A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials.
BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call. The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States.
How the attack works
BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025.
Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. Click the link, and you land on what looks like a normal Zoom or Teams interface. It is not.
The counterfeit meeting pages do two things simultaneously. They exfiltrate webcam footage while launching what’s called a ClickFix clipboard attack. In English: the fake site hijacks your clipboard to inject malicious commands, which then quietly harvest credentials from cryptocurrency wallet extensions like MetaMask.
Full compromise has been observed in under five minutes in multiple instances.
According to research from Arctic Wolf and JUMPSEC, roughly 80% of victims work in crypto or blockchain finance. Even more striking, 45% of those targeted are CEOs or founders.
An evolving operation with state-level sophistication
This isn’t BlueNoroff’s first rodeo. The group gained notoriety as part of the Lazarus Group’s 2016 attempt to steal $81 million from Bangladesh Bank. Since then, they’ve pivoted heavily toward crypto, refining their methods with each campaign.
The current operation shows signs of active, rapid development. Five versions of their phishing kit were released between May 31 and July 14, 2026. Attack activity aligns primarily with North Korean business hours, reinforcing the state-sponsored nature of the operation.
Reports indicate BlueNoroff now uses AI-generated avatars and deepfake composites to make their fake meeting environments more convincing. Victim data collected from earlier attacks feeds into future targeting, creating a meticulous counting mechanism that makes each subsequent campaign more effective.
What this means for crypto investors
BlueNoroff isn’t exploiting smart contract vulnerabilities or attacking blockchains directly. The central goal is harvesting wallet credentials and crypto data through social engineering, which means no amount of on-chain security auditing will protect you from this particular threat.
For individual users, hardware wallets remain the strongest protection against credential theft, since private keys never touch an internet-connected device. Two-factor authentication adds another layer, though it’s not bulletproof against sophisticated phishing that captures session tokens in real time.
If someone sends you a meeting link through Telegram or an unexpected Calendly invite, verify it through a separate channel before clicking. Check the URL character by character. And if a video call asks you to install anything or grant clipboard permissions, close the tab immediately.
With five versions of the phishing kit deployed in just six weeks, and more than 80 typosquatted domains representing infrastructure that can be redeployed as old domains get flagged, this is not a campaign that’s winding down.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
9







English (US) ·