21 Apr 2025

light mode

Fake Job Offers, GrassCall, and Crypto: A New Scam Uncovered

Fake jobs, video calling app and crypto - a new type of scam - The Coinomist

Cybercriminals from the Crazy Evil group are using fake job offers and a modified video-calling app to steal passwords and cryptocurrency from unsuspecting users.

On this page

They pose as employers in the Web3 industry and post attractive job openings on popular job platforms. During the initial interview, they send a link for a video call via GrassCall, a little-known app that looks legitimate but secretly installs malware on the victim's device.

This scam operation has already impacted hundreds of people.

Social Engineering Tactics

To trick users into downloading GrassCall, the hackers use social engineering tactics. They research candidates' profiles and create fake accounts on platforms like LinkedIn, WellFound, and CryptoJobsList. To make their scheme more convincing, they launch a full-scale virtual campaign with a fake website and an active social media presence. This setup often includes a fabricated backstory about the company's founding, building a permanent team, and even fake social media comments to enhance credibility.

Examples of fake job postings - The Coinomist
Examples of fake job postings. Source: Web3 user Choy

The scammers communicate through various messaging platforms, including Telegram, allowing them to quickly share instructions, send GrassCall download links, and answer questions in real time. This approach creates a sense of legitimacy and increases the chances of successfully infecting the victim’s device. 

Related: Social Engineering in Crypto: Top 5 Fraud Schemes

Technical Aspects of the Attack

When users download GrassCall, they are given the option to choose between Windows or macOS versions. However, regardless of the choice, the device becomes infected with malware. Once launched, the malicious software operates silently in the background, making it extremely difficult to detect. 

On Windows devices, the malware installs a Remote Access Trojan (RAT) combined with an info-stealer that harvests passwords, cookies, and other sensitive data. On macOS, it deploys Atomic Stealer, which extracts passwords from Apple Keychain and collects browser data.

All the other wallets would be compromised, best to create something on a new machine/ phone and transfer assets there. Computer, clean wipe, new OS install,

warned Web3 user Choy.

The malware scans infected systems for cryptocurrency wallets. If it detects any, it initiates password-cracking routines and swiftly transfers funds to the attackers’ wallets. The stolen data is transmitted to hacker-controlled servers, and detailed reports are then shared on Telegram channels to showcase the success of the attacks.

Estimates suggest that this scheme earns cybercriminals thousands of dollars per victim.

Consequences and Recommendations

These attacks leave crypto users vulnerable, leading to the loss of both sensitive data and accumulated funds with no way to prevent it. Such incidents undermine trust in the digital economy and raise concerns about the security of modern job platforms. Although many platforms have removed these fraudulent postings, it’s widely acknowledged that new scams will resurface repeatedly.

This issue has become widespread, prompting the formation of online communities where users share strategies for mitigating risks and removing malware from infected devices. 

Security experts strongly advise job seekers to thoroughly verify the legitimacy of companies and be wary of initial communications through messaging apps or requests to download software. These are clear warning signs of potential scams.

Related: Unraveling the Tactics of CryptoRom Scammers

Always keep your antivirus software up to date, change your passwords regularly, and seek help from cybersecurity professionals at the first sign of suspicious activity. Quick diagnostics can identify vulnerabilities and mitigate risks. 

Additionally, stay informed about the latest Web3 security trends, as scammers continuously refine their methods to keep pace with new security measures.

Lessons from the Modern Cyber Landscape

The GrassCall incident reveals just how sophisticated cybercriminal tactics have become in today’s digital world. It serves as a stark reminder for anyone in the crypto and blockchain space: To stay protected in this rapidly evolving tech environment, it’s crucial to use only trusted information sources, verify contacts carefully, and regularly update cybersecurity measures to safeguard personal data and digital assets from malicious actors.

Related: AI Is Making Crypto Scams Smarter—Insights from Chainalysis 2024

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
HashKey Launches Asia’s First XRP Tracker Fund in Collaboration with Ripple  

HashKey Launches Asia’s First XRP Tracker Fund in Collaboration with Ripple  

HashKey Capital and Ripple have launched the first XRP Tracker Fund in Asia. The fund targets professional investors and accepts both cash and in-kind contributions.

Dmytro Psevdonimenko
a16z Pours $55M into LayerZero with Tokens Locked for 3 Years

a16z Pours $55M into LayerZero with Tokens Locked for 3 Years

Andreessen Horowitz has taken a $55M position in LayerZero with a 3-year token lockup. The token’s price rose 10% on the heels of the news.

Dmytro Psevdonimenko
Circle Brings Trustless Refunds to USDC With New Onchain Protocol

Circle Brings Trustless Refunds to USDC With New Onchain Protocol

Refund Protocol marks a new chapter for USDC: a trust-minimized mechanism where users can dispute payments, trigger refunds, and rely on arbiters — without ever relinquishing token custody.

Vlad Vovk
Ripple’s $1.25B Target Hidden Road Wins FINRA License

Ripple’s $1.25B Target Hidden Road Wins FINRA License

Hidden Road, nearing acquisition by Ripple, has locked in its U.S. broker-dealer license—opening the door to expanded institutional fixed-income services.

Dmytro Psevdonimenko
Crypto X Today: Saylor eulogizes Bitcoin, Fong breaks silence, and more

Crypto X Today: Saylor eulogizes Bitcoin, Fong breaks silence, and more

Most Hot Crypto Discussions on X Today: Michael Saylor eulogizes Bitcoin, Tiffany Fong breaks silence, and more.

Lesia Dubenko
Crypto Discussions on X Today: Samson Mow, Elon Musk and more

Crypto Discussions on X Today: Samson Mow, Elon Musk and more

Crypto Discussions on X Today: Samson Mow believes Bitcoiners are capitulating, Musk has beef with crypto influencer and more

Lesia Dubenko
Shor’s Algorithm vs Bitcoin: Is Crypto Ready?

Shor’s Algorithm vs Bitcoin: Is Crypto Ready?

Peter Shor’s quantum algorithm could break Bitcoin’s core cryptography. What does this mean for ECDSA, crypto security, and whether the network is ready to fight back?

Elina Moskovchuk
Top Tools for Blockchain Development

Top Tools for Blockchain Development

Smart contract development calls for reliable tools that boost both security and speed. How do Solidity and Hardhat help developers ship faster?

Daryna Nesterenko
Layer 2 vs Layer 3: What’s the Difference?

Layer 2 vs Layer 3: What’s the Difference?

A complete guide comparing blockchain Layer 2 and Layer 3 solutions. Learn how they improve scalability, enhance decentralized applications, and shape the future of crypto.

The Coinomist
What Is Liquidation and How Does It Work?

What Is Liquidation and How Does It Work?

Learn what liquidation means, its types, and how it converts assets to cash. Understand how it functions in business, real estate, stocks, crypto, and more.

The Coinomist
What Does Vesting Mean? A Simple Explanation

What Does Vesting Mean? A Simple Explanation

A clear guide to vesting, covering its role in employee benefits, stock options, retirement plans, and crypto. Understand cliff, graded, and immediate vesting and why it matters.

The Coinomist
Solaxy: Scaling Solana with Layer 2 Technology

Solaxy: Scaling Solana with Layer 2 Technology

Solaxy uses L2 technology to boost Solana’s capabilities, one of the fastest blockchains in the industry. This article breaks down Solaxy’s technical features, its advantages, and its competitors.

Iaroslava Kramarenko
What Is OI? A Beginner’s Overview

What Is OI? A Beginner’s Overview

This guide explains open interest, a key metric in trading. Learn what OI is, how it works, and why it matters in futures, options, and crypto markets.

The Coinomist
Bitcoin Flat at $84K as Market Awaits Direction

Bitcoin Flat at $84K as Market Awaits Direction

Bitcoin is stuck in a tight range between $83K–$85K. Low volatility signals market indecision ahead of key triggers.

Anton Kryshtal
Fed Signals Cool the Crypto Surge: Bitcoin Hits a Wall at $85K

Fed Signals Cool the Crypto Surge: Bitcoin Hits a Wall at $85K

The latest Fed comments, rising inflation fears, and macro uncertainty are putting the brakes on Bitcoin’s breakout attempt above $85,000.

Anton Kryshtal
MORE
Crypto Tattoos: When Digital Identity Becomes Part of the Body

Crypto Tattoos: When Digital Identity Becomes Part of the Body

Crypto tattoos are emerging as the latest expression of digital culture. From Bitcoin symbols to QR codes and NFT artwork, believers in decentralization are now wearing their convictions on their skin.

Iaroslava Kramarenko
What Are AI Agents in Crypto?

What Are AI Agents in Crypto?

Crypto tools are getting smarter. AI agents are now among the most talked-about innovations, promising to change how users trade, invest, and interact with Web3 ecosystems.

Daryna Nesterenko
MORE