North Korean ‘fake Zoom’ crypto hacks now a daily threat: SEAL
Cybersecurity nonprofit Security Alliance (SEAL) warns they’re now seeing multiple daily attempts by North Korean hackers to scam victims using fake Zoom meetings.
The scam involves tricking victims into downloading malware during a fake Zoom call, which enables hackers to steal sensitive data, including passwords and private keys. Security researcher Taylor Monahan warned that the tactic has already looted over $300 million from users.
How the fake Zoom call scam works
Monahan said the scam starts with a message from a Telegram account of someone known to the victim, who is lulled into a false sense of security due to familiarity. The conversation then leads to an invitation to catch up over Zoom.
“They’ll share a link before the call that is usually masked to look real. There you can see the person + some of their partners/colleagues. These videos are not deepfakes as widely reported. They are real recordings from when they got hacked or public sources (podcasts),” she said.
However, once the call begins, the hackers feign audio issues and send a patch file, which, when opened, infects devices with malware. The hackers then end the sham call under the guise of rescheduling for another day.
“Unfortunately, your computer is already compromised. They just play it cool to prevent detection. They will eventually take all your crypto. And your passwords. And your company/protocol’s shit. And your Telegram account. Then you will go on to rekt all your friends.”
Here’s what to do if you’ve clicked the malware link
Monahan warns that anyone who has clicked on a link shared during a suspicious Zoom call should immediately disconnect from WiFi and turn off the affected device.
Then, use another device to transfer crypto to new wallets, change all passwords, activate two-factor authentication where possible, and perform a full memory wipe on the infected device before using it again.
She also stresses it’s “critical” to secure Telegram accounts to prevent the bad actors from gaining control by opening on a phone, going into settings, devices, terminating all other sessions, changing the password and adding or updating multifactor authentication.
Monahan said the hackers are gaining control of Telegram accounts and using the stored contacts to find and scam new victims.
“Lastly, if they hack your telegram, you need to TELL EVERYONE ASAP. You are about hack your friends. Please put your pride aside and SCREAM about it.”
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Clean Energy Market Fluidity: Ushering in a New Age with CFTC-Sanctioned Platforms
- REsurety's CleanTrade, the first CFTC-approved SEF for clean energy , is transforming market liquidity and transparency by standardizing VPPAs, PPAs, and RECs. - The platform attracted $16B in notional value within two months, enabling institutional investors to hedge energy risks while aligning with ESG goals through verifiable decarbonization metrics. - Renewable developers benefit from streamlined financing and securitization tools, creating predictable revenue streams and expanding access to capital

Investing in Human Capital for a Greener Tomorrow: The Growth of Education and Career Training in Renewable Energy
- Global energy transition drives rapid growth in renewable workforce demand, with U.S. wind turbine technician roles projected to surge 60.1% by 2033. - Institutions like Farmingdale State College bridge skill gaps through industry-aligned programs, offering hands-on training and partnerships with firms like Orsted and GE . - Investors gain strategic opportunities by funding vocational training and microcredentials, addressing decarbonization needs while boosting social equity through inclusive initiative

Clean Energy Market Fluidity: The CFTC-Endorsed Transformation
- CFTC approved CleanTrade as the first SEF for clean energy , addressing market fragmentation and liquidity gaps. - The platform enables institutional-scale trading of VPPAs and RECs with automated compliance and $16B in early trading volume. - Integrated analytics and regulatory compliance enhance transparency, reducing risks for investors in renewable energy assets. - Early adoption by Cargill and Mercuria highlights CleanTrade's potential to reshape $1.2T clean energy investment landscape.

How iRobot Strayed from Its Original Path
