• About
  • FAQ
  • Landing Page
Newsletter
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Uncategorized

Fake Zoom malware scam tied to North Korean hackers targets crypto users

admin by admin
December 15, 2025
in Uncategorized
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Fake Zoom malware scam tied to North Korean hackers targets crypto users
  • The scam relies on Telegram impersonation and pre recorded video calls to build trust.
  • Malware is delivered as a fake audio or SDK patch during the meeting.
  • Security Alliance says it is tracking multiple such attempts every day.

North Korean cybercriminals are escalating social engineering attacks by exploiting fake Zoom and Teams meetings to deploy malware that drains sensitive data and cryptocurrency wallets.

Cybersecurity firm Security Alliance, also known as SEAL, has warned that it is tracking multiple daily attempts linked to these campaigns.

The activity highlights a shift toward more convincing, real-time deception rather than crude phishing.

The warning follows disclosures by MetaMask security researcher Taylor Monahan, who has been monitoring the pattern closely and flagging the scale of losses already linked to the tactic.

The method relies on familiarity, trust, and workplace habits, making it particularly effective against professionals in crypto and tech who regularly use video conferencing tools.

How the fake Zoom scam works

The attack typically begins on Telegram, where victims receive a message from an account that appears to belong to someone they already know. The attackers specifically target contacts with existing chat history, increasing credibility and lowering suspicion.

Once engagement starts, the victim is guided toward scheduling a meeting through a Calendly link, which leads to what looks like a legitimate Zoom call.

When the meeting opens, the victim sees what appears to be a live video feed of their contact and other team members.

In reality, the footage is pre-recorded, not AI-generated deepfakes.

During the call, the attacker claims there are audio issues and suggests installing a quick fix.

A file is shared in the chat and presented as a patch or software development kit update to restore sound clarity.

That file contains the malware payload. Once installed, it gives the attacker remote access to the victim’s device.

Malware impact on crypto wallets

The malicious software is often a Remote Access Trojan. After installation, it silently extracts sensitive information, including passwords, internal security documentation, and private keys.

In crypto-focused environments, this can result in complete wallet drainage with little immediate indication of compromise.

Monahan has warned on X that more than $300m has already been stolen using variations of this approach, and that the same threat actors continue to exploit fake Zoom and Teams meetings to compromise users.

SEAL has echoed the concern, noting the frequency and consistency of these attempts across the crypto sector.

North Korea’s evolving cyber playbook

North Korean hacking groups have long been linked to financially motivated cybercrime, with proceeds believed to support the regime.

Groups such as Lazarus have previously targeted exchanges and blockchain firms through direct exploits and supply chain attacks.

More recently, these actors have leaned heavily into social engineering.

In recent months, they have infiltrated crypto companies using fake job applications and staged interview processes designed to deliver malware.

Last month, Lazarus was linked to a breach at South Korea’s largest exchange, Upbit, which resulted in losses of roughly $30.6 million.

The fake Zoom tactic reflects a broader strategic pivot toward human-centric attack vectors that bypass technical safeguards.

What experts say users should do

Security experts warn that once a malicious file is executed, speed matters.

In cases of suspected infection during a call, users are advised to immediately disconnect from WiFi and power off the device to interrupt data exfiltration.

The broader warning is to treat unexpected meeting links, software patches, and urgent technical requests with extreme caution, even when they appear to come from known contacts.


Share this article

Categories

Tags



Source link

Related articles

Playnance plans to list utility token G Coin on March 18

Playnance plans to list utility token G Coin on March 18

March 14, 2026
Bitcoin targets $73,000 as crypto bounces despite oil price jitters

Bitcoin targets $73,000 as crypto bounces despite oil price jitters

March 13, 2026
Share76Tweet47

Related Posts

Playnance plans to list utility token G Coin on March 18

Playnance plans to list utility token G Coin on March 18

by admin
March 14, 2026
0

Playnance to launch G Coin on March 18. Token enters market with 200,000 holders and $38M estimated valuation. Ecosystem...

Bitcoin targets $73,000 as crypto bounces despite oil price jitters

Bitcoin targets $73,000 as crypto bounces despite oil price jitters

by admin
March 13, 2026
0

Bitcoin is charging toward $73,000 amid a fresh decoupling from the stock market. The surge in BTC price comes despite...

XLM bounces from $0.15 lows, but bears remain in control

Ethereum price forecast: bulls hold $2K support amid CEX outflows

by admin
March 12, 2026
0

Ethereum price hovered just above $2,000 as whales moved ETH off exchanges. Large holder activity sees Ethereum exchange balances fall...

Internet Computer token surges 12% to near $3: why did ICP price spike?

Internet Computer token surges 12% to near $3: why did ICP price spike?

by admin
March 11, 2026
0

Internet Computer price jumped 12% to near $3 during Asian trading hours. The ICP token hit the intraday highs amid...

Polkadot price outlook: bulls test key resistance near $1.50

Polkadot price outlook: bulls test key resistance near $1.50

by admin
March 10, 2026
0

Polkadot price fluctuated in a tight range near $1.50 on Tuesday. Bulls could push to above $1.67 ahead of DOT...

Load More
  • Trending
  • Comments
  • Latest
XRP price holds firm amid 30% volume spike

XRP price holds firm amid 30% volume spike

December 26, 2025
Lido DAO’s LDO price spikes as Arthur Hayes acquires 1.85M tokens

Lido DAO’s LDO price spikes as Arthur Hayes acquires 1.85M tokens

December 26, 2025
Solana Pullback Finds Purpose As Strong Hands Eye Accumulation Below $160

Solana Pullback Finds Purpose As Strong Hands Eye Accumulation Below $160

November 6, 2025
Bitcoin hashprice sinks to 2-year low as AI pivots split miners

Bitcoin hashprice sinks to 2-year low as AI pivots split miners

November 5, 2025

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Bitcoin Hit a Major Milestone—Most Miners Won’t Be Around for the Next One

Bitcoin Hit a Major Milestone—Most Miners Won’t Be Around for the Next One

March 14, 2026
Playnance plans to list utility token G Coin on March 18

Playnance plans to list utility token G Coin on March 18

March 14, 2026
Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

March 14, 2026
Balaji Urges Crypto Industry to Build Tools for Refugees

Balaji Urges Crypto Industry to Build Tools for Refugees

March 14, 2026

Recent News

Bitcoin Hit a Major Milestone—Most Miners Won’t Be Around for the Next One

Bitcoin Hit a Major Milestone—Most Miners Won’t Be Around for the Next One

March 14, 2026
Playnance plans to list utility token G Coin on March 18

Playnance plans to list utility token G Coin on March 18

March 14, 2026

Categories

  • Bitcoin
  • Blockchain
  • Business
  • Ethereum
  • Guide
  • Market
  • Regulation
  • Ripple
  • Uncategorized
  • About
  • FAQ
  • Support Forum
  • Landing Page
  • Contact Us

© Copyright 2025 All Rights Reserved.

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© Copyright 2025 All Rights Reserved.