Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    The Robinhood Chain Paradox Built for Tokenized Stocks, Dominated by Memecoins
    The Robinhood Chain Paradox: Built for Tokenized Stocks, Dominated by Memecoins
    Senators to Brief Trump on CLARITY Act Path - Here's What to Expect
    Senators to Brief Trump on CLARITY Act Path – Here’s What to Expect
    CLARITY Act 5 Fights Still Unresolved Before the Merged Draft Drops
    CLARITY Act: 5 Fights Still Unresolved Before the Merged Draft Drops
  • Opinion
    OpinionShow More
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

North Korean Hackers Exploit Fake Zoom to Steal Crypto

Cybersecurity experts’ findings show how the hackers use hijacked Telegram accounts and fake video call updates to compromise devices and steal crypto.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2025-12-15
Make The Crypto Times preferred on GoogleGoogle
Share
North Korean Hackers Exploit Fake Zoom to Steal Crypto

Key Highlights

  • North Korean hackers use fake Zoom/Teams meetings and hijacked Telegram accounts to steal crypto and sensitive data from trusted contacts.
  • Victims often unknowingly run malicious updates, exposing wallets, passwords, and company secrets across Mac, Windows, and Linux systems.
  • Immediate action is critical: disconnect devices, secure accounts, and alert contacts to prevent further losses and malware spread.

North Korean hackers have increased their attacks and attack bases by creating fake Zoom and Teams meetings to steal cryptocurrencies and sensitive information. According to the cybersecurity company Security Alliance, these attacks take advantage of social engineering, a hacking technique that depends on the confidence level in professional networks.

The hackers start by hijacking a victim’s Telegram account, messaging known contacts, and sending a disguised link to schedule a call. Once victims interact, the attackers push malicious updates disguised as Zoom fixes, compromising computers across Mac, Windows, and Linux systems.

SEAL is tracking multiple DAILY attempts by North Korean actors utilizing “Fake Zoom” tactics for spreading malware as well as escalating their access to new victims.

Social engineering is at the root of the attack. Read the thread below for pointers on how to stay secure. https://t.co/2SQGdtPKGx

— Security Alliance (@_SEAL_Org) December 13, 2025

The firm shared cybersecurity expert Tay’s warning, which stated, “It all starts with the Telegram account of someone you know. They message everyone with prior conversation history. People you met at a conference. Or were introduced by a close friend. VCs. BDs. YOU CAN SEE THE CONVERSATION HISTORY. YOU KNOW THIS PERSON!” This approach tricks people by using familiar contacts, making them more likely to click on malicious links.

How the scam unfolds

The attack process is elaborate. Once a victim clicks the link, hackers request an “update” such as “Zoom Update SDK.scpt,” which secretly runs malware via AppleScript. Tay explained, “The malware EXFILTRATES EVERYTHING across Mac, Windows, and Linux. – All your wallets – Everything in password managers, Apple Notes, etc. – Your Telegram history + session auth tokens – Passwords, seed phrases, SSH keys, AWS creds.” Consequently, victims lose access to both personal and corporate assets, and their Telegram account becomes a tool to target others.

Attackers even simulate legitimate Zoom errors and provide screenshots, convincing victims to follow instructions. Tay added, “They are very very helpful. If you express skepticism, they quickly alleviate your concerns. Really smart people fall for this.” Victims often remain unaware that their systems have already been compromised.

Recent crypto heists signal escalation

This method aligns with North Korea’s recent cryptocurrency thefts. On November 27, South Korea’s largest crypto exchange, Upbit, suffered a $32 million hack. Yonhap News reported authorities suspect the Lazarus Group, linked to North Korea’s Reconnaissance General Bureau, orchestrated the attack. 

The breach targeted hot wallets storing Solana-based tokens like SOL and USDC. Upbit halted withdrawals, transferred funds to cold wallets, and launched a full investigation. A government source noted, “Rather than attacking the server, it is possible that the administrator account was hijacked or that the funds were transferred by pretending to be the administrator.”

Similarly, in August, Lazarus Group allegedly stole £17 million from the UK-based crypto exchange Lykke. The attack forced the company to shut down operations despite promising reimbursements. Authorities cited Bitcoin and Ethereum networks as channels used to launder stolen funds, highlighting the sophisticated nature of North Korean cyber campaigns.

Protecting yourself and your assets

Tay emphasized immediate action for affected users, “DISCONNECT WIFI – TURN COMPUTER OFF – DO NOT USE COMPUTER. ONLY USE PHONE/IPAD. Move funds to secure wallets or exchanges. Wipe the computer completely before using it again.” 

Additionally, users have been urged to secure Telegram accounts by terminating all other sessions and updating passwords and MFA. Promptly informing contacts is critical to prevent further breaches.

North Korea’s cyberattacks show that personal and work devices can be vulnerable. Even cautious users can be tricked by clever scams, making it important to secure accounts and device.

Also Read: RBI Deputy Governor: Crypto & Stablecoins are Threat to Monetary Stability

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto ScamNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

India Explains How Drug Syndicates Use Crypto to Evade Detection
India Explains How Drug Syndicates Use Crypto to Evade Detection
XRP Lawyer Slams Democrats Over CLARITY Act Support Pullout
XRP Lawyer Slams Democrats Over CLARITY Act Support Pullout
CFTC Chair Selig Backs c After Senate Draft Release
CFTC Chair Selig Backs CLARITY Act After Senate Draft Release
Bitcoin Nears Key Test as ETF Demand Returns: Glassnode
Bitcoin Nears Key Test as ETF Demand Returns: Glassnode
Can SpaceX Stock Reclaim $175 as August Share Unlock Nears?
Can SpaceX Stock Reclaim $175 as August Share Unlock Nears?

Find Us on Socials

You may also like

Ostium to Resume Trading on July 23 After $18M Arbitrum Exploit

Ostium to Resume Trading on July 23 After $18M Arbitrum Exploit

SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft

SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft

DOJ Moves to Seize $25M in Crypto From Global Scam Networks

DOJ Moves to Seize $25M in Crypto From Global Scam Networks

UN Warns Crypto Is Fueling $114B Southeast Asia Crime Economy

UN Warns Crypto Is Fueling $114B Southeast Asia Crime Economy

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information