A fake Zoom "update" is all it takes for hackers to seize crypto funds, cloud credentials, and entire Telegram accounts.A fake Zoom "update" is all it takes for hackers to seize crypto funds, cloud credentials, and entire Telegram accounts.

SEAL Warns of Daily Fake Zoom Attacks as DPRK Hackers Weaponize Familiar Faces

Cybersecurity firm, Security Alliance (SEAL), said it is tracking multiple daily attempts by North Korean-linked threat actors using so-called “fake Zoom” or “fake Teams” meetings to distribute malware and expand access to new victims.

The non-profit reshared a detailed warning from security researcher Taylor Monahan outlining how the attacks unfold and the scale of losses involved.

Fake Zoom Calls, Real Losses

Monahan said the campaign begins with a message from a compromised Telegram account belonging to someone the victim already knows. These often have prior conversation history intact, which lowers suspicion and leads to an invitation to reconnect via a video call scheduled through a shared link.

During the call, victims are shown what appear to be legitimate participants, using real recordings sourced from previously hacked accounts or public material rather than deepfakes, before attackers claim technical issues and instruct targets to apply an update or fix.

The file or command provided, usually disguised as a Zoom software development kit (SDK) update, installs malware that quietly compromises the device across Mac, Windows, and Linux systems. This allows attackers to exfiltrate cryptocurrency wallets, passwords, private keys, seed phrases, cloud credentials, and Telegram session tokens.

She said more than $300 million has already been stolen using the method, and attackers often delay further contact to avoid detection after the initial infection. SEAL said social engineering is central to the campaign, while adding that victims are reassured repeatedly when they express concern and are encouraged to proceed quickly to avoid wasting the apparent contact’s time.

Monahan warned that once a device is compromised, attackers take control of the victim’s Telegram account and use it to message contacts and repeat the scam. This creates a cascading effect through professional and social networks.

The researcher urged anyone who has clicked a suspicious link to immediately disconnect from the internet, turn off the affected device, and avoid using it, secure funds using another device, change passwords and credentials, and completely wipe the compromised computer before reuse. She also stressed the need to secure Telegram by terminating all other sessions from a phone, updating passwords, and enabling multifactor authentication to prevent further spread.

Lazarus-Style Tactics

In the past year, several platforms have flagged phishing campaigns using fake Zoom meeting links to steal millions in cryptocurrency. Binance founder Changpeng “CZ” Zhao warned about rising AI deepfake scams after crypto influencer Mai Fujimoto was hacked during a fake Zoom call. Attackers used a deepfake impersonation and a malicious link to install malware, which compromised her Telegram, MetaMask, and X accounts.

Bitget CEO Gracy Chen also warned of a growing wave of phishing attacks using fake Zoom and Microsoft Teams meeting invitations to target crypto professionals. Last week, Chen said attackers pose as legitimate meeting hosts, often contacting victims via Telegram or fake Calendly links.

During the call, they claim audio or connection issues and urge targets to download a supposed network update or SDK, which is actually malware designed to steal passwords and private keys. Chen said the tactic mirrors methods used by the Lazarus group and explained that scammers have impersonated Bitget representatives.

The post SEAL Warns of Daily Fake Zoom Attacks as DPRK Hackers Weaponize Familiar Faces appeared first on CryptoPotato.

Piyasa Fırsatı
Cloud Logosu
Cloud Fiyatı(CLOUD)
$0.08024
$0.08024$0.08024
-2.63%
USD
Cloud (CLOUD) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

The HackerNoon Newsletter: Cypherpunks Write Code: Zooko Wilcox  Zcash (9/21/2025)

The HackerNoon Newsletter: Cypherpunks Write Code: Zooko Wilcox Zcash (9/21/2025)

How are you, hacker? 🪐 What’s happening in tech today, September 21, 2025? The HackerNoon Newsletter brings the HackerNoon homepage straight to your inbox. On this day, Malta's Independence Day in 1964, U.S.A. Neutrality Acts in 1939, Belize Gained Full Independence in 1981, and we present you with these top quality stories. From Remote Work Reality Check: Malta, Madeira and the Canaries to Terraforming Mars Could Save Earth (or Doom Us All), let’s dive right in. Can You Spend Crypto Without Selling It? Inside The ether.fi Cash Card’s “Never Sell” Revolution By @ishanpandey [ 10 Min read ] In-depth review of the Ether.Fi Cash Card – a DeFi-driven Visa that lets you spend crypto without selling it. Read More. How Evergen Scaled Renewable Monitoring with TigerData (TimescaleDB) and Slashed Infrastructure Cost By @tigerdata [ 9 Min read ] How Evergen scaled renewable monitoring by moving from MongoDB to TigerData (TimescaleDB)—cutting infra use >50%, speeding queries <500 ms, centralizing data. Read More. From Postgres to ScyllaDB: How Coralogix Achieved 349x Faster Queries By @scylladb [ 8 Min read ] Coralogix boosted query speeds 349x by migrating from PostgreSQL to ScyllaDB, cutting latency from 30s to 86ms with smart data modeling. Read More. Remote Work Reality Check: Malta, Madeira and the Canaries By @socialdiscoverygroup [ 4 Min read ] Remote Work in Paradise? 4 Years, 3 Islands, 1 Honest Guide. Discover the real trade-offs of Malta, Madeira Canary Islands for digital nomads. Read More. Cypherpunks Write Code: Zooko Wilcox Zcash By @obyte [ 6 Min read ] Zooko Wilcox grew up coding and questioning systems, and that path led him to create the privacy coin Zcash. Lets see more of this story! Read More. Why a Decentralized Internet is Inevitable (or Not) by 2030 By @awesomemike [ 8 Min read ] Explore the arguments for and against a decentralized internet by 2030, examining technology, regulation, and societal impact shaping its future. Read More. Terraforming Mars Could Save Earth (or Doom Us All) By @kingdavvd [ 6 Min read ] Explore how space technology helps fight climate change, from satellites tracking emissions to innovations driving sustainability. Read More. Bitcoin Highs Bring Familiar Questions, but Discipline Outlasts Hype By @paulquickenden [ 3 Min read ] Bitcoin has hit a new high price - but is it the top? What could push it higher or lower? Heres a steady, hype-free take on reading the signals Read More. 🧑‍💻 What happened in your world this week? It's been said that writing can help consolidate technical knowledge, establish credibility, and contribute to emerging community standards. Feeling stuck? We got you covered ⬇️⬇️⬇️ ANSWER THESE GREATEST INTERVIEW QUESTIONS OF ALL TIME We hope you enjoy this worth of free reading material. Feel free to forward this email to a nerdy friend who'll love you for it.See you on Planet Internet! With love, The HackerNoon Team ✌️
Paylaş
Hackernoon2025/09/22 00:02
Sport.Fun’s FUN Token Sale Smashes 100% Target In One Day

Sport.Fun’s FUN Token Sale Smashes 100% Target In One Day

The post Sport.Fun’s FUN Token Sale Smashes 100% Target In One Day appeared on BitcoinEthereumNews.com. Stunning Success: Sport.Fun’s FUN Token Sale Smashes 100
Paylaş
BitcoinEthereumNews2025/12/18 11:04
A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Paylaş
BitcoinEthereumNews2025/09/18 02:23