Crypto Firms Face Daily ‘Fake Zoom’ Attacks Linked To North Korea, Experts Say

bitcoinistPublicado em 2025-12-16Última atualização em 2025-12-16

North Korean-linked hackers are using fake Zoom calls to drain crypto wallets in what security researchers say has become a near-daily threat to the cryptocurrency community. According to multiple security reports, the campaign has already netted roughly $300 million in stolen funds and shows few signs of slowing.

Fake Zoom Meetings Used To Drain Wallets

According to Security Alliance (SEAL) and other researchers, attackers first contact targets through messaging apps such as Telegram. They then invite victims to a video call that looks legitimate.

During the call, the impostors claim there is a problem with sound or video and offer a “fix” — a file or a link that appears to be an official update. When the victim runs the file, malware installs and begins stealing credentials, browser data, and crypto keys.

Several attacks are reported every day, and many follow the same pattern. Researchers say these staged calls let attackers bypass normal caution because people tend to trust someone they see on camera.

NimDoor, Other Malware Strains Target macOS And Wallets

Based on reports, one strain tied to these schemes is NimDoor, a macOS backdoor that can harvest keychain items, browser-stored passwords, and messaging data.

Security teams link NimDoor and related tools to BlueNoroff, a group connected to the Lazarus Group network. BlueNoroff has a long record of attacking crypto firms and exchanges.

Once the malware is in place, wallets have been emptied within minutes. Victims often discover the theft only after seeing outgoing transactions on the blockchain.

Total crypto market cap currently at $2.93 trillion. Chart: TradingView

Deepfakes And Calendar Invites Make Scams More Convincing

Researchers warn that attackers are not simply using fake names. They are also deploying AI-assisted deepfake video and voice tools to impersonate executives or known contacts.

Attackers sometimes send calendar invites that look like genuine meeting requests from platforms such as Calendly, directing targets to attacker-controlled Zoom links.

The level of social engineering makes the calls seem urgent and official, which reduces the time victims take to question what they are being asked to install.

Attackers Target Individuals And Small Firms Alike

Reports have disclosed that victims include individual traders, startup employees, and small teams at crypto companies. Losses are concentrated but widespread, with estimates around $300,000,000.

Some victims have lost funds tied to browser wallets and hot wallets; others had recovery phrases captured and used to drain accounts.

Security teams urge quick action when a suspicious update is offered during a remote session: They warn not to run it, verify separately, and treat unsolicited meeting fixes as high risk.

Featured image from Unsplash, chart from TradingView

Leituras Relacionadas

Xiaohongshu's Second Great Voyage, This Time Sailing Towards AI

Xiaohongshu's Second Voyage: Navigating Towards AI Since ChatGPT's emergence, Xiaohongshu's founder Mao Wenchao has been acutely aware of AI's potential threat, recognizing that the life advice people seek from chatbots overlaps directly with his platform's core business. Founded in 2013 as a PDF shopping guide for Chinese tourists, Xiaohongshu evolved into a massive community where millions share authentic, personal experiences—from product reviews to travel tips. This vast repository of "I've tried this" human judgment became its most valuable asset. However, the rise of AI, which delivers instant answers, challenges the very need for users to sift through numerous personal notes. Fearing its treasure trove of lived experience could become mere training data for others, Xiaohongshu is proactively adapting. In 2026, it established a dedicated AI division (Dots), launched RED Skill to turn user experiences into usable AI tools, and acquired the AI search product "Diandian." Its investments now extend to AI firms like MiniMax and hardware startups, moving upstream to address needs before they even become search queries. The platform's commercialization strategy is also evolving. With a newly acquired payment license and tools like the AIPS model to track consumer decision journeys, Xiaohongshu aims to seamlessly integrate recommendations with transactions, embedding commerce within AI-generated answers. Yet, a critical tension remains. While building smarter machines to organize and leverage its human experiences, Xiaohongshu must prevent AI from drowning out the authentic, flawed, and trustworthy "I've tried this" voices that built its community. Its core challenge is to harness AI's power without letting the map—the machine's perfect, synthesized answer—replace the territory of genuine human experience. This balance between technological advancement and preserving human trust defines its current journey and its future.

marsbitHá 6m

Xiaohongshu's Second Great Voyage, This Time Sailing Towards AI

marsbitHá 6m

SharpLink CEO: How to Understand Ethereum Developers Just Exceeded 1 Million?

SharpLink CEO reflects on the milestone of Ethereum surpassing 1 million historical developers, emphasizing that this figure represents the largest pool of technical talent ever assembled around an open, permissionless blockchain network. While approximately 232,000 developers remain active, the key question for the crypto industry is not which chain is fastest, but where the best builders choose to build long-term. Ethereum's advantage lies in a decade-long accumulation of infrastructure, standards, tools, liquidity, and a cohesive culture, making it the default operating system for programmable finance. This developer base is tackling complex challenges: the Glamsterdam upgrade aims to enhance scalability while preserving core principles; synchronous composability seeks to unify Rollup ecosystems; and significant efforts are underway for post-quantum security. Ethereum's deeper network effects stem from composability and shared standards (like the EVM and Solidity), creating a flywheel of more developers, tools, and liquidity. Three reinforcing strengths cement Ethereum's lead: credible neutrality (secured by ~900k validators), a modular architecture with interconnected Rollups, and a culture that attracts top researchers. The ecosystem is consolidating as the trusted coordination layer for internet-native finance, favored by large institutions valuing security and liquidity. The future of Ethereum is being built by this global community of founders and architects.

链捕手Há 21m

SharpLink CEO: How to Understand Ethereum Developers Just Exceeded 1 Million?

链捕手Há 21m

A Clod of Chinese Soil Chokes Two Japanese Giants

"Chinese Soil Chokes Japanese Giants" The production of a key electronic specialty gas, tungsten hexafluoride (WF6), vital for manufacturing AI chips, was halted by two leading Japanese producers—Kanto Denka and Central Glass. Their shutdown was not due to a technological failure but a sudden, critical shortage of a raw material they had long taken for granted: ultra-high-purity (6N-grade) tungsten powder, which is almost entirely sourced from China. Following a quiet Chinese export announcement in January 2026, tungsten powder shipments to Japan dropped to zero for months. Despite frantic efforts, Japanese companies found no viable alternative; imported powder was three times more expensive and lacked the required purity. Their existing stockpiles were exhausted by mid-2026. WF6 is essential for depositing tungsten into the microscopic contact holes of High Bandwidth Memory (HBM) chips, which are crucial for advanced processors like those from Nvidia. While Japanese firms had mastered producing ultra-pure WF6 gas, their entire supply chain relied on China's 6N tungsten powder—a dependency now revealed as a fatal vulnerability. China's dominance in this "soil" results from decades of painstaking R&D by companies like Xiamen Tungsten and China Tungsten & Hightech. They overcame immense technical hurdles, such as separating chemically similar molybdenum from tungsten, to achieve mass production of the world's purest tungsten powder. With their primary suppliers gone, Kanto Denka and Central Glass announced a permanent halt to WF6 production starting July 1, 2026. This immediately created a supply crisis for major semiconductor manufacturers like Samsung and SK Hynix, forcing them to urgently seek and certify new Chinese suppliers for WF6 itself. The reversal marks a dramatic shift: China has moved from exporting low-value raw materials to controlling the high-purity foundation of a critical global tech supply chain, upending a long-established industrial hierarchy.

marsbitHá 52m

A Clod of Chinese Soil Chokes Two Japanese Giants

marsbitHá 52m

Trading

Spot
Futuros
活动图片