Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026

    IEEE Course on Using AI to Modernize Power Grids

    August 5, 2026

    The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
    • IEEE Course on Using AI to Modernize Power Grids
    • The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
    • Puzzle Corner | MIT Technology Review
    • AI Influencers Are Heading Into Uncharted Territory
    • The Download: NASA’s new telescope and Chinese tech import curbs
    • A New Device Eases One of the Most Annoying Parts of Routine Physicals
    • NASA’s new dark energy space telescope can also detect killer asteroids
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Tech News»‘The attacker completed in under five minutes’: Experts warn of North Korea-linked campaign using fake Zoom meetings to target crypto execs
    Tech News

    ‘The attacker completed in under five minutes’: Experts warn of North Korea-linked campaign using fake Zoom meetings to target crypto execs

    kirklandc008@gmail.comBy kirklandc008@gmail.comApril 28, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    'The attacker completed in under five minutes': Experts warn of North Korea-linked campaign using fake Zoom meetings to target crypto execs
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • State-sponsored attackers crafted convincing fake video calls to target cryptocurrency firms
    • A clipboard hijack trick replaced benign commands with malware‑deploying code
    • The operation enabled rapid credential theft, persistence, and full system compromise

    Security researchers Arctic Wolf have revealed details of a highly sophisticated campaign targeting North American Web3 and cryptocurrency companies.

    It is conducted by state-sponsored threat actors called BlueNoroff, a financially motivated subgroup of the dreaded North Korean Lazarus Group, with a goal of establishing persistent access on their target’s devices.

    They do so by tricking the victim into installing malware on the computers themselves, but the way they do it is quite advanced.

    Article continues below

    You may like

    ClicFix has entered the chat

    While preparing for the attack, the threat actors would use real, high-value people from the Web3 world, generate convincing headshots using ChatGPT, and create semi-animated videos using Adobe Premiere Pro 2021.

    They would then create a fake Zoom video call website identical to the actual Zoom call page, and would display the video to make it look even more convincing.

    BlueNoroff would then invite the actual victim through Calendly, almost half a year into the future (most likely to make it look more convincing – important people are, after all, super busy).

    When the victim clicks on the Zoom link, they see what they’re used to seeing – a video call page with the person on the other side moving and acting as if they were real. However, eight seconds into the call, a message would pop up across the screen, saying their “SDK is deprecated” and presenting them with an “Update Now” button.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    The button leads to a typical ClickFix technique – to “fix” the problem, the victim needs to copy and paste a command. But since many are now aware of these attacks, BlueNoroff takes it a step further – the code being copied is actually legitimate and benign.

    However, the fake Zoom website has a malicious JavaScript application embedded which handles the “copy” action, intercepts the clipboard event in the browser, and replaces what the user thinks they copied with different code.

    That code, if executed, deploys malware on the device which establishes remote access to the system, allows BlueNoroff to exfiltrate credentials, session tokens, and other sensitive business data, and grants them the ability to move laterally throughout the network.

    “The technical execution chain in this campaign is both efficient and operationally disciplined,” Arctic Wolf said. “From initial URL click to full system compromise, including C2 establishment, Telegram session theft, browser credential harvesting, and persistence, the attacker completed in under five minutes.”

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

    attacker Campaign completed Crypto Execs experts Fake Korealinked Meetings minutes North target warn Zoom
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The AI Notetaker Has Been Invited to All the Meetings

    August 5, 2026

    I fixed my home office’s spotty Wi-Fi with Samsung’s free diagnostic tool – and it took just minutes

    July 24, 2026

    How attackers hosted a fake Claude download page on the claude.ai domain

    July 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
    • IEEE Course on Using AI to Modernize Power Grids
    • The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
    • Puzzle Corner | MIT Technology Review
    • AI Influencers Are Heading Into Uncharted Territory

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026

    IEEE Course on Using AI to Modernize Power Grids

    August 5, 2026

    The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

    August 5, 2026

    Puzzle Corner | MIT Technology Review

    August 5, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.