North Korean Actors Use ‘Fake Zoom’ to Drain Crypto Wallets, $300M Stolen Already

Blockchain
“They've stolen over $300m via this method already,” MetaMask security researcher Taylor Monahan said.
Author
Last updated: 

North Korean cybercriminals are using ‘fake Zoom’ tactics to install malware, stealing victims’ sensitive data, including passwords and private keys. Cybersecurity firm Security Alliance (SEAL) warned that it has been tracking “multiple daily” such attempts.

The warning comes after MetaMask security researcher Taylor Monahan first outlined the sophisticated trap orchestrated by the DPRK threat actors.

“They’ve stolen over $300m via this method already,” Monahan wrote on X. “DPRK threat actors are still rekting way too many of you via their fake Zoom / fake Teams meets.”

Fake Zoom Modus Operandi – “They’re Taking Over Your Telegrams”

According to Monahan, the scam typically begins with a message from a Telegram account, appears to belong to someone the victim knows.

“They message everyone with prior conversation history,” he said.

The hacker, disguised as the “known person,” then guides the victim to a Zoom link via Calendly. Once the meeting starts, the victim sees a live video feed of their contact and other team members, which is a recorded video in reality, rather than deepfakes.

The hacker then complains about the lack of audio clarity, sending a “patch” file via chat and asking the victim to restore the clarity by updating a software development kit, or SDK. The file shared contains the malware payload.

The malware, often a Remote Access Trojan (RAT), if installed, will exfiltrate sensitive data, including internal security protocols, passwords, and drain crypto wallets completely.

North Korean Hackers’ Strategic Pivot in Social Engineering Campaigns

North Korean hackers, including the infamous Lazarus Group, have been previously linked to high-profile crypto thefts aimed at generating millions in revenue.

For instance, recently sophisticated North Korean hackers infiltrated crypto companies through elaborate job application schemes and fake interview processes.

Last month, the Lazarus Group orchestrated a major cryptocurrency breach that drained roughly $30.6 million from South Korea’s largest exchange, Upbit.

In the latest ‘fake Zoom’ call tactic, experts have warned users to immediately disconnect from WiFi and power off the device to halt malware activity.

The latest attack comes at a time when global crypto thefts have reached $2.17 billion in stolen assets by mid-2025.

In the Article
Bitcoin
BTC
$91,060
0.87 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,221,852,332,056
3.63
Trending Crypto

More Articles

Price Analysis
Solana Price Prediction: RWA Ecosystem Hits $873M in January 2026, Up 325% in One Year
2026-01-03 13:51:58
Bitcoin News
Santiment Warns FOMO Could Return if Bitcoin Hits $92K
Anas Hassan
Anas Hassan
2026-01-03 13:18:07
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors