News

North Korean Hackers Are Booking Fake Zoom Calls to Drain Crypto Wallets

North Korean hackers using fake Zoom meetings to target crypto wallets, shown as a hooded figure amid fraudulent call windows

Security firm JUMPSEC has detailed a phishing operation it links to BlueNoroff, a North Korean threat group, that goes after people in the crypto industry through fake Zoom and Microsoft Teams meetings.

The reason it works has nothing to do with clever code. The invite arrives from someone the target already knows.

It starts with a stolen Telegram account

BlueNoroff takes over Telegram accounts belonging to real people working in crypto, then messages their contacts. According to JUMPSEC’s analysis of the phishing kit, the operators go after senior staff at well known companies, and the pitch is a simple Calendly link for a call.

The message lands inside a conversation the target recognises. Prior chat history is right there. The sender is a founder they met at a conference, or a fund contact a friend introduced them to. Nothing about it reads as cold outreach, which is exactly what makes it work. The same trust shortcut drives everything from the Coinbase text scam to fake support calls.

The Calendly booking then points to what looks like a Zoom meeting URL. The domain is fake, built to imitate the video service. Anyone who lands on it is asked to type a name and allow webcam access, which makes the page feel like the real thing. Researchers at Arctic Wolf counted more than 80 lookalike Zoom and Teams domains registered since late 2025.

The page reads your wallets before any malware shows up

This is the part that separates the campaign from ordinary phishing. While the victim sits in the fake waiting room, the page starts scanning the browser.

It looks for Ethereum wallet connections using the EIP-6963 standard and older detection methods, and checks for non-EVM wallets including Solana tools. On Windows it also pulls extension IDs from Chrome, Edge, Brave, Opera, Vivaldi and Firefox builds, then matches them against known wallet extensions such as MetaMask.

The results go straight to an operator dashboard. The victim sees nothing. By the time anyone decides whether to push malware, the attackers already know whose wallets are worth the effort.

Then comes the “SDK update”

The next step is a familiar excuse. The audio is not working, and the meeting client needs a quick fix. The victim is told to run an SDK update, a ClickFix style trick that ends with the target executing the command themselves.

Sean Moran, head of threat research at JUMPSEC, told The Hacker News the outdated SDK story only holds up on platforms people expect to have a heavyweight desktop client, which is why Zoom and Teams were picked.

On Windows the pasted command runs a PowerShell loader that pulls down a VBScript, adds a Microsoft Defender exclusion and restarts Defender so the exclusion takes hold. The implant then collects system details, checks browsers for wallet extensions and hunts for Telegram Web files.

On macOS the victim gets a fake Zoom or Teams installer while a stealer runs quietly behind it. Researchers found versions lifting system information and Chrome master keys out of the Apple Keychain, with data shipped out through a Telegram bot. JUMPSEC tracked four macOS variants between 22 April and 15 July, so the toolkit was being rebuilt throughout the campaign. It follows a long run of fake Zoom updates aimed at macOS users in the same industry.

Every victim becomes the next lure

Stolen Telegram sessions are the point. Anyone who runs the payload with Telegram Web open or Telegram Desktop installed can have their session taken and reused against their own contact list, which hands the operators a fresh batch of trusted accounts.

JUMPSEC describes it as a repeatable victim pipeline. One compromise pays for the next.

This is not a one off

Mandiant documented a near identical attack on a crypto executive earlier this month, down to the Telegram introduction and the Calendly link. The tooling changes, the entry point does not.

It also fits the wider shift we have tracked across the underground: attackers buying speed instead of skill. Criminal language models such as the ones covered in our breakdown of dark web LLMs like FraudGPT and WormGPT write the lure copy, and the VoidLink malware built largely by an AI agent showed how far the build side has moved. Our dark web statistics for 2026 put the growth in credential and wallet theft in context.

What to do about it

Treat a Calendly or meeting link from a Telegram contact as unverified, even when the account is real and the history is real. Confirm the call on a second channel before clicking. Check the domain in the address bar against zoom.us or teams.microsoft.com before typing anything into it.

No legitimate video call will ever ask you to paste a command into a terminal or run an SDK patch to fix your microphone. That request is the attack.

If you think you ran something, assume the wallet and the Telegram session are both gone. Move funds from any hot wallet on that machine, kill active Telegram sessions from another device, and warn your contacts before the next invite goes out in your name. A dark web monitoring service will not stop the initial theft, but it will tell you when the credentials pulled off your machine start circulating.

More incidents like this are tracked in our breach and threat news feed.

Written by hanna

I'm Hanna, a security consultant based in Berlin with more than twelve years of experience across offensive and defensive security. I started out on a blue team chasing alerts at 3 a.m., moved into red teaming because I wanted to understand the other side of the console, and now run an independent practice advising companies on threat intelligence, penetration testing, incident response planning, and security architecture.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted