North Korean hackers hijack Telegram, stage fake Zoom calls and deploy RAT malware to drain crypto wallets in a $300m long‑con campaign.​ North Korean cyber criminalsNorth Korean hackers hijack Telegram, stage fake Zoom calls and deploy RAT malware to drain crypto wallets in a $300m long‑con campaign.​ North Korean cyber criminals

North Korean ‘fake Zoom’ hustle drains $300m from crypto execs’ wallets

2025/12/15 19:16

North Korean hackers hijack Telegram, stage fake Zoom calls and deploy RAT malware to drain crypto wallets in a $300m long‑con campaign.​

Summary
  • Attackers hijack trusted Telegram accounts, then lure crypto executives into fake Zoom or Teams calls using spoofed calendar invites.​
  • Pre‑recorded video of known industry figures masks RAT‑laden “patch” files that give hackers full system control and wallet access.​
  • The scheme forms part of North Korea’s wider campaign that has stolen over $2 billion in crypto, including the record Bybit breach.

North Korean cyber criminals have stolen over $300 million through a sophisticated social engineering campaign that impersonates trusted industry figures in fake video meetings, according to a security alert issued by MetaMask security researcher Taylor Monahan.

North Korean hackers go ‘long con’

The scheme, described as a “long con” operation, targets cryptocurrency executives through compromised communication channels, Monahan stated in the alert.

The attack begins when hackers gain control of a trusted Telegram account, typically belonging to a venture capitalist or conference contact known to the victim, according to the researcher. Attackers exploit previous chat history to establish legitimacy before directing victims to video calls on Zoom or Microsoft Teams through disguised calendar links.

During the meeting, victims view what appears to be a live video feed of their contact. The feed is often a recycled recording from a podcast or public appearance, according to the alert.

The attack culminates when the impersonator simulates a technical problem. After citing audio or video issues, the attacker instructs the victim to download a specific script or update a software development kit. The file contains malicious software, the researcher reported.

Once installed, the malware—often a Remote Access Trojan (RAT)—grants attackers complete system control, according to the alert. The RAT drains cryptocurrency wallets and extracts sensitive data, including internal security protocols and Telegram session tokens, which are then used to target additional victims in the network.

Monahan stated that the operation “weaponizes professional courtesy,” exploiting the psychological pressure of business meetings to induce errors in judgment. The researcher advised that any request to download software during a call should be considered an active attack signal.

The fake meeting strategy forms part of a broader campaign by North Korean actors, who have stolen an estimated $2 billion from the cryptocurrency industry over the past year, including the Bybit breach, according to industry reports.

Market Opportunity
Belong Logo
Belong Price(LONG)
$0.00605
$0.00605$0.00605
-3.27%
USD
Belong (LONG) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP gaat multichain: 5 inzichten uit Ripple’s strategie op Solana Breakpoint

XRP gaat multichain: 5 inzichten uit Ripple’s strategie op Solana Breakpoint

Ripple zet een duidelijke stap richting een bredere rol voor XRP binnen het multichain-ecosysteem. Tijdens het Solana Breakpoint-event lichtte Luke Judges, Global
Share
Coinstats2025/12/16 00:17
Market Direction and Use Case Comparison for 2026 –

Market Direction and Use Case Comparison for 2026 –

The post Market Direction and Use Case Comparison for 2026 – appeared on BitcoinEthereumNews.com. Cryptocurrency markets remain mixed as major assets show varying
Share
BitcoinEthereumNews2025/12/16 00:21
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48