Confluence News

North Korea hackers scan crypto wallets through fake Zoom calls

News-screening summary only. This is not investment advice and does not confirm market response.

North Korea's BlueNoroff group is running an active, technically advanced phishing campaign that scans victims' crypto wallets via fake Zoom/Teams calls before deploying cross-platform malware, posing a direct theft risk to crypto executives and users. JUMPSEC recovered live source code confirming wallet-profiling, AI-generated participant video, and malware delivery chains for both Windows and macOS, with the campaign ongoing as of July 2026.

Status
Active
Confirmation
Confirmed
Event type
SECURITY_INCIDENT
Market scope
SECTOR
Direction
-1
Impact / urgency
4 / 4
Impact category
HIGH
Risk stance
RISK OFF
Promotion
PROMOTED · 74/100
Promotion reason
Active, confirmed nation-state cyberattack campaign with live source-code evidence, targeting crypto wallets via novel pre-malware wallet-profiling technique, ongoing toolkit evolution documented through July 2026, and direct relevance to asset security across the crypto sector.
Duration class
PERSISTENT
Assets
ETH, SOL
Sectors
Blockchain Finance, Cryptocurrency, Cybersecurity, Investment
First detected
Impact started
Scheduled for
Not published
Occurred at

Sources

North Korea hackers scan crypto wallets through fake Zoom calls

Crypto.news · ESTABLISHED_MEDIA · Best available