Fake Zoom, Real Thieves: North Korean Hackers from BlueNoroff Scan Your Crypto Wallets
Your microphone isn’t working? It might be a trap. The cybersecurity company JUMPSEC has just dissected the latest campaign from BlueNoroff, an offshoot of the infamous Lazarus Group in the service of Pyongyang. The agenda includes fake Zoom and Microsoft Teams meetings, hijacked Telegram accounts, and malware that inventories the wallets of its victims even before striking. Crypto professionals are the primary targets, on both Windows and macOS.
Key Points {#h-key-points}
- BlueNoroff, linked to the North Korean Lazarus Group, traps crypto professionals through fake Zoom and Microsoft Teams meetings sent from hijacked Telegram accounts.
- The phishing kit inventories the browser wallet extensions to prioritize the wealthiest targets before delivering the malware.
- The malware strikes Windows and macOS: credentials, Chrome keys, and Telegram sessions are exfiltrated via a Telegram bot, with compromises occurring in less than five minutes.
- According to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in 2025, with a cumulative haul exceeding $6.75 billion since 2017.
Five Minutes to Trap a Victim {#h-five-minutes-to-trap-a-victim}
It all starts with an innocuous message. The target receives an invitation via the compromised Telegram account of a real contact or through a Calendly appointment link. The appointment leads to a typosquatted domain, meaning an address almost identical to that of the legitimate platform. More than 80 domains imitating Zoom or Teams have been registered since late 2025, according to researchers.
The fake meeting room takes realism to great lengths. Operators display fake participants, sometimes generated by AI or recycled from images of previous victims. From a control panel, the hacker animates the scene live and sends the infamous message: your microphone isn’t working.
The proposed solution? Install a supposed update for the Zoom SDK (Software Development Kit). This pretext actually triggers a ClickFix-type attack: the page copies a malicious command into the clipboard, and the victim executes it themselves in their terminal. In several documented cases, complete machine compromise took less than five minutes.
A Malware That Sorts Its Targets by Wallet {#h-a-malware-that-sorts-its-targets-by-wallet}
The real novelty lies in the reconnaissance phase. While the victim is busy fixing their fake microphone problem, the phishing kit scans their browser and lists the installed wallet extensions, with MetaMask at the top. Operators can thus gauge the value of each target and reserve their most elaborate payloads for the most well-stocked accounts.
Next comes the infection, tailored to the victim's system. On Windows, the execution chain installs persistence, remote control, and credential theft. On macOS, a fake Zoom or Teams installer appears while a stealer in the background sucks up system information, the master keys of Chrome stored in Apple’s Keychain, and Telegram sessions. The data then flows to a Telegram bot, and the malware can download an additional payload. JUMPSEC identified four macOS variants between April 22 and July 15, evidence of continuously refined tooling throughout the campaign.
< Malicious actors increasingly recognize that compromising individuals who control access can be as valuable as attacking the infrastructure itself. >
Researchers from JUMPSEC, in their report
Pyongyang and Its Crypto Heist Industry {#h-pyongyang-and-its-crypto-heist-industry}
BlueNoroff does not operate alone. The group belongs to the Lazarus galaxy, this digital armed wing of the North Korean regime that has already created fake companies to trap developers and is heavily suspected in the Upbit hack. The numerical tally is staggering: according to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in the year 2025 alone, including the Bybit heist of $1.5 billion. Since 2017, Pyongyang's cumulative haul exceeds $6.75 billion, enough to sustainably fund its armament programs.
In the face of adversaries of this caliber, a few simple reflexes remain the best defenses. Always check the exact domain of a meeting link, even if sent by a close contact, as their Telegram account may have been hijacked. Never paste a command into your terminal at the request of a website; no legitimate video conference requires it. And keep the majority of your funds on a hardware wallet isolated from your work machine: the day the fake Zoom rings, it will find nothing to scan.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

Everything You Need to Check on Your Car Before Doing the VTV to Pass the Process

Wheat and soybean prices reach two-year highs due to the impact of the Middle East war

Can Recent Crypto Exchange Closures Signal the End of the Bear Market?

Hyperliquid, Multicoin back CFTC prediction market rules

Crypto is rewriting how Wall Street traders spend their weekends

Elon Musk predicts the end of mandatory work and money within 10 years

XRP Whales Buy While Small Wallets Sell

Will Money Become Obsolete by 2036? Bitcoin as the Ultimate Currency?

Artificial Intelligence Consumes Increasing Amounts of Electricity and Accelerates Investments in Data Centers

Which Cryptocurrencies Does Elon Musk Invest In?

Experts' Opinions on the Future Fed Rate Decision Are Divided

The leading prop trading firms: Multi-asset vs crypto-native compared

Zcash sets Ironwood upgrade for July 28 after Orchard bug

Can You Trade Stocks With USDT? Why Crypto Exchanges Are Moving Into TradFi

Value Investing Guru Warns: AI Bubble May Burst, SpaceX is Nonsense, Bitcoin Will Go to Zero

Dollar: After Another Weekly Increase, the Market Processes Official Signals on the Exchange Rate

Institutions and On-chain Funds Optimistic About Changxin's Continued Surge, Except for Koreans

Who Benefits After AI Creates Trillions in Value? The U.S. Sparks Debate on AI Wealth Distribution Models

Coinbase bets on agentic finance as Base payments cross 100M

Oil Falls More Than 6% After Pause in Middle East Attacks as Markets Surge

First Research Report from Yili Hua's New AI Fund: The Wave of AI Computing Assetization, Axe Compute May Become the Most Undervalued GPU Computing Entry in the US Stock Market

A Collective Confession of the Three Longest-Lasting Crypto OGs – FACE Podcast

BNY unit wins MiCA entry as Europe’s crypto register hits 309

Reduction of VAT, support for IDPs and businesses: frontline communities present key proposals to the government program

Are crypto tokens overpriced when equity owns the real profits?

EU MiCA Transition Period Ends, Many Crypto Service Providers Face Exit Pressure? Understanding MiCA

U.S. Treasuries Pressure Walsh: Hawkish Stance Alone Is Not Enough, Market Wants Rate Hikes

Propinder Launches Free Prop Firm Comparison Tool For Trading Challenges

Nearly 90% of Stolen Funds Cannot Be Recovered: Web3 Attack Targets Shift from 'Code' to 'People' in the First Half of 2026










