A fake Zoom "update" is all it takes for hackers to seize crypto funds, cloud credentials, and entire Telegram accounts.A fake Zoom "update" is all it takes for hackers to seize crypto funds, cloud credentials, and entire Telegram accounts.

SEAL Warns of Daily Fake Zoom Attacks as DPRK Hackers Weaponize Familiar Faces

2025/12/16 05:05

Cybersecurity firm, Security Alliance (SEAL), said it is tracking multiple daily attempts by North Korean-linked threat actors using so-called “fake Zoom” or “fake Teams” meetings to distribute malware and expand access to new victims.

The non-profit reshared a detailed warning from security researcher Taylor Monahan outlining how the attacks unfold and the scale of losses involved.

Fake Zoom Calls, Real Losses

Monahan said the campaign begins with a message from a compromised Telegram account belonging to someone the victim already knows. These often have prior conversation history intact, which lowers suspicion and leads to an invitation to reconnect via a video call scheduled through a shared link.

During the call, victims are shown what appear to be legitimate participants, using real recordings sourced from previously hacked accounts or public material rather than deepfakes, before attackers claim technical issues and instruct targets to apply an update or fix.

The file or command provided, usually disguised as a Zoom software development kit (SDK) update, installs malware that quietly compromises the device across Mac, Windows, and Linux systems. This allows attackers to exfiltrate cryptocurrency wallets, passwords, private keys, seed phrases, cloud credentials, and Telegram session tokens.

She said more than $300 million has already been stolen using the method, and attackers often delay further contact to avoid detection after the initial infection. SEAL said social engineering is central to the campaign, while adding that victims are reassured repeatedly when they express concern and are encouraged to proceed quickly to avoid wasting the apparent contact’s time.

Monahan warned that once a device is compromised, attackers take control of the victim’s Telegram account and use it to message contacts and repeat the scam. This creates a cascading effect through professional and social networks.

The researcher urged anyone who has clicked a suspicious link to immediately disconnect from the internet, turn off the affected device, and avoid using it, secure funds using another device, change passwords and credentials, and completely wipe the compromised computer before reuse. She also stressed the need to secure Telegram by terminating all other sessions from a phone, updating passwords, and enabling multifactor authentication to prevent further spread.

Lazarus-Style Tactics

In the past year, several platforms have flagged phishing campaigns using fake Zoom meeting links to steal millions in cryptocurrency. Binance founder Changpeng “CZ” Zhao warned about rising AI deepfake scams after crypto influencer Mai Fujimoto was hacked during a fake Zoom call. Attackers used a deepfake impersonation and a malicious link to install malware, which compromised her Telegram, MetaMask, and X accounts.

Bitget CEO Gracy Chen also warned of a growing wave of phishing attacks using fake Zoom and Microsoft Teams meeting invitations to target crypto professionals. Last week, Chen said attackers pose as legitimate meeting hosts, often contacting victims via Telegram or fake Calendly links.

During the call, they claim audio or connection issues and urge targets to download a supposed network update or SDK, which is actually malware designed to steal passwords and private keys. Chen said the tactic mirrors methods used by the Lazarus group and explained that scammers have impersonated Bitget representatives.

The post SEAL Warns of Daily Fake Zoom Attacks as DPRK Hackers Weaponize Familiar Faces appeared first on CryptoPotato.

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.08589
$0.08589$0.08589
+0.40%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Binance Whale Loses $11.58 Million as Bitcoin Crashes Below $86,000

Binance Whale Loses $11.58 Million as Bitcoin Crashes Below $86,000

A major trader on Binance suffered an $11.58 million liquidation on a BTC/USDT long position as Bitcoin plunged below the $86,000 level. The entire position was wiped out in a single order, demonstrating the unforgiving nature of leveraged cryptocurrency trading during periods of intense selling pressure.
Share
MEXC NEWS2025/12/16 14:39
Tom Lee: Crypto's Best Years Lie Ahead as Adoption Gap Reveals Massive Growth Potential

Tom Lee: Crypto's Best Years Lie Ahead as Adoption Gap Reveals Massive Growth Potential

Tom Lee, co-founder and head of research at Fundstrat Global Advisors, has offered a compelling framework for understanding Bitcoin's growth runway. His analysis centers on a stark comparison: only 4 million Bitcoin wallets currently hold $10,000 or more, while approximately 900 million IRA and brokerage accounts globally contain at least that amount.
Share
MEXC NEWS2025/12/16 14:46
Quantexa Launches Platform to Reduce Stablecoin Strain on Small Banks

Quantexa Launches Platform to Reduce Stablecoin Strain on Small Banks

The post Quantexa Launches Platform to Reduce Stablecoin Strain on Small Banks appeared on BitcoinEthereumNews.com. In brief Quantexa designed an AML solution for mid-size and community banks. It can help them identify crypto-powered crime, according to Quantexa’s Christopher Bagnall. Stablecoin legislation is expected to unlock new competitors. Quantexa, a data and analytics software firm, introduced a product on Wednesday that’s intended to help smaller financial institutions fight crypto-powered crime in the U.S. The London-based company is now offering a cloud-based, anti-money laundering (AML) solution through Microsoft’s cloud computing platform, which is “designed specifically for U.S. mid-size and community banks,” according to a press release. Quantexa said the pre-packaged product allows teams investigating financial crimes to make faster decisions with less overhead while maintaining accuracy, noting that banks are held to the same compliance standards across the U.S., despite what resources they may have. The product, dubbed Cloud AML, is also meant to reduce “false positives.”  A company survey published earlier this month found that 36% of AML professionals think digital assets will have the biggest impact on the AML industry within the next five years. The product’s debut follows the passage of stablecoin legislation in the U.S. this summer that’s expected to unlock competition from the likes of Bank of Ameerica and Citigroup. With federal rules in place, stablecoins are expected to become more mainstream. Some banks are taking a forward-looking approach toward their products, but most are more concerned about the ability to monitor inflows and outflows within the context of financial crime, Chris Bagnall, Quantexa’s head of financial crimes solutions for North America, told Decrypt. “They’re just trying to find a way to monitor it, and that’s pretty much it,” he said. “Only the most innovative banks, which is a small handful in this space, are focused on making it a business.” Banks may be able to see that a customer received or…
Share
BitcoinEthereumNews2025/09/18 11:28