Crypto Firms Face Daily ‘Fake Zoom’ Attacks Linked To North Korea, Experts Say

bitcoinistPublished on 2025-12-16Last updated on 2025-12-16

North Korean-linked hackers are using fake Zoom calls to drain crypto wallets in what security researchers say has become a near-daily threat to the cryptocurrency community. According to multiple security reports, the campaign has already netted roughly $300 million in stolen funds and shows few signs of slowing.

Fake Zoom Meetings Used To Drain Wallets

According to Security Alliance (SEAL) and other researchers, attackers first contact targets through messaging apps such as Telegram. They then invite victims to a video call that looks legitimate.

During the call, the impostors claim there is a problem with sound or video and offer a “fix” — a file or a link that appears to be an official update. When the victim runs the file, malware installs and begins stealing credentials, browser data, and crypto keys.

Several attacks are reported every day, and many follow the same pattern. Researchers say these staged calls let attackers bypass normal caution because people tend to trust someone they see on camera.

NimDoor, Other Malware Strains Target macOS And Wallets

Based on reports, one strain tied to these schemes is NimDoor, a macOS backdoor that can harvest keychain items, browser-stored passwords, and messaging data.

Security teams link NimDoor and related tools to BlueNoroff, a group connected to the Lazarus Group network. BlueNoroff has a long record of attacking crypto firms and exchanges.

Once the malware is in place, wallets have been emptied within minutes. Victims often discover the theft only after seeing outgoing transactions on the blockchain.

Total crypto market cap currently at $2.93 trillion. Chart: TradingView

Deepfakes And Calendar Invites Make Scams More Convincing

Researchers warn that attackers are not simply using fake names. They are also deploying AI-assisted deepfake video and voice tools to impersonate executives or known contacts.

Attackers sometimes send calendar invites that look like genuine meeting requests from platforms such as Calendly, directing targets to attacker-controlled Zoom links.

The level of social engineering makes the calls seem urgent and official, which reduces the time victims take to question what they are being asked to install.

Attackers Target Individuals And Small Firms Alike

Reports have disclosed that victims include individual traders, startup employees, and small teams at crypto companies. Losses are concentrated but widespread, with estimates around $300,000,000.

Some victims have lost funds tied to browser wallets and hot wallets; others had recovery phrases captured and used to drain accounts.

Security teams urge quick action when a suspicious update is offered during a remote session: They warn not to run it, verify separately, and treat unsolicited meeting fixes as high risk.

Featured image from Unsplash, chart from TradingView

Related Reads

What Happens to Ethereum Developer Tools After the Grants Run Out?

On February 27th, the Ethereum Foundation (EF) announced Project Odin, a structured sustainability support program designed for a select group of strategic, previously grant-funded teams. Unlike a standard grant, Odin offers a long-term advisory mechanism focused on helping these teams establish credible, sustainable paths within a two-year framework, thereby reducing long-term dependence on single funding sources. The program addresses a critical post-grant challenge: how essential public goods, especially major developer tools, can achieve financial sustainability beyond initial funding. While grants from EF and programs like Gitcoin or RetroPGF remain vital for startups and research, they often fall short for mature, widely-used infrastructure. Tools like compilers, languages, and network stacks are deeply embedded but struggle with monetization, trapped between being too foundational to lose and too public to generate natural revenue. Project Odin provides teams with a dedicated Strategic Advisor to guide them through a three-phase process: 1) analyzing current funding and realistic options, 2) validating potential paths with stakeholders, and 3) executing plans, which may include crafting support contracts, service agreements, or other recurring revenue models. The first pilot participant is Vyper, a critical smart contract language for the EVM, highlighting the need for sustainable models for core infrastructure. The initiative reframes the public goods conversation from "who should be funded" to "how do already-proven teams avoid perpetual funding crises?" It encourages ecosystem participants—protocols and projects that depend on these tools—to view sustainable support not just as charity, but as essential risk management for their own operational supply chains.

marsbit21m ago

What Happens to Ethereum Developer Tools After the Grants Run Out?

marsbit21m ago

MARA Reports Q1 Revenue Below Expectations, Net Loss of $1.3 Billion, Stock Plunges After Hours

Bitcoin mining firm MARA Holdings reported disappointing Q1 2024 results, causing its stock to erase all daily gains and fall 3.44% in after-hours trading. Revenue dropped 18% year-over-year to $174.6 million, missing Wall Street estimates of $192.7 million. The company posted a net loss of $1.3 billion, a significant increase from a $533.4 million loss a year ago, primarily driven by unrealized losses on its holdings of 38,689 Bitcoin, which depreciated in value during the quarter. MARA also sold over 15,100 BTC in late March to repurchase debt at a discount. The broader mining environment remains challenging due to a 35% decline in Bitcoin's price from its all-time high and a nearly 30% increase in mining difficulty over the past year. MARA's market cap ranking among U.S. miners has slipped to seventh. Critically, the company announced a strategic pivot away from Bitcoin mining expansion. It stated it has no plans to purchase new mining equipment and is fully transitioning toward AI data centers. Its strategy involves retrofitting existing mining sites for AI and high-performance computing (HPC) and leveraging its recent $1.5 billion acquisition of Long Ridge Energy & Power, a gas-fired power plant and data center. This infrastructure could eventually support 600 MW of AI compute capacity, allowing MARA to redeploy up to 90% of its non-custodial mining power for AI and IT workloads.

marsbit22m ago

MARA Reports Q1 Revenue Below Expectations, Net Loss of $1.3 Billion, Stock Plunges After Hours

marsbit22m ago

The AI Investment Landscape Is Being Reshaped: Beyond the 'Magnificent Seven', What Opportunities Lie in the Semiconductor Supply Chain?

AI Investment Map is Reshaping: Opportunities Beyond the 'Magnificent Seven' Since ChatGPT ignited the AI wave, investment initially focused on the "Magnificent Seven" tech giants dominating cloud infrastructure. However, the rise of DeepSeek and debates on AI capital expenditure effectiveness are shifting this dynamic. Investors now recognize opportunities deeper in the supply chain—the companies providing the essential "picks and shovels." Early concerns about an AI investment "arms race" and potential low returns were partly alleviated by strong Q1 earnings from cloud providers, validating robust compute demand. This has highlighted a more certain investment thesis: regardless of which AI applications ultimately win, massive capital expenditure will first fuel demand for semiconductors and related components. This "pick-and-shovel" logic has driven semiconductor ETFs to record highs. Key beneficiaries include: * **Memory Chipmakers (e.g., SK Hynix, Samsung, Micron)**: High Bandwidth Memory (HBM) is a critical bottleneck for AI training. * **Photonics Companies**: Crucial for high-speed data transfer within AI data centers. * **The Broader "AI-11" Semiconductor Ecosystem**: This encompasses foundries & lithography (TSMC, ASML), logic & custom chips (AMD, Broadcom, Intel, Marvell), and enterprise storage (SanDisk, Western Digital). Every dollar of AI infrastructure spending flows through this chain. While the "Magnificent Seven" remain dominant in market size, their earnings growth premium over the rest of the S&P 500 ("S&P 493") is narrowing. Market attention and marginal investment are shifting towards the expanding semiconductor supply chain. The investment narrative is evolving from "betting on the ultimate AI winner" to "investing in the certainty of the infrastructure build-out." Understanding this shift from the demand side to the supply side is key to identifying future AI investment opportunities.

marsbit51m ago

The AI Investment Landscape Is Being Reshaped: Beyond the 'Magnificent Seven', What Opportunities Lie in the Semiconductor Supply Chain?

marsbit51m ago

Trading

Spot
Futures
活动图片