BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes
North Korean hackers BlueNoroff use fake Zoom and Teams meetings to steal crypto wallet credentials, hitting over 100 victims across 20 The post BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes appeared first on Crypto

BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes The North Korean hacking group has hit over 100 targets across 20 countries using typosquatted meeting domains and AI-generated avatars to steal wallet credentials Share Add us on Google by Editorial Team Jul. 25, 2026 A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials. BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call.
The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States. How the attack works BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025.
Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. Click the link, and you land on what looks like a normal Zoom or Teams interface. It is not.
The counterfeit meeting pages do two things simultaneously. They exfiltrate webcam footage while launching what’s called a ClickFix clipboard attack. In English: the fake site hijacks your clipboard to inject malicious commands, which then quietly harvest credentials from cryptocurrency wallet extensions like MetaMask.
Advertisement Full compromise has been observed in under five minutes in multiple instances. According to research from Arctic Wolf and JUMPSEC, roughly 80% of victims work in crypto or blockchain finance. Even more striking, 45% of those targeted are CEOs or founders.
An evolving operation with state-level sophistication This isn’t BlueNoroff’s first rodeo. The group gained notoriety as part of the Lazarus Group’s 2016 attempt to steal $81 million from Bangladesh Bank. Since then, they’ve pivoted heavily toward crypto, refining their methods with each campaign.
The current operation shows signs of active, rapid development. Five versions of their phishing kit were released between May 31 and July 14, 2026. Attack activity aligns primarily with North Korean business hours, reinforcing the state-sponsored nature of the operation.
Reports indicate BlueNoroff now uses AI-generated avatars and deepfake composites to make their fake meeting environments more convincing. Victim data collected from earlier attacks feeds into future targeting, creating a meticulous counting mechanism that makes each subsequent campaign more effective. What this means for crypto investors BlueNoroff isn’t exploiting smart contract vulnerabilities or attacking blockchains directly.
The central goal is harvesting wallet credentials and crypto data through social engineering, which means no amount of on-chain security auditing will protect you from this particular threat. For individual users, hardware wallets remain the strongest protection against credential theft, since private keys never touch an internet-connected device. Two-factor authentication adds another layer, though it’s not bulletproof against sophisticated phishing that captures session tokens in real time.
If someone sends you a meeting link through Telegram or an unexpected Calendly invite, verify it through a separate channel before clicking. Check the URL character by character. And if a video call asks you to install anything or grant clipboard permissions, close the tab immediately.
With five versions of the phishing kit deployed in just six weeks, and more than 80 typosquatted domains representing infrastructure that can be redeployed as old domains get flagged, this is not a campaign that’s winding down. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
MARKETS BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes The North Korean hacking group has hit over 100 targets across 20 countries using typosquatted meeting domains and AI-generated avatars to steal wallet credentials by Editorial Team Jul. 25, 2026 Share Add us on Google A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials. BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call.
The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States. How the attack works BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025.
Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitatio
Đọc thêm từ Tiền số / Crypto

5 Years After the Bitcoin Law, Crypto Accounts for Just 0.7% of El Salvador’s $5B Remittance Market
The Central Bank of El Salvador reported that cryptocurrency remittances failed to reach up to 1% of all volumes received during the first half of 2026. Only $35.4 million out of the over $5 billion received by Salvadorans was settled using digital currencies between January and

Iran and Oman continue talks on Strait of Hormuz security
Iran and Oman continue talks on Strait of Hormuz security. U.S.-Iran diplomatic meeting by August 31, 2026 at 43.5% YES. The post Iran and Oman continue talks on Strait of Hormuz security appeared first on Crypto Briefing.

BitMart shuts down trading as BMX crashes more than 60%
BitMart starts a phased shutdown, halts deposits and new orders, and will end all trading on August 26 as BMX drops about 63% in 24 hours.

Mitsubishi Motors partners with Tokyo startup to produce AI humanoid robots at scale
Mitsubishi Motors and University of Tokyo spinout Highlanders plan to produce 1,000 AI humanoid robots per month by early 2027 at Mitsubishi's The post Mitsubishi Motors partners with Tokyo startup to produce AI humanoid robots at scale appeared first on Crypto Briefing.