Elusive Comet

2025-03-24 • Security AllianceSEAL Releases Advisory on ELUSIVE COMET

The Security Alliance (SEAL) identified Elusive Comet as a threat actor running an ongoing social-engineering campaign against cryptocurrency users designed to install malware and steal funds, responsible for millions of dollars in losses. The group operates a fabricated venture capital persona, Aureon Capital, along with related entities including a press outlet and a podcast, maintaining polished websites and active social media profiles, sometimes impersonating real people with notable credentials, to establish an extensive and convincing online presence. Elusive Comet typically initiates contact with prospective victims over social media direct messages or email, inviting them to appear as podcast guests, then schedules a video call, often withholding details until the last minute to create urgency. During the call, the victim is asked to share their screen, at which point the group requests remote control through the meeting platform; if granted, this access is used to install an infostealer or remote access trojan. Security researchers have noted the group's methodology mirrors techniques used in a separate large cryptocurrency exchange hack, reflecting a broader shift toward operational, human-centric attacks in the industry.

Related Actors

Related Reports in This Cluster

Top Authors

View Elusive Comet reports only

View Elusive Comet reports only