurrency Thieves Caught Hijacking Zoom 'Remote Control' Feature
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.