• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Clarity act

Lummis ties Clarity Act’s fate to North Korea’s $6.75 billion crypto haul

07/27/2026
Coinbase prediction market

The agency that fined Wall Street for deleted texts just got caught doing the same thing

07/27/2026
Crypto malware

North Korean hackers scanned 100 crypto executives’ wallets through fake Zoom calls

07/27/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Clarity act

Lummis ties Clarity Act’s fate to North Korea’s $6.75 billion crypto haul

07/27/2026
Coinbase prediction market

The agency that fined Wall Street for deleted texts just got caught doing the same thing

07/27/2026
Crypto malware

North Korean hackers scanned 100 crypto executives’ wallets through fake Zoom calls

07/27/2026
Monday, July 27, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Breaking News

North Korean hackers scanned 100 crypto executives’ wallets through fake Zoom calls

The North Korea-linked hacking group is using compromised Telegram accounts, AI-generated faces and fake meeting updates to identify valuable crypto targets before deploying malware.

by Elizabeth Omotoke
3 hours ago
in Breaking News
Reading Time: 5 mins read
0
Crypto malware

Crypto malware

Share on FacebookShare on Twitter

North Korean hacking group BlueNoroff has compromised more than 100 crypto and Web3 executives across 20-plus countries by scanning victims’ wallets during fake Zoom and Microsoft Teams calls before deciding whether to deploy malware, according to research from cybersecurity firms JUMPSEC and Arctic Wolf.

Security researchers at UK cybersecurity firm JUMPSEC said they obtained and analyzed the source code of an active phishing kit that impersonates Zoom and Microsoft Teams. The operation combines compromised Telegram accounts, fake meeting invitations, AI-generated video participants and wallet fingerprinting to create a highly targeted attack chain.

The campaign has reached more than 100 victims across over 20 countries, according to research from Arctic Wolf. The United States accounted for 41% of identified targets, while roughly 80% worked in cryptocurrency, blockchain finance or related sectors. Founders and CEOs made up 45% of the targets.

JUMPSEC described the operation as a system that combines “compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline.”

Crypto malware campaign profiles wallets before infection

The most significant feature of the campaign is what happens before the malware is delivered.

JUMPSEC said BlueNoroff’s fake meeting pages can quietly inspect a visitor’s browser for cryptocurrency wallet activity. The kit uses EIP-6963 and older browser-based methods to identify Ethereum-compatible wallets, while also checking for non-EVM ecosystems such as Solana.

The information is sent to an attacker-controlled dashboard without displaying a warning to the victim. On Windows, the kit also checks browser-extension identifiers across Chrome, Edge, Brave, Opera, Vivaldi and Firefox, allowing operators to identify installations such as MetaMask.

That reconnaissance gives attackers a way to separate ordinary visitors from potentially lucrative targets.

Rather than automatically dropping a malicious payload on everyone who opens the fake meeting page, operators can assess whether a target appears to have valuable crypto infrastructure and then decide whether to proceed.

This makes the operation more than conventional phishing. It is effectively a filtering system designed to prioritize people who may have access to digital assets.

Fake Zoom calls weaponize trust and AI

The campaign’s first step often begins with a compromised Telegram account belonging to someone within the cryptocurrency industry.

Attackers use the hijacked account to send convincing meeting invitations, including Calendly links, to contacts who already trust the sender. The recipient is then directed toward a domain designed to resemble a legitimate Zoom or Teams address.

JUMPSEC found more than one version of the meeting kit and evidence of an incomplete Google Meet clone in the exposed code. The fake Teams environment includes familiar interface features such as emoji reactions, device controls and background effects, making the page look less like a phishing site and more like a genuine business meeting.

The deception becomes more sophisticated once the victim joins.

The fake meeting can request webcam access and quietly transmit the camera feed to the operator. The victim is then shown a waiting screen while a pre-recorded participant appears to be joining the call.

The supposed participant may tell the victim that their microphone is malfunctioning before claiming that a Zoom software component needs an update. A fake update notification then creates the opening for the next stage of the attack.

According to JUMPSEC, the face shown during the call is not necessarily a live participant. Attackers have combined AI-generated headshots with body movements captured from previous meetings, creating synthetic participants designed to appear believable.

Arctic Wolf similarly described the operation as a “self-sustaining deepfake pipeline,” with stolen victim material potentially helping create more convincing lures for subsequent targets.

Windows and macOS receive different malware payloads

Once a target has been selected, the Crypto malware operation shifts from reconnaissance to compromise.

On Windows, the fake Zoom update uses a ClickFix-style technique. The victim is presented with instructions that appear to solve a meeting problem, but the browser can manipulate the clipboard so that a malicious command is executed instead.

JUMPSEC found that the Windows chain uses PowerShell to retrieve a VBScript-based implant. The malware can collect system information, search browsers for wallet extensions and look for Telegram Web-related files. The attackers also attempt to weaken Microsoft Defender protections as part of the infection process.

The macOS operation follows a different route. Victims are presented with fake Zoom or Teams software installers while a stealer operates in the background. Researchers found that the malware can collect system information and target Chrome master keys stored through Apple’s Keychain infrastructure.

The rapid development of the campaign is another warning sign. JUMPSEC identified four macOS malware variants between April 22 and July 15, while researchers identified five phishing-kit versions between May 31 and July 14.

Crypto malware targets executives where trust meets private keys

The scale and targeting of the operation underline why Crypto malware remains a major threat to cryptocurrency companies.

Arctic Wolf’s investigation found more than 80 typosquatted Zoom and Microsoft Teams domains associated with the campaign, registered between late 2025 and March 2026. Researchers also found that the majority of identified targets were connected to cryptocurrency or blockchain finance, while nearly half were founders or CEOs.

That targeting pattern is significant. Senior executives and founders may have access to company wallets, signing systems, sensitive communications or employees who control digital assets.

The campaign also demonstrates how one successful compromise can create another opportunity. A hijacked Telegram account can expose the victim’s network of industry contacts, allowing attackers to approach additional targets through an already trusted communication channel.

For crypto firms, the lesson is straightforward: a familiar face, a legitimate-looking calendar invitation or a routine video call is no longer enough to establish trust.

The emergence of AI-generated meeting participants makes visual verification harder, while wallet reconnaissance allows attackers to determine whether a target is potentially worth the effort before deploying the full Crypto malware payload.

BlueNoroff’s activity also reinforces the broader threat associated with the Lazarus Group ecosystem, which has repeatedly targeted cryptocurrency and financial institutions. JUMPSEC said the group’s financial motivation makes Web3 organizations particularly attractive because they concentrate valuable digital assets and frequently depend on employees to manage access to those assets.

For crypto executives, the safest response is to treat unexpected meeting links, browser-based software updates and copied commands with extreme suspicion. The Crypto malware threat is no longer simply about clicking a malicious attachment. In this campaign, the attack begins by learning who the victim is, what they may control and who they trust—before the malware ever arrives.

Tags: Blockchain Securitycrypto crimecrypto executivescrypto walletsCryptocurrency Newscryptocurrency securitycyber espionagecybersecuritydigital assetsfake Zoom scamLazarus groupnorth koreaphishing attacksocial engineeringweb3 security
Share197Tweet123
Elizabeth Omotoke

Elizabeth Omotoke

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Clarity act

Lummis ties Clarity Act’s fate to North Korea’s $6.75 billion crypto haul

07/27/2026
Coinbase prediction market

The agency that fined Wall Street for deleted texts just got caught doing the same thing

07/27/2026
Crypto malware

North Korean hackers scanned 100 crypto executives’ wallets through fake Zoom calls

07/27/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.