Got contacted by someone posing as a client for a call. The meeting link opened Zoom/Teams but showed an invalid meeting ID. When I flagged it, they sent a “fix” — a Terminal command to paste and run. It was malware: downloaded an unsigned binary + shell script from wirevixbox.us, ran them silently in the background, then cleared the terminal to hide it. macOS’s built-in warning for suspicious pasted commands is what caught it — I dismissed the warning but didn’t hit Enter, so nothing executed. Red flags to know: • No legitimate meeting app ever needs a Terminal command to join • Broken meeting ID + a suggested “fix” = the fix is the attack • Silent background execution (nohup, /dev/null) + screen-clearing after = hiding evidence
Blocklist wirevixbox.us if you can. Reported to Google Safe Browsing and URLhaus. Sharing in case others in crypto/payments are getting targeted with the same pretext.
submitted by /u/Long_Importance_3294 [link] [comments]r/CryptoCurrencyRead More
You might also be interested in reading Bitcoin Price Turns Vulnerable As Indicators Point To More Weakness.
