BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes
North Korean hackers BlueNoroff use fake Zoom and Teams meetings to steal crypto wallet credentials, hitting over 100 victims across 20 The post BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes appeared first on Crypto

BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes The North Korean hacking group has hit over 100 targets across 20 countries using typosquatted meeting domains and AI-generated avatars to steal wallet credentials Share Add us on Google by Editorial Team Jul. 25, 2026 A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials. BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call.
The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States. How the attack works BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025.
Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. Click the link, and you land on what looks like a normal Zoom or Teams interface. It is not.
The counterfeit meeting pages do two things simultaneously. They exfiltrate webcam footage while launching what’s called a ClickFix clipboard attack. In English: the fake site hijacks your clipboard to inject malicious commands, which then quietly harvest credentials from cryptocurrency wallet extensions like MetaMask.
Advertisement Full compromise has been observed in under five minutes in multiple instances. According to research from Arctic Wolf and JUMPSEC, roughly 80% of victims work in crypto or blockchain finance. Even more striking, 45% of those targeted are CEOs or founders.
An evolving operation with state-level sophistication This isn’t BlueNoroff’s first rodeo. The group gained notoriety as part of the Lazarus Group’s 2016 attempt to steal $81 million from Bangladesh Bank. Since then, they’ve pivoted heavily toward crypto, refining their methods with each campaign.
The current operation shows signs of active, rapid development. Five versions of their phishing kit were released between May 31 and July 14, 2026. Attack activity aligns primarily with North Korean business hours, reinforcing the state-sponsored nature of the operation.
Reports indicate BlueNoroff now uses AI-generated avatars and deepfake composites to make their fake meeting environments more convincing. Victim data collected from earlier attacks feeds into future targeting, creating a meticulous counting mechanism that makes each subsequent campaign more effective. What this means for crypto investors BlueNoroff isn’t exploiting smart contract vulnerabilities or attacking blockchains directly.
The central goal is harvesting wallet credentials and crypto data through social engineering, which means no amount of on-chain security auditing will protect you from this particular threat. For individual users, hardware wallets remain the strongest protection against credential theft, since private keys never touch an internet-connected device. Two-factor authentication adds another layer, though it’s not bulletproof against sophisticated phishing that captures session tokens in real time.
If someone sends you a meeting link through Telegram or an unexpected Calendly invite, verify it through a separate channel before clicking. Check the URL character by character. And if a video call asks you to install anything or grant clipboard permissions, close the tab immediately.
With five versions of the phishing kit deployed in just six weeks, and more than 80 typosquatted domains representing infrastructure that can be redeployed as old domains get flagged, this is not a campaign that’s winding down. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
MARKETS BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes The North Korean hacking group has hit over 100 targets across 20 countries using typosquatted meeting domains and AI-generated avatars to steal wallet credentials by Editorial Team Jul. 25, 2026 Share Add us on Google A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials. BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call.
The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States. How the attack works BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025.
Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitatio
Đọc thêm từ Tiền số / Crypto
Is Ethereum price nearing a bottom? THREE signals point to a shift
If the short-term uptick in onchain activity is sustained, while leverage is under control, a price uptick driven by organic demand could be viable.

Hydropower overtakes gas as Bitcoin mining power use jumps 38%
Cambridge data shows Bitcoin mining power use rose 38% to 190 TWh as hydropower led the mix and low-carbon energy reached 59.4% in late 2025

Binance runs monthly phishing tests on employees, warns of dismissal for repeat failures
Binance's red team runs monthly phishing simulations on employees, with repeated failures leading to dismissal as social engineering drives 65% The post Binance runs monthly phishing tests on employees, warns of dismissal for repeat failures appeared first on Crypto Briefing.

Cash App removes all fees on large Bitcoin purchases and recurring buys
Cash App eliminates all fees and spreads on Bitcoin purchases over $2,000 and recurring buys, positioning itself as the cheapest option in the US The post Cash App removes all fees on large Bitcoin purchases and recurring buys appeared first on Crypto Briefing.