Imagine getting a Zoom invite from your boss or a top crypto exec. You join, see their face and hear their voice. They ask you to install a quick “Zoom update” for better meeting quality. Minutes later, your crypto wallets are drained. This is not a movie plot—it’s the real attack hitting crypto and Web3 companies right now.
The , linked to North Korean hackers from the Lazarus group, has upped its game. They mix social tricks, AI tricks, and sneaky macOS malware to steal millions in crypto. This campaign started in late 2025 and keeps growing. It targets high-value players in crypto exchanges, Web3 startups, and blockchain firms.
In this post, we break down the full attack step by step. We cover how it works, who gets hit, and simple ways to fight back. If you work in crypto or Web3, read on—this could save your funds.
is a sneaky cyber crew backed by North Korea. They go by names like APT38, Sapphire Sleet, or Stardust Chollima. Their goal? Steal money to dodge sanctions and fund their operations.
These hackers love financial targets. They hit banks, crypto exchanges, and fintech apps. They build custom malware for Windows, macOS, and Linux. What makes them scary? They adapt fast to new tech like AI and deepfakes.
Past hits include big crypto thefts. Now, they focus on Web3—think DeFi, NFTs, and blockchain projects. Their attacks mix spy tricks with theft, making them hard to spot.
‘s latest trick is a multi-step plan. It starts with trust and ends with empty wallets. Here’s how it unfolds:
Hackers send fake messages on Telegram or email. They pretend to be crypto big shots—like CEOs or partners. The message invites you to a “urgent meeting” about a deal or investment.
Links look like real Calendly, Google Meet, Zoom, or Teams invites. But they lead to fake sites—like typosquatted domains controlled by hackers. Example: something like support[.]us05web-zoom[.]biz.
You join the “meeting.” A deepfake video and voice of a real exec greets you. AI makes it look and sound perfect. They build trust fast, then say: “Download this Zoom extension for HD video.”
Victims download files like zoom_sdk_support.scpt for macOS. This is an AppleScript loader. It hides your tracks (disables bash history), checks your Mac type (Apple Silicon or not), installs Rosetta 2 if needed, and pulls more malware.
From there, it sets up backdoors, steals data, and phones home to hackers.
The malware is modular—like Lego blocks for crime. Key parts:
This setup lets hackers move sideways, stay hidden, and steal big.
Security pros map this to MITRE ATT&CK framework. Key moves:
Knowing these helps your tools detect it.
Over 100 crypto orgs in 20+ countries. Hot spots: US, Singapore, UK. 80% in crypto finance, 45% C-level execs or founders.
Attack speed? Initial contact to compromise: under 5 minutes. Some infections last 66 days. Losses? Direct crypto theft via clipboard swaps, plus spread to contacts via hijacked Telegram.
Here’s the scary part. Hackers grab your webcam during infection. Mix it with AI to make new deepfakes. Use them to trick your contacts. It’s a chain reaction— one hit leads to more.
They scout targets via LinkedIn, Twitter, websites. Focus on CEOs, CTOs, wallet admins in North America, SE Asia, Europe.
Don’t panic—fight back with these steps:
Run audits often. Tools like EDR can flag tricks early.
The and from show how cyber crime evolves. Crypto and Web3 are goldmines for hackers. But with awareness and defenses, you can protect your assets.
Share this post if it helps. Stay vigilant—your next meeting might not be what it seems.
Discuss this news on our Telegram Community. Subscribe to us on Google news and do follow us on Twitter @Blockmanity
Did you like the news you just read? Please leave a feedback to help us serve you better
Disclaimer: Blockmanity is a news portal and does not provide any financial advice. Blockmanity's role is to inform the cryptocurrency and blockchain community about what's going on in this space. Please do your own due diligence before making any investment. Blockmanity won't be responsible for any loss of funds.
: Why It's Joining Indiana and Tennessee to Stop Scams Minnesota is on the verge…
Is the Hype Around Eco-Friendly Crypto Just Hot Air? Everyone talks about Bitcoin's massive energy…
vs Blockchains: Simple Guide for Crypto Newbies Blockchain technology powers cryptocurrencies like Bitcoin and Ethereum.…
Introduction: A Big Move for PayPal in Crypto PayPal, the giant in online payments, is…
Global Regulators Open the Door to Digital Assets – But Is Your Bank Ready? Regulators…
Visa Supercharges Stablecoin Payments by Adding : Base, Polygon, and More Big news for the…