North Korea hackers scan crypto wallets through fake Zoom calls
News-screening summary only. This is not investment advice and does not confirm market response.
North Korea's BlueNoroff group is running an active, technically advanced phishing campaign that scans victims' crypto wallets via fake Zoom/Teams calls before deploying cross-platform malware, posing a direct theft risk to crypto executives and users. JUMPSEC recovered live source code confirming wallet-profiling, AI-generated participant video, and malware delivery chains for both Windows and macOS, with the campaign ongoing as of July 2026.
- Status
- Active
- Confirmation
- Confirmed
- Event type
- SECURITY_INCIDENT
- Market scope
- SECTOR
- Direction
- -1
- Impact / urgency
- 4 / 4
- Impact category
- HIGH
- Risk stance
- RISK OFF
- Promotion
- PROMOTED · 74/100
- Promotion reason
- Active, confirmed nation-state cyberattack campaign with live source-code evidence, targeting crypto wallets via novel pre-malware wallet-profiling technique, ongoing toolkit evolution documented through July 2026, and direct relevance to asset security across the crypto sector.
- Duration class
- PERSISTENT
- Assets
- ETH, SOL
- Sectors
- Blockchain Finance, Cryptocurrency, Cybersecurity, Investment
- First detected
- Impact started
- Scheduled for
- Not published
- Occurred at
Sources
North Korea hackers scan crypto wallets through fake Zoom calls
Crypto.news · ESTABLISHED_MEDIA · Best available