A North Korean hacking unit is using fake Zoom and Microsoft Teams meetings to rob crypto professionals of their wallet credentials.
BlueNoroff, a subgroup of the infamous Lazarus Group, has been running a campaign that weaponizes the mundane act of joining a video call. The operation has already reached over 100 victims across more than 20 countries, with 41% of targets located in the United States.
How the attack works
BlueNoroff registers domains that look almost identical to legitimate meeting platforms, a technique known as typosquatting. More than 80 of these lookalike domains have been created since late 2025.
Victims typically receive spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. Click the link, and you land on what looks like a normal Zoom or Teams interface. It is not.








