Latest News

North Korea-Linked BlueNoroff Uses Fake Zoom and Teams…

Cybersecurity researchers warn that the Lazarus subgroup is weaponizing fake video conferences to profile victims before deploying malware designed to steal crypto wallets and credentials. North Korea-linked hacking group BlueNoroff has launched a sophisticated social-engineering campaign that uses fake Zoom and Microsoft Teams meetings to target cryptocurrency users, adding a new layer of deception to one of the industry’s most persistent cyber threats.

According to cybersecurity researchers, the attackers begin by compromising Telegram accounts or impersonating trusted industry contacts before inviting victims to what appear to be legitimate business meetings. The campaign primarily targets cryptocurrency founders, developers, investors and other Web3 professionals, relying on carefully crafted social engineering rather than exploiting blockchain vulnerabilities. Once a victim joins the meeting, the attackers claim there is a technical issue with the call and instruct the target to install a supposed software update or software development kit (SDK) to resolve audio or video problems. Instead of fixing the meeting, the download installs malware capable of compromising the victim’s device.

Researchers say the malicious software can search for browser-stored wallet credentials, steal Telegram session data, harvest authentication tokens and collect other sensitive system information that may ultimately allow attackers to access cryptocurrency holdings.

Campaign Blends AI With Traditional Social Engineering

Security analysts attribute the operation to BlueNoroff, a financially motivated subgroup of North Korea’s Lazarus Group that has been linked to numerous high-profile cryptocurrency thefts over the past decade. Unlike many previous campaigns that relied on phishing emails, this operation uses live or prerecorded video meetings, AI-generated avatars, typosquatted Zoom and Microsoft Teams domains, and convincing impersonations of known industry figures to build trust before delivering malware.

Researchers estimate the campaign has already targeted more than 100 individuals across over 20 countries, with the United States accounting for the largest share of victims. Some attacks reportedly compromise victims in less than five minutes after the fake meeting begins. The tactics reflect a broader trend in cybercrime in which attackers increasingly exploit human behavior instead of searching for software vulnerabilities. By persuading users to install malware themselves, the hackers can bypass many conventional security controls.

BlueNoroff has historically focused on stealing cryptocurrency to generate revenue for North Korea, making exchanges, decentralized finance platforms, venture funds and blockchain developers frequent targets.

Crypto Industry Faces Growing Human Security Risk

The latest campaign underscores how cryptocurrency security has expanded beyond protecting private keys and smart contracts. Even sophisticated organizations with strong technical defenses remain vulnerable if employees can be manipulated into granting attackers direct access to their devices. Cybersecurity experts recommend verifying meeting invitations through independent communication channels, avoiding downloads suggested during unexpected calls and confirming website addresses before installing any software. Organizations are also encouraged to use hardware security keys, endpoint detection tools and strict application controls to reduce the impact of successful social-engineering attacks. The campaign follows several years of increasingly aggressive operations attributed to North Korean hacking groups, including attacks on cryptocurrency exchanges, bridge protocols and individual wallet holders that have collectively resulted in billions of dollars in digital asset losses.

As cryptocurrency adoption continues to grow, attackers appear increasingly willing to combine artificial intelligence, identity impersonation and trusted collaboration platforms into highly convincing fraud campaigns. For crypto users, the lesson is becoming increasingly clear: the greatest security risk may no longer be the blockchain itself, but the seemingly ordinary video meeting invitation that arrives from someone they believe they already know.

You may also like