BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes

2 hours ago 1



A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials. BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call. The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States. How the attack works BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025. Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. Click the link, and you land on what looks like a normal Zoom or Teams interface. It is not. The counterfeit meeting pages do two things simultaneously. They exfiltrate webcam footage while launching what’s called a ClickFix clipboard attack. In English: the fake site hijacks your clipboard to inject malicious commands, which then quietly harvest credentials from cryptocurrency wallet extensions like MetaMask. Full compromise has been obs...

Read Entire Article