
North Korean hacking groups are using fake Zoom meetings to steal cryptocurrency from digital asset users by installing malware on victims' devices.
Security researchers said attackers pose as employers, investors or business partners before inviting targets to fraudulent video calls that request software downloads.
The malware is designed to scan devices for cryptocurrency wallets, private keys and browser credentials before sending the stolen information to the attackers.
Researchers said the campaign primarily targets cryptocurrency companies, developers, investors and other people who manage digital assets.
North Korean cyber groups have previously been linked to major cryptocurrency thefts, with stolen funds often used to support the country's sanctions-evasion activities.
Security experts recommend verifying meeting invitations, avoiding unknown software downloads and using hardware wallets and multi-factor authentication to reduce the risk of theft.