North Korean hackers hijack Telegram, stage fake Zoom calls and deploy RAT malware to drain crypto wallets in a $300m long‑con campaign.​ North Korean cyber criminalsNorth Korean hackers hijack Telegram, stage fake Zoom calls and deploy RAT malware to drain crypto wallets in a $300m long‑con campaign.​ North Korean cyber criminals

North Korean ‘fake Zoom’ hustle drains $300m from crypto execs’ wallets

North Korean hackers hijack Telegram, stage fake Zoom calls and deploy RAT malware to drain crypto wallets in a $300m long‑con campaign.​

Summary
  • Attackers hijack trusted Telegram accounts, then lure crypto executives into fake Zoom or Teams calls using spoofed calendar invites.​
  • Pre‑recorded video of known industry figures masks RAT‑laden “patch” files that give hackers full system control and wallet access.​
  • The scheme forms part of North Korea’s wider campaign that has stolen over $2 billion in crypto, including the record Bybit breach.

North Korean cyber criminals have stolen over $300 million through a sophisticated social engineering campaign that impersonates trusted industry figures in fake video meetings, according to a security alert issued by MetaMask security researcher Taylor Monahan.

North Korean hackers go ‘long con’

The scheme, described as a “long con” operation, targets cryptocurrency executives through compromised communication channels, Monahan stated in the alert.

The attack begins when hackers gain control of a trusted Telegram account, typically belonging to a venture capitalist or conference contact known to the victim, according to the researcher. Attackers exploit previous chat history to establish legitimacy before directing victims to video calls on Zoom or Microsoft Teams through disguised calendar links.

During the meeting, victims view what appears to be a live video feed of their contact. The feed is often a recycled recording from a podcast or public appearance, according to the alert.

The attack culminates when the impersonator simulates a technical problem. After citing audio or video issues, the attacker instructs the victim to download a specific script or update a software development kit. The file contains malicious software, the researcher reported.

Once installed, the malware—often a Remote Access Trojan (RAT)—grants attackers complete system control, according to the alert. The RAT drains cryptocurrency wallets and extracts sensitive data, including internal security protocols and Telegram session tokens, which are then used to target additional victims in the network.

Monahan stated that the operation “weaponizes professional courtesy,” exploiting the psychological pressure of business meetings to induce errors in judgment. The researcher advised that any request to download software during a call should be considered an active attack signal.

The fake meeting strategy forms part of a broader campaign by North Korean actors, who have stolen an estimated $2 billion from the cryptocurrency industry over the past year, including the Bybit breach, according to industry reports.

Market Opportunity
Belong Logo
Belong Price(LONG)
$0.009809
$0.009809$0.009809
+68.36%
USD
Belong (LONG) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Exploring the Future of the Internet with ‘web3 with a16z’

Exploring the Future of the Internet with ‘web3 with a16z’

The post Exploring the Future of the Internet with ‘web3 with a16z’ appeared on BitcoinEthereumNews.com. Peter Zhang Sep 18, 2025 22:39 The podcast ‘web3 with a16z’ explores the transformative potential of Web3, offering insights from key industry figures on how this new internet era empowers users to own digital content. The podcast series “web3 with a16z” is shedding light on the transformative potential of the next generation of the internet, commonly referred to as Web3. This series, produced by a16z crypto, delves into how this burgeoning internet era empowers users, from artists to developers, to not just read or write but to own pieces of the digital landscape. Understanding Web3 In contrast to its predecessors, Web1 and Web2, which focused on reading and writing capabilities, Web3 introduces the concept of ownership. This shift is unlocking unprecedented levels of creativity and entrepreneurship, as individuals and organizations can now have a stake in the digital content they create or engage with. According to the a16z crypto, this ownership aspect is crucial in driving the next wave of innovation and economic opportunity in the digital realm. Diverse Content and Expert Insights The podcast doesn’t just stop at explaining the concepts; it offers a variety of formats and topics that cater to different interests within the crypto and Web3 space. From the latest trends to in-depth research and data insights, “web3 with a16z” provides a platform for top scientists and industry leaders to share their knowledge and expertise. This makes it a valuable resource for anyone looking to understand the nuances of crypto and the broader implications of Web3. A Resource for Builders and Users One of the core aims of the podcast is to serve as a definitive guide for both builders and users of the internet. Whether you are a coder, a company, or a community, the insights provided…
Share
BitcoinEthereumNews2025/09/19 19:50
Unstoppable: Why No Public Company Can Ever Catch MicroStrategy’s Massive Bitcoin Holdings

Unstoppable: Why No Public Company Can Ever Catch MicroStrategy’s Massive Bitcoin Holdings

BitcoinWorld Unstoppable: Why No Public Company Can Ever Catch MicroStrategy’s Massive Bitcoin Holdings Imagine trying to build a mountain of gold, only to discover
Share
bitcoinworld2025/12/17 14:30
How Crypto Could Reshape Finance, AI, and Privacy by 2026: A16z Crypto

How Crypto Could Reshape Finance, AI, and Privacy by 2026: A16z Crypto

The post How Crypto Could Reshape Finance, AI, and Privacy by 2026: A16z Crypto appeared on BitcoinEthereumNews.com. From stablecoin payments to AI-driven agents
Share
BitcoinEthereumNews2025/12/17 14:38