Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    MicroStrategy Stock Mirrors Bitcoin's Wildest Swings 7 Times BTC Moved MSTR
    MicroStrategy Stock Mirrors Bitcoin’s Wildest Swings: 7 Times BTC Moved MSTR
    Beyond Bitcoin Treasuries How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    Beyond Bitcoin Treasuries: How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    Exclusive Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Exclusive: Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Crypto PACs Reshape US Elections: Trump's Pro-Crypto Agenda Takes Shape
    Crypto PACs Reshape US Elections: Trump’s Pro-Crypto Agenda Takes Shape
  • Opinion
    OpinionShow More
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

North Korean Hackers Exploit Fake Zoom to Steal Crypto

Cybersecurity experts’ findings show how the hackers use hijacked Telegram accounts and fake video call updates to compromise devices and steal crypto.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: December 15, 2025 3:11 PM
Published 2025-12-15
Share
Last updated: December 15, 2025 3:11 PM
Published 2025-12-15
North Korean Hackers Exploit Fake Zoom to Steal Crypto

Key Highlights

  • North Korean hackers use fake Zoom/Teams meetings and hijacked Telegram accounts to steal crypto and sensitive data from trusted contacts.
  • Victims often unknowingly run malicious updates, exposing wallets, passwords, and company secrets across Mac, Windows, and Linux systems.
  • Immediate action is critical: disconnect devices, secure accounts, and alert contacts to prevent further losses and malware spread.

North Korean hackers have increased their attacks and attack bases by creating fake Zoom and Teams meetings to steal cryptocurrencies and sensitive information. According to the cybersecurity company Security Alliance, these attacks take advantage of social engineering, a hacking technique that depends on the confidence level in professional networks.

The hackers start by hijacking a victim’s Telegram account, messaging known contacts, and sending a disguised link to schedule a call. Once victims interact, the attackers push malicious updates disguised as Zoom fixes, compromising computers across Mac, Windows, and Linux systems.

SEAL is tracking multiple DAILY attempts by North Korean actors utilizing “Fake Zoom” tactics for spreading malware as well as escalating their access to new victims.

Social engineering is at the root of the attack. Read the thread below for pointers on how to stay secure. https://t.co/2SQGdtPKGx

— Security Alliance (@_SEAL_Org) December 13, 2025

The firm shared cybersecurity expert Tay’s warning, which stated, “It all starts with the Telegram account of someone you know. They message everyone with prior conversation history. People you met at a conference. Or were introduced by a close friend. VCs. BDs. YOU CAN SEE THE CONVERSATION HISTORY. YOU KNOW THIS PERSON!” This approach tricks people by using familiar contacts, making them more likely to click on malicious links.

How the scam unfolds

The attack process is elaborate. Once a victim clicks the link, hackers request an “update” such as “Zoom Update SDK.scpt,” which secretly runs malware via AppleScript. Tay explained, “The malware EXFILTRATES EVERYTHING across Mac, Windows, and Linux. – All your wallets – Everything in password managers, Apple Notes, etc. – Your Telegram history + session auth tokens – Passwords, seed phrases, SSH keys, AWS creds.” Consequently, victims lose access to both personal and corporate assets, and their Telegram account becomes a tool to target others.

Attackers even simulate legitimate Zoom errors and provide screenshots, convincing victims to follow instructions. Tay added, “They are very very helpful. If you express skepticism, they quickly alleviate your concerns. Really smart people fall for this.” Victims often remain unaware that their systems have already been compromised.

Recent crypto heists signal escalation

This method aligns with North Korea’s recent cryptocurrency thefts. On November 27, South Korea’s largest crypto exchange, Upbit, suffered a $32 million hack. Yonhap News reported authorities suspect the Lazarus Group, linked to North Korea’s Reconnaissance General Bureau, orchestrated the attack. 

The breach targeted hot wallets storing Solana-based tokens like SOL and USDC. Upbit halted withdrawals, transferred funds to cold wallets, and launched a full investigation. A government source noted, “Rather than attacking the server, it is possible that the administrator account was hijacked or that the funds were transferred by pretending to be the administrator.”

Similarly, in August, Lazarus Group allegedly stole £17 million from the UK-based crypto exchange Lykke. The attack forced the company to shut down operations despite promising reimbursements. Authorities cited Bitcoin and Ethereum networks as channels used to launder stolen funds, highlighting the sophisticated nature of North Korean cyber campaigns.

Protecting yourself and your assets

Tay emphasized immediate action for affected users, “DISCONNECT WIFI – TURN COMPUTER OFF – DO NOT USE COMPUTER. ONLY USE PHONE/IPAD. Move funds to secure wallets or exchanges. Wipe the computer completely before using it again.” 

Additionally, users have been urged to secure Telegram accounts by terminating all other sessions and updating passwords and MFA. Promptly informing contacts is critical to prevent further breaches.

North Korea’s cyberattacks show that personal and work devices can be vulnerable. Even cautious users can be tricked by clever scams, making it important to secure accounts and device.

Also Read: RBI Deputy Governor: Crypto & Stablecoins are Threat to Monetary Stability

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto ScamNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Pro-Crypto Senators Press Regulators to Replace Basel's Capital Rules
Pro-Crypto Senators Press Regulators to Replace Basel’s Capital Rules
Meta, Microsoft, Coinbase Partner With DOJ to Bust Southeast Asian Scams
Meta, Microsoft, Coinbase Partner With DOJ to Bust Southeast Asian Scams
Arthur Hayes Dumps Entire HYPE and NEAR Stack Days After $100K Charity Bet
Arthur Hayes Dumps Entire HYPE and NEAR Stack Days After $100K Charity Bet
Goldman Sachs, Apex, and Archax Team Up for Tokenized Real Estate Fund
Goldman Sachs, Apex, and Archax Team Up for Tokenized Real Estate Fund 
Capital is Rotating from Bitcoin to AI: Strategy Chairman Michael Saylor Explains Why BTC Price is Falling
Capital is Rotating from Bitcoin to AI: Strategy Chairman Michael Saylor Explains Why BTC Price is Falling

Find Us on Socials

You may also like

IronWorm Malware Targets Web3 Developers via Compromised npm Packages

IronWorm Malware Targets Web3 Developers via Compromised npm Packages

World Cup 2026 LASD Issues Warning Over FIFA Crypto Scams

World Cup 2026: LASD Issues Warning Over FIFA Crypto Scams

ATM Token Exploit Drains $243K Through Hidden Swap Loophole

ATM Token Exploit Drains $243K Through Hidden Swap Loophole

£5M Crypto Gift Scandal: U.K PM Starmer Puts Nigel Farage on the Spot

£5M Crypto Gift Scandal: U.K PM Starmer Puts Nigel Farage on the Spot

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information