
North Korean hackers BlueNoroff have hit over 100 crypto targets in 20 countries using typosquatted Zoom and Teams domains. Compromise takes under five minutes. Security researchers warn the campaign is accelerating.
Alpha Score of 75 reflects strong overall profile with strong momentum, strong value, strong quality, moderate sentiment.
A North Korean hacking group is using fake Zoom and Microsoft Teams meetings to steal wallet credentials from crypto professionals, security researchers said.
BlueNoroff, a subgroup of the Lazarus Group, has hit over 100 victims across more than 20 countries since late 2025. Forty-one percent of targets are in the United States, according to research from Arctic Wolf and JUMPSEC.
The group registers domains that look nearly identical to legitimate meeting platforms, a technique called typosquatting. More than 80 such domains have been created since late 2025. Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. Click the link and the page looks like a normal Zoom or Teams interface. It is not.
The counterfeit meeting pages do two things at once. They exfiltrate webcam footage while launching a ClickFix clipboard attack. The fake site hijacks the clipboard to inject malicious commands that harvest credentials from cryptocurrency wallet extensions like MetaMask. Multiple instances show full compromise in under five minutes, the researchers said.
Roughly 80% of victims work in crypto or blockchain finance. Forty-five percent are CEOs or founders.
BlueNoroff is part of the Lazarus Group, which attempted to steal $81 million from Bangladesh Bank in 2016. Since then the group has shifted focus to crypto, refining methods with each campaign. The current operation shows rapid development: five versions of their phishing kit were released between May 31 and July 14, 2026. Attack activity aligns with North Korean business hours, reinforcing the state-sponsored nature of the operation, researchers said.
BlueNoroff now uses AI-generated avatars and deepfake composites to make fake meeting environments more convincing. Victim data from earlier attacks feeds into future targeting, making each subsequent campaign more effective.
The group is not exploiting smart contract vulnerabilities or attacking blockchains directly. The goal is harvesting wallet credentials through social engineering. On-chain security audits do not protect against this threat.
For individual users, hardware wallets remain the strongest defense because private keys never touch an internet-connected device. Two-factor authentication adds protection, though sophisticated phishing can capture session tokens in real time.
Security researchers said the campaign shows no signs of slowing. Five versions of the phishing kit have been deployed in six weeks, and more than 80 typosquatted domains represent infrastructure that can be redeployed as old domains get flagged.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.