{"id":413286,"date":"2026-09-12T04:22:14","date_gmt":"2026-09-12T04:22:14","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=413286"},"modified":"2026-09-12T04:22:14","modified_gmt":"2026-09-12T04:22:14","slug":"video-call-update-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/video-call-update-scam\/","title":{"rendered":"Fake Video Call Update Scam Drains Crypto Wallets"},"content":{"rendered":"<p>A video call update scam can start when a prospective client sends a meeting link to discuss a project. The browser opens a familiar-looking conference page, but the call will not start.<\/p><div id=\"mwtad3703528480\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>A notice says one component has expired and offers a quick update. The meeting is only a pretext, and the download is the part the sender actually wants.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Fake browser video meeting page claiming a required component has expired\" width=\"1536\" height=\"1024\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/video-call-update-scam-1.png\"><\/p>\n<div id=\"mwtad2538479321\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The meeting problem is staged on a fake webpage<\/h3>\n<p>A video call update scam begins with an ordinary business approach. Someone posing as a client, partner, investor, or contractor suggests a call and supplies a browser link.<\/p>\n<p>The page imitates a conferencing service and may show a loading screen, participant name, or preview controls. Instead of joining, the visitor sees an expired component or compatibility error.<\/p>\n<p>The proposed fix is malicious. It may be a downloaded file or a set of commands that installs credential-stealing malware on the computer.<\/p>\n<h3>Cryptocurrency users are valuable because transactions cannot be reversed<\/h3>\n<p>People working with digital assets may have wallet extensions, exchange sessions, signing tools, password managers, and business credentials on one device.<\/p>\n<p>Malware can search for those assets, steal an authenticated browser session, alter a payment address, or prepare a transaction that appears safe until it is signed.<\/p>\n<p>Once cryptocurrency moves to an attacker-controlled wallet, a bank cannot simply cancel the transfer. That makes prevention and immediate containment unusually important.<\/p>\n<h3>Police have warned about this precise meeting-link technique<\/h3>\n<p>The <a href=\"https:\/\/www.police.gov.sg\/Media-Hub\/News\/2026\/07\/20260701_police_advisory_on_cryptocurrency_scams_involving_malicious_links\" target=\"_blank\" rel=\"noopener\">Singapore Police Force documented malicious meeting links<\/a> sent by people posing as clients or business associates through messaging platforms.<\/p>\n<p>According to the advisory, victims saw a pop-up saying a software component had expired, then were told to download a file and execute commands. The resulting malware compromised their devices and cryptocurrency holdings.<\/p>\n<p>Warning signs include:<\/p>\n<ul>\n<li>a new business contact insisting on a meeting link they control;<\/li>\n<li>a conferencing page hosted on an unfamiliar or misspelled domain;<\/li>\n<li>a browser call demanding a separate codec, extension, or component update;<\/li>\n<li>instructions copied into Terminal, PowerShell, Run, or Command Prompt;<\/li>\n<li>a request to bypass a security warning so the meeting can begin;<\/li>\n<li>a download that arrives as an archive, script, disk image, or installer;<\/li>\n<li>a caller becoming urgent when you suggest using your own meeting room;<\/li>\n<li>unexpected wallet prompts or login alerts after opening the file.<\/li>\n<\/ul>\n<div id=\"mwtad2338947503\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Fake Update Is More Dangerous Than a Broken Call<\/h2>\n<p>A legitimate web meeting normally works through the browser or an application installed from the provider&#8217;s official site. A stranger&#8217;s page should not decide what software your computer needs.<\/p>\n<p>Attackers use a plausible technical interruption because people want to solve it quickly. Nobody wants a client waiting while they research a codec or compare domains.<\/p>\n<p>The page may adapt its instructions to the operating system. Windows visitors see one command, macOS visitors another, and researchers may receive harmless content.<\/p>\n<p>That selective behavior helps the campaign avoid detection. It also explains why a colleague opening the same link may not see the warning later.<\/p>\n<p>Command-based installation can appear less suspicious than an executable. The victim believes they are repairing the browser, yet the pasted command may download several hidden components.<\/p>\n<p>The meeting contact stays available to troubleshoot. If the first command fails, the scammer offers a second and explains why security protections must be changed.<\/p>\n<p>Once the payload runs, closing the fake page does not remove it. The malware may start with the computer, steal data in the background, or create remote access.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Fraudulent video conferencing update page offering a malicious download\" width=\"1536\" height=\"1024\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/video-call-update-scam-2.png\"><\/p>\n<div id=\"mwtad1117944799\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Video Call Update Scam Works<\/h2>\n<h3>Step 1: A business persona opens a believable conversation<\/h3>\n<p>The attacker contacts a cryptocurrency holder or employee through Telegram, LinkedIn, email, or another platform. The message references a deal, service, partnership, or investment.<\/p>\n<p>Public profiles make personalization easy. Knowing the victim&#8217;s role, company, or recent project is not proof of a genuine relationship.<\/p>\n<h3>Step 2: The attacker supplies the meeting room<\/h3>\n<p>Rather than accepting a link from the victim, the contact sends a special browser invitation. The URL and page resemble a known conferencing brand without necessarily using its real domain.<\/p>\n<p>The fake interface may display the caller&#8217;s name or a waiting participant to create pressure to join.<\/p>\n<h3>Step 3: A technical error interrupts the call<\/h3>\n<p>The page claims the camera, audio component, browser extension, or conferencing module is outdated. The error is designed, not discovered.<\/p>\n<p>A countdown, reconnect loop, or waiting-room notice can make the victim feel responsible for the delay.<\/p>\n<h3>Step 4: The victim is guided through the malicious fix<\/h3>\n<p>The site offers a file or tells the victim to copy commands into a system tool. The attacker may provide live assistance through chat.<\/p>\n<p>Security warnings are dismissed as normal because the component supposedly comes from the meeting provider.<\/p>\n<h3>Step 5: Malware steals sessions and credentials<\/h3>\n<p>The installed payload searches browsers, extensions, password stores, clipboard data, files, and application sessions. It can send selected information to attacker infrastructure.<\/p>\n<p>A stolen session may remain useful even if the victim has multifactor authentication, because the login was already approved before the theft.<\/p>\n<h3>Step 6: Wallet approvals or transfers are manipulated<\/h3>\n<p>The attacker may access exchange accounts, replace copied wallet addresses, or trick the victim into signing a transaction with broader effects than expected.<\/p>\n<p>On-chain approvals can grant future token access. A small or harmless-looking interaction may create continuing permission for another wallet.<\/p>\n<h3>Step 7: The meeting vanishes while access remains<\/h3>\n<p>The contact stops responding or claims the call must be rescheduled. Meanwhile, malware and stolen tokens may continue providing access.<\/p>\n<p>Later theft may look unrelated because it occurs after the fake meeting has faded from attention.<\/p>\n<div id=\"mwtad2965206498\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Verify a Video Meeting Safely<\/h2>\n<p>Create the meeting yourself using an account and application you already trust. A genuine contact interested in the conversation should be able to join your room.<\/p>\n<p>If they must host, inspect the parent domain before opening anything. A familiar brand word placed elsewhere in the address does not make the site official.<\/p>\n<p>Open the meeting provider manually and check whether an update is available there. Do not use the download button on a page reached from an unsolicited message.<\/p>\n<p>Never paste a command from a meeting page into a system prompt. Text can hide remote downloads, encoded scripts, persistence changes, and security exclusions.<\/p>\n<p>Use a separate low-privilege device for first calls with unknown contacts when practical. It should not contain wallet extensions, seed phrases, business secrets, or authenticated financial sessions.<\/p>\n<p>Confirm the person&#8217;s identity through an independent channel. Contact the organization using a public website or existing relationship rather than details in the same message.<\/p>\n<p>If a call fails, stop. A delayed meeting has a small cost; executing unknown software on a wallet-connected computer can have an irreversible one.<\/p>\n<div id=\"mwtad1449286203\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Wallet Prompts Can Hide More Than a Single Payment<\/h2>\n<p>Cryptocurrency theft does not always begin with a visible transfer. A malicious page can request permission to spend a token later, connect to a wallet, or sign structured data the victim cannot easily interpret.<\/p>\n<p>Read the destination, network, asset, amount, and permission scope on a trusted wallet interface. Do not rely on the explanation displayed by the website requesting the signature.<\/p>\n<p>A hardware wallet protects keys but cannot correct a transaction the owner intentionally approves. Its screen matters only if the user verifies what it shows.<\/p>\n<p>Clipboard-changing malware can replace a copied wallet address. Compare the beginning, middle, and end of the address on the signing device before approval.<\/p>\n<p>Token permissions should be reviewed after any suspected compromise. Revoking a malicious approval can prevent later movement, but it does not recover assets already transferred.<\/p>\n<p>If a seed phrase, private key, or recovery secret was exposed, the wallet cannot be made safe by changing a password. Remaining assets need a new uncompromised wallet created on a clean device.<\/p>\n<div id=\"mwtad2543267172\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Browser Page Cannot Legitimately Ask You to Do<\/h2>\n<p>A conferencing site can request browser permission to use the camera and microphone. That permission appears in the browser interface and can be reviewed or revoked without installing a mystery component.<\/p>\n<p>The page should not require a command in Terminal, PowerShell, or Command Prompt. Browsers do not repair audio by asking visitors to run encoded text supplied by a stranger.<\/p>\n<p>A meeting also does not need access to wallet seed phrases, exchange logins, browser exports, password stores, or cryptocurrency signatures. Any such request is unrelated to video communication.<\/p>\n<p>Be cautious when instructions use keyboard shortcuts to open system tools. The sequence may be designed to make downloaded code execute before the victim can read it.<\/p>\n<p>A real application update identifies its publisher and is distributed through the provider&#8217;s signed installer or official app store. A file hosted on the meeting organizer&#8217;s domain lacks that independent chain.<\/p>\n<p>If the contact says a security alert is normal, ask them to join a room you create instead. Refusal exposes that the technical problem belongs to the scam script.<\/p>\n<p>Business urgency cannot change these rules. A genuine customer can wait while software is verified, and a legitimate provider does not punish users for protecting wallet-connected devices.<\/p>\n<p>Report the meeting URL before closing the conversation. Hosting providers and conferencing brands may be able to disable the imitation before more targets reach it.<\/p>\n<p>Warn colleagues who may have received the same invitation. A copied business conversation can target several employees while making each approach look private and carefully researched.<\/p>\n<div id=\"mwtad1402611426\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>The business contact must exist outside the message<\/h3>\n<p>Confirm the person&#8217;s role through the organization&#8217;s official website, known colleagues, or a previously established channel. A profile and logo are easy to copy.<\/p>\n<p>Ask the company whether the proposed meeting and project are genuine.<\/p>\n<h3>The meeting address must belong to the real provider<\/h3>\n<p>Read the entire parent domain and compare it with a bookmark or official app. Ignore brand names placed in subdomains, paths, or decorative page text.<\/p>\n<p>A valid padlock only means the connection is encrypted; it does not identify an honest site.<\/p>\n<h3>Support must not arrive through the suspicious page<\/h3>\n<p>Obtain updates from the official provider&#8217;s application store or website. Do not accept technical support from the stranger who benefits from the installation.<\/p>\n<p>Close the page and contact the real service independently if an update seems necessary.<\/p>\n<h3>The download needs a verifiable software trail<\/h3>\n<p>Check the publisher, signature, source, hash, and documentation. Unknown scripts and unsigned packages should not run on a device holding valuable sessions.<\/p>\n<p>An explanation in chat is not software provenance.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Disconnect the device immediately.<\/strong> Turn off network access and stop using it for email, banking, exchanges, or wallet activity.<\/li>\n<li><strong>Move at-risk assets safely.<\/strong> From a clean device, contact custodial platforms and transfer self-custodied assets to a new wallet if private keys may be exposed.<\/li>\n<li><strong>Revoke suspicious permissions.<\/strong> Review token approvals and connected applications through trusted wallet tools. Unknown allowances can enable later theft.<\/li>\n<li><strong>End active sessions.<\/strong> Revoke browser, email, exchange, cloud, and messaging sessions, then change credentials from a separate trusted device.<\/li>\n<li><strong>Preserve the attack trail.<\/strong> Save the profile, chats, meeting URL, download, commands, wallet addresses, transaction hashes, and timestamps for investigators.<\/li>\n<li><strong>Get the device examined.<\/strong> Run a full Malwarebytes scan for known credential stealers, and seek professional incident response when business or high-value accounts were accessible.<\/li>\n<li><strong>Block repeat exposure.<\/strong> AdGuard can stop some known malicious meeting pages and advertising redirects, but it cannot make an unknown installer trustworthy.<\/li>\n<li><strong>Notify affected organizations.<\/strong> Tell your employer, partners, exchanges, and impersonated meeting provider before the attacker can abuse stolen access.<\/li>\n<li><strong>Report the incident.<\/strong> Contact local police and your national cybercrime agency. US victims can submit the domains and wallet evidence to <a href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noopener\">IC3.gov<\/a>.<\/li>\n<li><strong>Expect follow-up contact.<\/strong> Reject anyone offering guaranteed crypto recovery, transaction reversal, or hacking services for an advance payment.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Can a browser meeting legitimately need an update?<\/h3>\n<p>A provider may update its app, but you should obtain software through its official site or app store, never through a stranger&#8217;s meeting page.<\/p>\n<h3>Is the link safe if it shows a padlock?<\/h3>\n<p>No. HTTPS encrypts the connection but does not prove that the site&#8217;s owner is the company being imitated.<\/p>\n<h3>What if I downloaded the file but did not open it?<\/h3>\n<p>Delete it without running it, clear the browser download, and scan the device. Risk rises sharply if a command or installer executed.<\/p>\n<h3>Will changing my wallet password protect the funds?<\/h3>\n<p>Not if a seed phrase, private key, session, or token approval was exposed. Use a clean device and follow the wallet&#8217;s compromise procedure.<\/p>\n<h3>Can a hardware wallet prevent this scam?<\/h3>\n<p>It can protect key storage, but it cannot prevent a user from approving a malicious transaction or broad token permission.<\/p>\n<h3>Why would a scammer bother with a video-call story?<\/h3>\n<p>The planned technical failure gives the attacker a natural reason to make the victim download software and act quickly.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>A video call update scam turns a routine business meeting into permission to run malware on a valuable computer.<\/p>\n<p>If an unknown meeting page asks for a component, download, or system command, close it. Recreate the call through your own trusted service and verify the contact before touching any file.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A video call update scam can start when a prospective client sends a meeting link to discuss a project. The browser opens a familiar-looking conference page, but the call will not start. A notice says &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Video Call Update Scam Drains Crypto Wallets\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/video-call-update-scam\/#more-413286\" aria-label=\"Read more about Fake Video Call Update Scam Drains Crypto Wallets\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":413282,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-413286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/413286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=413286"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/413286\/revisions"}],"predecessor-version":[{"id":413325,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/413286\/revisions\/413325"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/413282"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=413286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=413286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=413286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}