Need help? Support
BITCOIN
Tether Dominance USDT.D

Which group ran fake Zoom attacks?

Published 445 words 3 min read

TLDR

North Korean state?linked hackers, notably the Lazarus Group, are behind the recent fake Zoom attack wave targeting crypto teams, according to multiple security briefings and reports. North Korean hackers

  1. The scheme uses Telegram impersonation, pre?recorded Zoom videos, and a fake SDK or audio patch to drop malware. Attack method detailed
  2. Losses are reported at over $300 million, with attempts seen multiple times per day. Scale and frequency
  3. Some write?ups link sub?group BlueNoroff and macOS malware such as NimDoor to this campaign. Attribution notes

Deep Dive

1. Modus Operandi

The attack typically starts from a compromised or spoofed Telegram account of someone the target knows, moving the conversation to a calendar invite and Zoom call. During the call, attackers simulate audio issues and push a supposed Zoom/SDK patch, which is actually a remote?access Trojan that exfiltrates passwords, wallet keys, and session tokens. This pattern has been documented in recent reports. Attack method detailed

Once tokens and credentials are taken, the victims Telegram and contacts can be leveraged for further compromises, creating a cascade of trusted introductions. Report of daily attempts

What this means

Treat any request to install software or patches during a live call as high risk. Verify identities on a separate channel before opening links or files.

2. Scale And Frequency

Security Alliance (SEAL) and researcher Taylor Monahan report multiple attempts per day and cumulative thefts exceeding $300 million from this and related social?engineering tactics. The volume indicates an industrialized campaign rather than isolated incidents. Scale and frequency

The workflow leverages routine business behaviors (calendar invites, video calls) to lower defenses, which explains the breadth of victims across funds, founders, and engineers. Additional context

What this means

Even sophisticated teams are vulnerable when social context feels normal. Build a default pause for any mid?call install prompts or new tooling requests.

3. Who Is Behind It

Multiple outlets attribute the campaign to North Korean actors, with Lazarus frequently named and BlueNoroff referenced in connection with macOS tooling such as NimDoor. This aligns with prior DPRK playbooks that emphasize social engineering alongside malware delivery. Attribution notes

The same ecosystem has been tied to earlier crypto thefts and job?interview scams, indicating continuity of tactics, targets, and objectives. Background reference

What this means

If your role involves approvals, treasury, or code signing, assume you are a high?value target and tighten verification steps for meeting links and downloads.

Conclusion

Reports indicate the fake Zoom attacks are a coordinated North Korean operation centered on social engineering, with Lazarus and associated units implicated. The method exploits trust and routine workflows to deliver malware at scale. The most effective countermeasure is process discipline around identity checks and a blanket refusal to install software or patches during live calls, especially when initiated via messaging apps.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top