Polylog
The Polylog Crypto Intelligence Brief

Morning Edition · Monday, July 27, 2026Published at 1:22 AM EDT · New York

North Korea's BlueNoroff Uses Fake Zoom and Teams Calls to Drain Crypto Wallets in Under Five Minutes

The group has reached more than 100 victims across over 20 countries, scanning browsers for wallets before deciding who receives its malware.

North Korea's BlueNoroff Uses Fake Zoom and Teams Calls to Drain Crypto Wallets in Under Five Minutes

Researchers have documented a campaign by BlueNoroff, a subgroup of the North Korea-linked Lazarus Group, that uses routine video calls to steal cryptocurrency. As French-language outlet Goku Crypto News reported, the group targets crypto professionals using compromised Telegram accounts to send invitations to fake Zoom and Microsoft Teams meetings.

The method is deliberate. BlueNoroff registers domains that closely resemble legitimate meeting platforms, a technique known as typosquatting, and has created more than 80 such lookalike domains since late 2025. Before delivering any malware, the group's phishing kit scans a victim's browser for installed wallets, then decides which targets are worth infecting. Reports indicate the attackers now use AI-generated avatars and deepfake composites to make the fake meetings more convincing, and released five versions of the kit between May 31 and July 14.

The operation has reached more than 100 victims across over 20 countries, with 41% of targets in the United States, and researchers say some victims are compromised in under five minutes. This attack does not exploit a smart-contract bug. It compromises the device and the private keys stored there, a separate attack surface from the on-chain exploits that dominate loss tallies.

The root cause is social engineering combined with endpoint compromise. Once private keys are harvested, no protocol audit protects the holder.

Veracity: Corroborated
77/100
If true, who benefits

Cybersecurity vendors selling detection and response, and Western governments building the sanctions case against Pyongyang, gain from the North Korea attribution.

The nuance

The link to North Korea rests on researcher inference from reused tooling and infrastructure rather than confirmation, and Pyongyang denies running such operations.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

Key-harvesting malware shifts the risk from protocols to individuals, meaning the exposed parties are employees and executives at exchanges, funds, and protocols whose personal devices hold access to organizational wallets. The channel is social trust in familiar tools like calendar invites and video calls, which no on-chain security control addresses. Two outcomes are plausible: firms tighten device and communication hygiene and the campaign's yield falls, or the deepfake tooling keeps improving faster than defenses and losses climb.

What to watch

  • Whether any exchange or fund publicly attributes a large theft to this specific BlueNoroff kit, which would confirm the scale of losses.
  • Adoption of hardware wallets and dedicated signing devices among crypto professionals, a direct defense against key-harvesting malware.

Observations to monitor, not financial advice.

3 sources

Synthesized from: Polylog editors · The Hacker News · crypto.news

Part of a tracked trend

Endpoint Malware Targets Crypto Keys Beyond Smart-Contract Exploits

Beyond on-chain contract exploits, key-harvesting malware targets private keys at the device and supply-chain level, opening a distinct and growing attack surface for crypto holders.