Morning Edition · Monday, July 27, 2026Published at 1:22 AM EDT · New York
North Korea's BlueNoroff Uses Fake Zoom and Teams Calls to Drain Crypto Wallets in Under Five Minutes
The group has reached more than 100 victims across over 20 countries, scanning browsers for wallets before deciding who receives its malware.

Researchers have documented a campaign by BlueNoroff, a subgroup of the North Korea-linked Lazarus Group, that uses routine video calls to steal cryptocurrency. As French-language outlet Goku Crypto News reported, the group targets crypto professionals using compromised Telegram accounts to send invitations to fake Zoom and Microsoft Teams meetings.
The method is deliberate. BlueNoroff registers domains that closely resemble legitimate meeting platforms, a technique known as typosquatting, and has created more than 80 such lookalike domains since late 2025. Before delivering any malware, the group's phishing kit scans a victim's browser for installed wallets, then decides which targets are worth infecting. Reports indicate the attackers now use AI-generated avatars and deepfake composites to make the fake meetings more convincing, and released five versions of the kit between May 31 and July 14.
The operation has reached more than 100 victims across over 20 countries, with 41% of targets in the United States, and researchers say some victims are compromised in under five minutes. This attack does not exploit a smart-contract bug. It compromises the device and the private keys stored there, a separate attack surface from the on-chain exploits that dominate loss tallies.
The root cause is social engineering combined with endpoint compromise. Once private keys are harvested, no protocol audit protects the holder.
- If true, who benefits
Cybersecurity vendors selling detection and response, and Western governments building the sanctions case against Pyongyang, gain from the North Korea attribution.
- The nuance
The link to North Korea rests on researcher inference from reused tooling and infrastructure rather than confirmation, and Pyongyang denies running such operations.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Key-harvesting malware shifts the risk from protocols to individuals, meaning the exposed parties are employees and executives at exchanges, funds, and protocols whose personal devices hold access to organizational wallets. The channel is social trust in familiar tools like calendar invites and video calls, which no on-chain security control addresses. Two outcomes are plausible: firms tighten device and communication hygiene and the campaign's yield falls, or the deepfake tooling keeps improving faster than defenses and losses climb.
What to watch
- Whether any exchange or fund publicly attributes a large theft to this specific BlueNoroff kit, which would confirm the scale of losses.
- Adoption of hardware wallets and dedicated signing devices among crypto professionals, a direct defense against key-harvesting malware.
Observations to monitor, not financial advice.
Synthesized from: Polylog editors · The Hacker News · crypto.news
Part of a tracked trend
Endpoint Malware Targets Crypto Keys Beyond Smart-Contract Exploits
Beyond on-chain contract exploits, key-harvesting malware targets private keys at the device and supply-chain level, opening a distinct and growing attack surface for crypto holders.
More from this edition
- Aztec Turns On Its Alpha V5 Privacy Network on Ethereum, Cutting Private Transactions to Under $0.05
- DeFi Loses Tens of Millions in July as Oracle and Governance Attacks Recur Across Chains
- BitMart to Shut Down After Nine Years, and Its BMX Token Falls About 58%
- Cardano's Hoskinson Says Bitcoin Could Lose Its Lead If Governance Fails a Quantum Test
- Ethereum Researchers Study Proprietary AMMs That Now Handle a Third of Solana's On-Chain Trading
- Miden Pitches Confidential Execution as a Prerequisite, Not a Feature, in Blockchain's Next Phase
- South Korea's POSCO International Puts Live Invoices On-Chain in Tokenization Test With LG CNS
- MiCA and UK Compliance Costs Point Toward a New Wave of European Crypto Mergers
- A Lawsuit Claims Dormant Bitcoin as Lost Property, and Congress Moves to Close the Opening With CLARITY
- Two Public Companies Sold 511 Bitcoin in a Day to Escape $31.7 Million in Debt
- Bitcoin Trades Near $65,000 as United States and Iran Pause Strikes and Brent Crude Falls About 7%