Fake Zoom, Real Thieves: North Korean Hackers from BlueNoroff Scan Your Crypto Wallets
Your microphone isn’t working? It might be a trap. The cybersecurity company JUMPSEC has just dissected the latest campaign from BlueNoroff, an offshoot of the infamous Lazarus Group in the service of Pyongyang. The agenda includes fake Zoom and Microsoft Teams meetings, hijacked Telegram accounts, and malware that inventories the wallets of its victims even before striking. Crypto professionals are the primary targets, on both Windows and macOS.
Key Points {#h-key-points}
- BlueNoroff, linked to the North Korean Lazarus Group, traps crypto professionals through fake Zoom and Microsoft Teams meetings sent from hijacked Telegram accounts.
- The phishing kit inventories the browser wallet extensions to prioritize the wealthiest targets before delivering the malware.
- The malware strikes Windows and macOS: credentials, Chrome keys, and Telegram sessions are exfiltrated via a Telegram bot, with compromises occurring in less than five minutes.
- According to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in 2025, with a cumulative haul exceeding $6.75 billion since 2017.
Five Minutes to Trap a Victim {#h-five-minutes-to-trap-a-victim}
It all starts with an innocuous message. The target receives an invitation via the compromised Telegram account of a real contact or through a Calendly appointment link. The appointment leads to a typosquatted domain, meaning an address almost identical to that of the legitimate platform. More than 80 domains imitating Zoom or Teams have been registered since late 2025, according to researchers.
The fake meeting room takes realism to great lengths. Operators display fake participants, sometimes generated by AI or recycled from images of previous victims. From a control panel, the hacker animates the scene live and sends the infamous message: your microphone isn’t working.
The proposed solution? Install a supposed update for the Zoom SDK (Software Development Kit). This pretext actually triggers a ClickFix-type attack: the page copies a malicious command into the clipboard, and the victim executes it themselves in their terminal. In several documented cases, complete machine compromise took less than five minutes.
A Malware That Sorts Its Targets by Wallet {#h-a-malware-that-sorts-its-targets-by-wallet}
The real novelty lies in the reconnaissance phase. While the victim is busy fixing their fake microphone problem, the phishing kit scans their browser and lists the installed wallet extensions, with MetaMask at the top. Operators can thus gauge the value of each target and reserve their most elaborate payloads for the most well-stocked accounts.
Next comes the infection, tailored to the victim's system. On Windows, the execution chain installs persistence, remote control, and credential theft. On macOS, a fake Zoom or Teams installer appears while a stealer in the background sucks up system information, the master keys of Chrome stored in Apple’s Keychain, and Telegram sessions. The data then flows to a Telegram bot, and the malware can download an additional payload. JUMPSEC identified four macOS variants between April 22 and July 15, evidence of continuously refined tooling throughout the campaign.
< Malicious actors increasingly recognize that compromising individuals who control access can be as valuable as attacking the infrastructure itself. >
Researchers from JUMPSEC, in their report
Pyongyang and Its Crypto Heist Industry {#h-pyongyang-and-its-crypto-heist-industry}
BlueNoroff does not operate alone. The group belongs to the Lazarus galaxy, this digital armed wing of the North Korean regime that has already created fake companies to trap developers and is heavily suspected in the Upbit hack. The numerical tally is staggering: according to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in the year 2025 alone, including the Bybit heist of $1.5 billion. Since 2017, Pyongyang's cumulative haul exceeds $6.75 billion, enough to sustainably fund its armament programs.
In the face of adversaries of this caliber, a few simple reflexes remain the best defenses. Always check the exact domain of a meeting link, even if sent by a close contact, as their Telegram account may have been hijacked. Never paste a command into your terminal at the request of a website; no legitimate video conference requires it. And keep the majority of your funds on a hardware wallet isolated from your work machine: the day the fake Zoom rings, it will find nothing to scan.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Senior Nanny

Coinbase names new CTO after 14% workforce cut

ANSES Credit Installments: How to Know How Much You Owe

Solana vs Sui Whitepaper Comparison: Architecture, Performance & Scalability

"Not Just Holding Assets, But Making Them Work" - Evernorth CEO Discusses XRP Management Strategy

Oil Supports Sunflower Oil Prices, but Oversupply Limits Growth

Uzbekistan crypto mining: How will the Beshkala Mining Valley operate?

Is It Time for Airdrop After User Verification? Base's Airdrop on the Agenda?

Morgan Stanley Estimates CapEx Profits: How AI Infrastructure Can Earn 25%-50% Returns from Renting GPUs to Selling Tokens?

Losing $41.9 Million and Still Terminating the Contract? Block's Major Mining Client Chooses to Exit

$1.8 Million Lost to Fake Cryptocurrency App, Apple Sued by Victims

Altman Reflects on OpenAI's Toughest Year

Why Are South Koreans' Funds Flowing to the U.S. from 'Western Learning Ants' to Korean Pensions?

Rate Hike or Pause? New Federal Reserve Insights: Tonight's FOMC Key Points Explained

Silicon Valley VCs Observe Chinese Startups: A Tougher Capital Environment Breeds More Aggressive Companies

Who is the Biggest Winner in Changxin's IPO Feast?

Jump Capital doubles down on crypto with new $350M fund

134 Senior Bank Executives Call for Stablecoin Law Reform to Prevent Deposit Outflows

WEEX Daily Market Highlights | 2026.07.29
The following is WEEX's daily roundup of key stock token market highlights and upcoming earnings, helping you stay on top of market-moving events and trading opportunities.

Low Probability, High Impact: Citigroup Issues Extreme Risk Warnings for Commodities in the Second Half of 2026

4 Crypto Platforms Shut Down in a Month: Why This is Just the Beginning

July 29 Fed Rate Decision Schedule and Market Impact: What Warsh's Announcement Means for Big Tech Earnings
July 29 Fed rate decision schedule: what Kevin Warsh's FOMC announcement means for Big Tech earnings from Microsoft, Meta, Apple, and Amazon in 2026.

JPX-QUICK Cryptocurrency Index Announces Four Reference Exchanges

After Abolishing Forward Guidance, Warsh May Raise Rates Sooner Than Market Expects

Dialogue with Tom Lee: The Recent Plunge in Korean Stocks is Forced Deleveraging, Don't Trade in Structural Trends

ARK Invest researcher predicts more crypto shutdowns

Beware! Is PIPEDOG a Scam? What Are the On-Chain Doubts?

Crypto Venture Capital: 61 Fundraising Rounds in June, a Six-Year Low

When will I receive ANSES payments: retirees, AUH, unemployment, and other benefits for Wednesday, July 29











