# North Korea's BlueNoroff Uses Fake Zoom and Teams Calls to Drain Crypto Wallets in Under Five Minutes

The group has reached more than 100 victims across over 20 countries, scanning browsers for wallets before deciding who receives its malware.

- Published: 2026-07-27T05:22:39.277Z
- Canonical: https://polylog.news/crypto/2026-07-27/north-korea-s-bluenoroff-uses-fake-zoom-and-teams-calls-to-d
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Polylog editors](https://polylog.news), [The Hacker News](https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html), [crypto.news](https://crypto.news/north-korea-hackers-scan-crypto-wallets-through-fake-zoom-calls/)

Researchers have documented a campaign by BlueNoroff, a subgroup of the North Korea-linked Lazarus Group, that uses routine video calls to steal cryptocurrency. As French-language outlet Goku Crypto News [reported](https://t.me/GokuCryptoNews/20224), the group targets crypto professionals using compromised Telegram accounts to send invitations to fake Zoom and Microsoft Teams meetings.

The method is deliberate. BlueNoroff registers domains that closely resemble legitimate meeting platforms, a technique known as typosquatting, and has [created more than 80 such lookalike domains](https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html) since late 2025. Before delivering any malware, the group's phishing kit scans a victim's browser for installed wallets, then decides which targets are worth infecting. Reports indicate the attackers now use AI-generated avatars and deepfake composites to make the fake meetings more convincing, and released five versions of the kit between May 31 and July 14.

The operation has reached [more than 100 victims across over 20 countries](https://crypto.news/north-korea-hackers-scan-crypto-wallets-through-fake-zoom-calls/), with 41% of targets in the United States, and researchers say some victims are compromised in under five minutes. This attack does not exploit a smart-contract bug. It compromises the device and the private keys stored there, a separate attack surface from the on-chain exploits that dominate loss tallies.

The root cause is social engineering combined with endpoint compromise. Once private keys are harvested, no protocol audit protects the holder.

## What this means

Key-harvesting malware shifts the risk from protocols to individuals, meaning the exposed parties are employees and executives at exchanges, funds, and protocols whose personal devices hold access to organizational wallets. The channel is social trust in familiar tools like calendar invites and video calls, which no on-chain security control addresses. Two outcomes are plausible: firms tighten device and communication hygiene and the campaign's yield falls, or the deepfake tooling keeps improving faster than defenses and losses climb.

## What to watch

- Whether any exchange or fund publicly attributes a large theft to this specific BlueNoroff kit, which would confirm the scale of losses.
- Adoption of hardware wallets and dedicated signing devices among crypto professionals, a direct defense against key-harvesting malware.
