Just in:
SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // UAE presses ahead with projects despite uncertainty // GCC workplace AI adoption reaches 93% // Putin holds talks with Pezeshkian in Bishkek // Wellcome Partners with CJ Foods to Bring Over 100 Korean Favourites to Hong Kong // UAE non-oil growth accelerates to 20-month high // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Drone strike damages Kuwait residential complex, no injuries // Gambling Goblin repurposes Brazil government sites for SEO // Single-word dispute leaves G20 finance statement divided // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Russia brings cryptocurrency market law into force // Haldwani purification row: Caste back on political centre-stage // TotalEnergies, ExxonMobil connect Angolan suppliers to procurement // LatAm gushers and possible Venezuela exit a nightmare for Opec // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers //

Deepfake Zoom trap widens crypto risk

BlueNoroff has intensified its campaign against cryptocurrency executives by combining fake Zoom meetings, AI-generated video lures and fileless PowerShell malware in an intrusion that gave attackers access to a North American Web3 company for 66 days.

The operation, first detected after an intrusion began on 23 January 2026, marks a sharper turn in North Korea-linked cyber activity against digital asset businesses. Instead of relying on crude phishing pages or malicious attachments, the attackers used a manipulated Calendly invitation, a typosquatted Zoom link and a realistic browser-based meeting room to persuade the victim to run attacker-supplied commands under the guise of fixing audio problems.

The campaign has been attributed with high confidence to BlueNoroff, a financially motivated subgroup associated with the Lazarus ecosystem and North Korea’s Reconnaissance General Bureau. The group has long focused on banks, cryptocurrency platforms, blockchain developers, venture capital figures and executives with access to wallets, private keys, treasury systems or strategic deal information.

The latest attack chain began with impersonation of a trusted figure in the fintech legal sector. The victim received what appeared to be a legitimate meeting request, with the conferencing link later swapped for a domain that closely resembled Zoom. Once opened, the page displayed a convincing meeting interface, complete with participant tiles, apparent motion and simulated speaker activity.

The meeting was not live. The fake interface used pre-staged media, stolen video and AI-generated imagery to create the appearance of a real call. After the victim granted camera and microphone permissions, the page could capture live footage, adding a self-reinforcing element to the campaign. Video collected from one target could be repurposed to deceive another person in the same professional network.

The malware delivery relied on a ClickFix-style technique, a method in which victims are instructed to copy and paste commands into Windows tools to solve a fabricated technical problem. In this case, the lure centred on a fake Zoom software development kit update. The visible instructions appeared benign, but clipboard manipulation substituted the copied text with a PowerShell command that downloaded and executed the attacker’s payload.

That payload was designed to remain largely memory-resident. The PowerShell chain used obfuscation, execution policy bypasses and hidden processes to reduce visibility. Once active, the implant established command-and-control communications, collected system details, checked for virtual machine indicators and waited for further instructions. Its five-second beaconing pattern allowed the operators to issue tasks quickly while keeping the compromise inside normal user-session activity.

Post-exploitation activity showed clear financial and intelligence-gathering intent. Modules were used to steal Telegram Desktop session data, enumerate installed software, capture screens, extract browser artefacts and attempt privilege escalation. Telegram session theft is particularly significant in the cryptocurrency sector because founders, developers and investors often use messaging platforms for deal discussions, wallet coordination and introductions to new counterparties.

The infrastructure behind the campaign included command servers, exfiltration endpoints and more than 80 typosquatted domains imitating Zoom and Microsoft Teams. Registration patterns from late 2025 through March 2026 point to a prepared campaign rather than a one-off intrusion. Investigators also identified about 100 additional targets, with a heavy concentration in the United States, Singapore and the United Kingdom. A large majority operated in cryptocurrency, and nearly half were founders or chief executives.

BlueNoroff’s methods reflect a wider shift in North Korea-linked cryptocurrency theft. The most damaging attacks increasingly exploit people, communications channels and operational infrastructure rather than smart-contract flaws alone. Centralised exchanges, custodians, foundations and Web3 service providers present high-value targets because a single compromised workstation or messaging account can open access to treasury movements, deployment systems or executive decision-making.

The group’s tactics also show how generative AI is changing social engineering. Synthetic portraits, cloned meeting participants and manipulated video assets reduce the friction involved in impersonation. A victim no longer needs to believe only a text message or email; they can be shown what appears to be a familiar face inside a familiar meeting application.

The defensive implications are immediate for cryptocurrency companies. Meeting links embedded in calendar invitations require scrutiny, especially when a Google Meet invite is changed to a Zoom or Teams URL. Browser requests for camera access on unfamiliar domains should be treated as high risk. Staff should be trained that legitimate conferencing providers do not require users to paste terminal or PowerShell commands to restore audio.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Adobe widens Saudi AI access with $4 billion programme // Wellcome Partners with CJ Foods to Bring Over 100 Korean Favourites to Hong Kong // Haldwani purification row: Caste back on political centre-stage // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // ICICI Bank narrows gap on HDFC Nifty lead // Xi reaches Cairo as China broadens Egypt engagement // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Russia brings cryptocurrency market law into force // Tenchijin Joins “Science Castle Asia 2026” as Official Main Partner to Inspire Asia’s Next Generation of Researchers // TotalEnergies, ExxonMobil connect Angolan suppliers to procurement // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // UAE non-oil growth accelerates to 20-month high // Anthropic broadens Claude access with Fable 5.1 // Putin holds talks with Pezeshkian in Bishkek // LatAm gushers and possible Venezuela exit a nightmare for Opec // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Gambling Goblin repurposes Brazil government sites for SEO // UAE presses ahead with projects despite uncertainty //