Crypto Firms Face Daily ‘Fake Zoom’ Attacks Linked To North Korea, Experts Say

bitcoinistОпубликовано 2025-12-16Обновлено 2025-12-16

North Korean-linked hackers are using fake Zoom calls to drain crypto wallets in what security researchers say has become a near-daily threat to the cryptocurrency community. According to multiple security reports, the campaign has already netted roughly $300 million in stolen funds and shows few signs of slowing.

Fake Zoom Meetings Used To Drain Wallets

According to Security Alliance (SEAL) and other researchers, attackers first contact targets through messaging apps such as Telegram. They then invite victims to a video call that looks legitimate.

During the call, the impostors claim there is a problem with sound or video and offer a “fix” — a file or a link that appears to be an official update. When the victim runs the file, malware installs and begins stealing credentials, browser data, and crypto keys.

Several attacks are reported every day, and many follow the same pattern. Researchers say these staged calls let attackers bypass normal caution because people tend to trust someone they see on camera.

NimDoor, Other Malware Strains Target macOS And Wallets

Based on reports, one strain tied to these schemes is NimDoor, a macOS backdoor that can harvest keychain items, browser-stored passwords, and messaging data.

Security teams link NimDoor and related tools to BlueNoroff, a group connected to the Lazarus Group network. BlueNoroff has a long record of attacking crypto firms and exchanges.

Once the malware is in place, wallets have been emptied within minutes. Victims often discover the theft only after seeing outgoing transactions on the blockchain.

Total crypto market cap currently at $2.93 trillion. Chart: TradingView

Deepfakes And Calendar Invites Make Scams More Convincing

Researchers warn that attackers are not simply using fake names. They are also deploying AI-assisted deepfake video and voice tools to impersonate executives or known contacts.

Attackers sometimes send calendar invites that look like genuine meeting requests from platforms such as Calendly, directing targets to attacker-controlled Zoom links.

The level of social engineering makes the calls seem urgent and official, which reduces the time victims take to question what they are being asked to install.

Attackers Target Individuals And Small Firms Alike

Reports have disclosed that victims include individual traders, startup employees, and small teams at crypto companies. Losses are concentrated but widespread, with estimates around $300,000,000.

Some victims have lost funds tied to browser wallets and hot wallets; others had recovery phrases captured and used to drain accounts.

Security teams urge quick action when a suspicious update is offered during a remote session: They warn not to run it, verify separately, and treat unsolicited meeting fixes as high risk.

Featured image from Unsplash, chart from TradingView

Похожее

600 People, $66 Billion: The First Major Cash-Out in the Era of Large Models

The first systematic "big cash-out" of the AI era occurred in October 2025, when over 600 current and former OpenAI employees sold a total of $6.6 billion in shares via a secondary market. Approximately 75 individuals maxed out a $30 million per-person sale limit, while around 525 others cashed out an average of $8.3 million each. This event, exceeding the scale of any 2024 US IPO, functioned as a "shadow IPO." It marked a radical departure from the traditional Silicon Valley path of waiting for a public listing, instead allowing employees to convert equity to cash after just two years of tenure—a direct retention tool in a fiercely competitive talent market where rivals like Meta have offered packages worth hundreds of millions. This massive liquidity event presents a dual-edged sword for OpenAI. While it helps retain talent, it also risks triggering a brain drain as newly wealthy employees may depart. Furthermore, it creates a dilemma for those who sold: they forfeited potential future gains as the company's valuation soared from $400 billion to $852 billion within months. In stark contrast, employees at rival Anthropic demonstrated greater reluctance to sell during their own secondary offering. The financial narratives of the two labs also diverge sharply. OpenAI, while achieving over $20 billion in annualized revenue by 2025, faces massive projected losses (up to $14 billion in 2026), a long path to cash flow positivity, and significant revenue-sharing payments to Microsoft. Anthropic reports rapid revenue growth, improving gross margins, and a faster path to profitability. OpenAI's trajectory is thus balanced precariously between skyrocketing valuation based on funding narratives and the pressures of sustained financial losses post-cash-out. The event underscores that the AI race has evolved into a capital and human experiment, where immense wealth crystallizes the complex calculations of greed, fear, and ambition within the industry.

marsbit4 мин. назад

600 People, $66 Billion: The First Major Cash-Out in the Era of Large Models

marsbit4 мин. назад

NVIDIA Begins Adding Soap to the Bubble

NVIDIA is taking on a dual role: not just as a leading chip supplier, but as a massive capital allocator across the entire AI supply chain. In 2026, the company has committed over $40 billion in investments within five months, targeting everything from optical fiber manufacturing and data center operations to foundational AI model development. This investment spree, described as a systematic "sprinkler" approach, primarily funds companies that are major buyers of NVIDIA's own GPUs. Critics, including analysts from Goldman Sachs, label this a "circular revenue" loop—comparable to a supplier financing a customer to buy more of its products. A prominent example is NVIDIA's investment in OpenAI, which is expected to generate around $13 billion in revenue for NVIDIA, much of which may be reinvested back into OpenAI. While CEO Jensen Huang dismisses the "circular financing" critique as "absurd," arguing the investments are confidence votes in long-term generational shifts, some analysts express discomfort. They note that while investments in critical supply chain components like optics are strategically sound, funding new cloud providers like CoreWeave feels like "pre-paying for your own GPUs." The strategy carries significant risks. If the AI investment cycle turns, the market may question how much demand is genuine versus artificially sustained by NVIDIA's own balance sheet. Despite posting record-breaking earnings—$215.9 billion in annual revenue and $120 billion in net profit for FY2026—NVIDIA's stock fell after its report, signaling that "beating expectations" may no longer be enough to assure investors about the duration of the AI spending boom. The article concludes that while a bubble isn't necessarily a fraud, NVIDIA's actions resemble adding soap to a bubble—making it appear more robust and durable. This creates a complex scenario requiring extreme冷静 from investors to distinguish between real structural growth and financial engineering.

marsbit21 мин. назад

NVIDIA Begins Adding Soap to the Bubble

marsbit21 мин. назад

Short Positions Have Been Squeezed Out: Will the Next Leg of the U.S. Stock AI Rally Continue in Seoul?

"Short Squeeze Exhausted: Will the Next Leg of the AI Rally Continue in Seoul?" A Nomura report suggests the US AI stock rally, which saw the S&P 500 rise ~16.6% in 28 days largely driven by 10 key stocks, may be pausing. The fuel from short covering, CTA fund positioning, and volatility-control strategies is nearing its limit. For the rally to continue, new momentum from retail and sentiment-driven FOMO (Fear Of Missing Out) is needed. South Korea's market provided a potential answer on the very day the report was published. The KOSPI index surged 4.32%, triggering a buy-side circuit breaker, led by massive gains in chip giants SK Hynix (+11.98%) and Samsung. This surge is characterized by retail "hynix FOMO" and overseas funds precisely buying into AI themes via chip-focused ETFs, shifting from broad Korean market ETFs. The Korean rally is a high-beta extension of the US AI capital expenditure story, as major cloud providers plan massive infrastructure spending, directly benefiting memory chip leaders. However, this linkage also implies vulnerability. The sustainability of this next leg depends on whether US tech stocks correct, the trajectory of US inflation (with upcoming CPI data key), and geopolitical tensions around the Strait of Hormuz. Seoul has emerged as the new epicenter of the AI trade, but its fate remains tied to these broader macro and market dynamics.

marsbit26 мин. назад

Short Positions Have Been Squeezed Out: Will the Next Leg of the U.S. Stock AI Rally Continue in Seoul?

marsbit26 мин. назад

Торговля

Спот
Фьючерсы
活动图片