Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»Fake Zoom malware scam linked to North Korean hackers targets cryptocurrency users
HACKING NEWS

Fake Zoom malware scam linked to North Korean hackers targets cryptocurrency users

By Crypto FlexsDecember 18, 20253 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Fake Zoom malware scam linked to North Korean hackers targets cryptocurrency users
Share
Facebook Twitter LinkedIn Pinterest Email

  • The scam uses Telegram impersonation and pre-recorded video calls to build trust.
  • Malware is delivered as fake audio or SDK patches during meetings.
  • The Security Alliance says it tracks such attempts several times daily.

Cybercriminals in North Korea are expanding their social engineering attacks by exploiting fake Zoom and Teams meetings to distribute malware that leaks sensitive data and cryptocurrency wallets.

Cybersecurity firm Security Alliance, also known as SEAL, warned that it is tracking several daily attempts related to such campaigns.

This activity highlights the shift from crude phishing to more persuasive real-time fraud.

The warning comes after it was revealed by MetaMask security researcher Taylor Monahan, who has been closely monitoring the pattern and has already indicated the scale of losses associated with the tactic.

This method is especially effective for cryptocurrency and technology professionals who regularly use video conferencing tools, as it relies on familiarity, trust, and workplace habits.

How Fake Zoom Scams Work

Attacks typically begin on Telegram, where victims receive messages from an account that appears to belong to someone they already know. Attackers specifically target contacts with existing chat history to increase trust and reduce suspicion.

Once engagement begins, victims are directed to schedule a meeting via a Calendly link that looks like a legitimate Zoom call.

When a meeting opens, victims see what appears to be a live video feed of their contacts and other team members.

In fact, the video is not an AI-generated deepfake, but a pre-recorded video.

During the call, the attacker claims there is an audio problem and offers to install a quick fix.

Files are shared in chat and delivered as patches or software development kit updates to restore sound clarity.

The file contains a malware payload. Once installed, attackers can remotely access the victim’s device.

Impact of malware on cryptocurrency wallets

Malicious software is often a remote access Trojan. After installation, it automatically extracts sensitive information such as passwords, internal security documents, and private keys.

In a cryptocurrency-centric environment, wallets can be completely depleted with little to no immediate signs of compromise.

Monahan warned that more than $300 million has already been stolen using a variation of this approach against X, and that the same threat actors continue to exploit fake Zoom and Teams meetings to compromise users.

SEAL expressed concern, noting the frequency and consistency of these attempts across the cryptocurrency sector.

North Korea’s evolving cyber playbook

North Korean hacking groups have long been associated with financially motivated cybercrime that funds support for the North Korean regime.

Groups like Lazarus have previously targeted exchanges and blockchain companies through direct attacks and supply chain attacks.

Recently, these actors have relied heavily on social engineering.

In recent months, they have infiltrated cryptocurrency companies using fake job applications and a staged interview process designed to deliver malware.

Last month, Lazarus suffered a loss of approximately $30.6 million in connection with a breach at Upbit, Korea’s largest exchange.

Fake Zoom tactics reflect a broader strategic pivot toward human-centric attack vectors that bypass technological safeguards.

What experts say you should do

Security experts warn that speed is important when running malicious files.

If infection is suspected during a call, users are advised to immediately disconnect from WiFi and power off the device to stop data leakage.

The broader warning is to handle unexpected meeting links, software patches, and urgent technical requests with extreme caution, even if they appear to come from known contacts.


Share this article

Category

tag

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Everyday Guides Book Series — Rethink Your Strategy

July 20, 2026

KuCoin unveils Celestia Stage as Tomorrowland Belgium 2026 partnership expands

July 18, 2026

Videos and Podcasts | Vault 12

July 14, 2026
Add A Comment

Comments are closed.

Recent Posts

NOWPayments Releases Cross-Chain Payout Data Revealing Key Performance Benchmarks Across TRON, BNB Chain, and Solana

September 21, 2026

Bitmine Immersion Technologies (BMNR) Announces ETH Holdings Reach 5.98 Million Tokens, and Total Crypto and Total Cash Holdings of $17.1 Billion

September 21, 2026

Zoomex to Host Traders After Party During TOKEN2049 Singapore, Connecting Traders and the Web3 Community

September 21, 2026

Multi-Asset Trading Venue Monochrome Exchange Announces IEO of Its Native Token, $MCR

September 20, 2026

SwapToZEC.com Details How to Swap Crypto to Zcash (ZEC) or Exchange One Cryptocurrency for Another

September 18, 2026

AML RightSource Recognized with CobraSight Award for Digital Asset Compliance Expertise

September 17, 2026

1win Adds Provably Fair Technology to Its Crypto Games

September 17, 2026

Tria Deepens Korea Push as Diamond Sponsor of Korea Blockchain Week 2026

September 16, 2026

MEXC Launches $1M “Discover Your Wall Street DNA” Campaign to Help Traders Find Their Market Fit

September 16, 2026

38.66M USDT in Risk Funds Intercepted, Futures Insurance Fund Hits 792M USDT

September 16, 2026

BASIS.pro Expands On-Chain Infrastructure with XDC Network Partnership and Zypher DAO as Auto Earn Goes Live

September 16, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

NOWPayments Releases Cross-Chain Payout Data Revealing Key Performance Benchmarks Across TRON, BNB Chain, and Solana

September 21, 2026

Bitmine Immersion Technologies (BMNR) Announces ETH Holdings Reach 5.98 Million Tokens, and Total Crypto and Total Cash Holdings of $17.1 Billion

September 21, 2026

Zoomex to Host Traders After Party During TOKEN2049 Singapore, Connecting Traders and the Web3 Community

September 21, 2026
Most Popular

MANTRA co -founder says that forced liquidation has caused 90% conflicts of OM tokens.

April 14, 2025

Bitcoin’s repeated declines and spot ETF outflows have increased the odds of BTC below $60,000.

October 23, 2024

A great platform for online trading

December 6, 2023
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.