Wu Shuo learned that Slow Fog has tweeted to remind users to be wary of phishing attacks disguised as Zoom meeting links, in which attackers use the domain "app[.]us4zoom[.]us" to impersonate legitimate Zoom meeting links. The webpage is highly similar to the real Zoom meeting interface. When users click the "Start Meeting" button, it triggers the download of a malicious installer instead of launching the local Zoom client. Hackers collect user data and decrypt it to steal sensitive information such as mnemonics and private keys. These attacks often combine social engineering and Trojan techniques. Based on the analysis of a hacker address provided by a victim, the hacker address has profited over one million dollars, including USD0++, MORPHO, ETH, etc., among which USD0++ and MORPHO were exchanged for 296 ETH.