Fake Zoom, Real Thieves: North Korean Hackers from BlueNoroff Scan Your Crypto Wallets
Your microphone isn’t working? It might be a trap. The cybersecurity company JUMPSEC has just dissected the latest campaign from BlueNoroff, an offshoot of the infamous Lazarus Group in the service of Pyongyang. The agenda includes fake Zoom and Microsoft Teams meetings, hijacked Telegram accounts, and malware that inventories the wallets of its victims even before striking. Crypto professionals are the primary targets, on both Windows and macOS.
Key Points {#h-key-points}
- BlueNoroff, linked to the North Korean Lazarus Group, traps crypto professionals through fake Zoom and Microsoft Teams meetings sent from hijacked Telegram accounts.
- The phishing kit inventories the browser wallet extensions to prioritize the wealthiest targets before delivering the malware.
- The malware strikes Windows and macOS: credentials, Chrome keys, and Telegram sessions are exfiltrated via a Telegram bot, with compromises occurring in less than five minutes.
- According to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in 2025, with a cumulative haul exceeding $6.75 billion since 2017.
Five Minutes to Trap a Victim {#h-five-minutes-to-trap-a-victim}
It all starts with an innocuous message. The target receives an invitation via the compromised Telegram account of a real contact or through a Calendly appointment link. The appointment leads to a typosquatted domain, meaning an address almost identical to that of the legitimate platform. More than 80 domains imitating Zoom or Teams have been registered since late 2025, according to researchers.
The fake meeting room takes realism to great lengths. Operators display fake participants, sometimes generated by AI or recycled from images of previous victims. From a control panel, the hacker animates the scene live and sends the infamous message: your microphone isn’t working.
The proposed solution? Install a supposed update for the Zoom SDK (Software Development Kit). This pretext actually triggers a ClickFix-type attack: the page copies a malicious command into the clipboard, and the victim executes it themselves in their terminal. In several documented cases, complete machine compromise took less than five minutes.
A Malware That Sorts Its Targets by Wallet {#h-a-malware-that-sorts-its-targets-by-wallet}
The real novelty lies in the reconnaissance phase. While the victim is busy fixing their fake microphone problem, the phishing kit scans their browser and lists the installed wallet extensions, with MetaMask at the top. Operators can thus gauge the value of each target and reserve their most elaborate payloads for the most well-stocked accounts.
Next comes the infection, tailored to the victim's system. On Windows, the execution chain installs persistence, remote control, and credential theft. On macOS, a fake Zoom or Teams installer appears while a stealer in the background sucks up system information, the master keys of Chrome stored in Apple’s Keychain, and Telegram sessions. The data then flows to a Telegram bot, and the malware can download an additional payload. JUMPSEC identified four macOS variants between April 22 and July 15, evidence of continuously refined tooling throughout the campaign.
< Malicious actors increasingly recognize that compromising individuals who control access can be as valuable as attacking the infrastructure itself. >
Researchers from JUMPSEC, in their report
Pyongyang and Its Crypto Heist Industry {#h-pyongyang-and-its-crypto-heist-industry}
BlueNoroff does not operate alone. The group belongs to the Lazarus galaxy, this digital armed wing of the North Korean regime that has already created fake companies to trap developers and is heavily suspected in the Upbit hack. The numerical tally is staggering: according to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in the year 2025 alone, including the Bybit heist of $1.5 billion. Since 2017, Pyongyang's cumulative haul exceeds $6.75 billion, enough to sustainably fund its armament programs.
In the face of adversaries of this caliber, a few simple reflexes remain the best defenses. Always check the exact domain of a meeting link, even if sent by a close contact, as their Telegram account may have been hijacked. Never paste a command into your terminal at the request of a website; no legitimate video conference requires it. And keep the majority of your funds on a hardware wallet isolated from your work machine: the day the fake Zoom rings, it will find nothing to scan.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Azure Surpasses $100 Billion, Driving Record Revenue for Microsoft

Who were the seven people who died in the helicopter accident in San Juan

Cryptocurrency Exchanges Are 'Stealing' Ground from Traditional Brokers

BCRA Resumes Purchases as Reserves Exceed $49 Billion Again

Flock Cameras Face Growing Backlash as Privacy Concerns Reach Capitol Hill

Spider-Man: A New Day

Over 100 Participants Close Ethereum Institutional Funding

"There is no soft inflation target at the FED": Kevin Warsh

Poland Falls Behind in Cryptocurrency Dispute Due to Politicians

Goodbye to Corner Furniture: The Decorating Trend Transforming Homes in 2026

FIFA: $20 Billion Linked to Trump-Connected Fund, UEFA Pushes Back

Status Quo on the Fed in the USA, Bitcoin Raises Only an Eyebrow

Aviva Investors launches first tokenized fund on XRPL

China vs USA: After AI, the Humanoid Robot War is Declared

As crypto perpetual futures boom, Ethereum’s role is shifting

License Retention on the Road: When They Can Take It Away and How to Avoid It

Tecnópolis: A Giant of Entertainment Joins the Bid for the Concession of the Site

Visa CEO sidesteps labeling Open USD a challenger to Tether and USDC: 'Our role is not to pick winners'

Anchorage Digital says Fed’s proposed payment account is no 'workable substitute' for master account

Kimi K3: The License That Is Only Open Source in Name

Why locked liquidity does not mean a token is safe

CABA Launches a Contest to Transform the Look of the Microcenter: Who Can Participate and How to Sign Up

Morgan Stanley is using $7.4 trillion in client assets and rock-bottom fees to hijack Wall Street’s crypto boom

Unemployment Benefit from ANSES in August: Amounts and New Changes

XRP retail trading launches on licensed Hong Kong venue

OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Face

The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs

US Banks Maintain Optimism on Argentina's Macro Outlook, but Warn of Growth Challenges

XRP Ledger activates fix, blocks nodes below 3.2.0











