Fake Zoom, Real Thieves: North Korean Hackers from BlueNoroff Scan Your Crypto Wallets
Your microphone isn’t working? It might be a trap. The cybersecurity company JUMPSEC has just dissected the latest campaign from BlueNoroff, an offshoot of the infamous Lazarus Group in the service of Pyongyang. The agenda includes fake Zoom and Microsoft Teams meetings, hijacked Telegram accounts, and malware that inventories the wallets of its victims even before striking. Crypto professionals are the primary targets, on both Windows and macOS.
Key Points {#h-key-points}
- BlueNoroff, linked to the North Korean Lazarus Group, traps crypto professionals through fake Zoom and Microsoft Teams meetings sent from hijacked Telegram accounts.
- The phishing kit inventories the browser wallet extensions to prioritize the wealthiest targets before delivering the malware.
- The malware strikes Windows and macOS: credentials, Chrome keys, and Telegram sessions are exfiltrated via a Telegram bot, with compromises occurring in less than five minutes.
- According to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in 2025, with a cumulative haul exceeding $6.75 billion since 2017.
Five Minutes to Trap a Victim {#h-five-minutes-to-trap-a-victim}
It all starts with an innocuous message. The target receives an invitation via the compromised Telegram account of a real contact or through a Calendly appointment link. The appointment leads to a typosquatted domain, meaning an address almost identical to that of the legitimate platform. More than 80 domains imitating Zoom or Teams have been registered since late 2025, according to researchers.
The fake meeting room takes realism to great lengths. Operators display fake participants, sometimes generated by AI or recycled from images of previous victims. From a control panel, the hacker animates the scene live and sends the infamous message: your microphone isn’t working.
The proposed solution? Install a supposed update for the Zoom SDK (Software Development Kit). This pretext actually triggers a ClickFix-type attack: the page copies a malicious command into the clipboard, and the victim executes it themselves in their terminal. In several documented cases, complete machine compromise took less than five minutes.
A Malware That Sorts Its Targets by Wallet {#h-a-malware-that-sorts-its-targets-by-wallet}
The real novelty lies in the reconnaissance phase. While the victim is busy fixing their fake microphone problem, the phishing kit scans their browser and lists the installed wallet extensions, with MetaMask at the top. Operators can thus gauge the value of each target and reserve their most elaborate payloads for the most well-stocked accounts.
Next comes the infection, tailored to the victim's system. On Windows, the execution chain installs persistence, remote control, and credential theft. On macOS, a fake Zoom or Teams installer appears while a stealer in the background sucks up system information, the master keys of Chrome stored in Apple’s Keychain, and Telegram sessions. The data then flows to a Telegram bot, and the malware can download an additional payload. JUMPSEC identified four macOS variants between April 22 and July 15, evidence of continuously refined tooling throughout the campaign.
< Malicious actors increasingly recognize that compromising individuals who control access can be as valuable as attacking the infrastructure itself. >
Researchers from JUMPSEC, in their report
Pyongyang and Its Crypto Heist Industry {#h-pyongyang-and-its-crypto-heist-industry}
BlueNoroff does not operate alone. The group belongs to the Lazarus galaxy, this digital armed wing of the North Korean regime that has already created fake companies to trap developers and is heavily suspected in the Upbit hack. The numerical tally is staggering: according to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in the year 2025 alone, including the Bybit heist of $1.5 billion. Since 2017, Pyongyang's cumulative haul exceeds $6.75 billion, enough to sustainably fund its armament programs.
In the face of adversaries of this caliber, a few simple reflexes remain the best defenses. Always check the exact domain of a meeting link, even if sent by a close contact, as their Telegram account may have been hijacked. Never paste a command into your terminal at the request of a website; no legitimate video conference requires it. And keep the majority of your funds on a hardware wallet isolated from your work machine: the day the fake Zoom rings, it will find nothing to scan.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

WEEX GOGOGO Ep.5 Goes Live July 31: Trade Smarter, Move Faster
WEEX GOGOGO Ep.5 goes live July 31, 19:00 (UTC+8). Watch the WEEX product launch for the 1000 BTC Protection Fund, TG Mini App, Passkey security, and a live prize pool worth thousands. Set your reminder now.

Alphabet: Record Profit and Worst Cash Flow in Its History, at the Same Time

The inside story of how a hike in Hong Kong changed crypto trading forever

Tiger Research: AI Agent Wallets Become New Battlefield in Cryptocurrency, Giants like Coinbase Prepare for Micro Payments

New Cardano partnership promises to monetize your private data, but payouts likely start at just $1.25 a year

The Tranquil Corner of San Luis to Disconnect from Routine Among Dikes and Hills

Tokenized Gold: How the Crypto Technology Works That Allows You to Buy a Gram of Precious Metal Without Holding It in Your Hand

Dash RSI: The Detail of the Movement That Challenges Imminent Reversal

Kalshi: A White House Employee Loses Job After Betting on Trump's Speeches

Bernstein cuts Circle price target to $140, says Open USD threat will fade

18 confirmed dead after earthquake in Japan: search for missing continues

XRP Reaches $100 Trillion? Analysts Point Out That Collateral is Key

Four women accuse actor and musician Jared Leto of sexual offenses

Salary, Schedule, and Booking: What Motivates Ukrainians to Change Jobs

Real Vision Founder: Rethinking the Long-Term Value of Cryptocurrency After 13 Years of Bull and Bear Markets

Ondo Buries Its Own Blockchain for a Private Network Tailored for Institutional Perpetuals

Nextflow AI OS Unveils at Malaysia Blockchain Week, Launching the World’s First AI Smart Body Phone to Ignite Southeast Asia's Web3 Market

STRC Dividend Becomes a 'Poison Pill', $500 Million in DeFi Synthetic Dollars Trapped

They survived the crypto crash of 2022, but they are closing down in 2026

Primitive Ventures: After US Brokerages Exit, Chinese Retail Investors Are Searching for the 'Missing Buy Button'

Institutions and Ethereum Whales Send Important Signal. Is There Unnecessary Rush?

Nine Major Doubts Smart People Have About Bitcoin

Government and Economic Freedom: Is the State a Brake or an Engine?

Increases in ARCA: How much will be paid in monotributo starting August 2026

When 8 Million ETH Start to "Move": A Structural Change in Staking After the Pectra Era?

Kimi Secures Over $3.5 Billion in Funding, Valuation Rises to $35 Billion, Pre-IPO Round Launched Early

Ripple-era SEC chair Jay Clayton confirmed as DNI

Senior Nanny

Coinbase names new CTO after 14% workforce cut

ANSES Credit Installments: How to Know How Much You Owe
WEEX GOGOGO Ep.5 Goes Live July 31: Trade Smarter, Move Faster
WEEX GOGOGO Ep.5 goes live July 31, 19:00 (UTC+8). Watch the WEEX product launch for the 1000 BTC Protection Fund, TG Mini App, Passkey security, and a live prize pool worth thousands. Set your reminder now.











