惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
Google DeepMind News
Google DeepMind News
小众软件
小众软件
GbyAI
GbyAI
酷 壳 – CoolShell
酷 壳 – CoolShell
F
Fortinet All Blogs
博客园 - 三生石上(FineUI控件)
B
Blog
量子位
B
Blog RSS Feed
Vercel News
Vercel News
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
爱范儿
爱范儿
Jina AI
Jina AI
C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
H
Hackread – Cybersecurity News, Data Breaches, AI and More
云风的 BLOG
云风的 BLOG

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
North Korea-linked actor targets Web3 execs in social-eng...
David Jones · 2026-04-27 · via Cybersecurity Dive - Latest News

An article from site logo

Founders and other top executives were compromised to gain access to crypto wallets.

Published April 27, 2026

Businessmen use Bitcoin to lure others into a trap

Getty Images

Researchers warn that a financially motivated unit of North Korea’s Lazarus Group has been running a social-engineering campaign that uses fake Zoom or Teams calls against senior-level executives in cryptocurrency and blockchain. 

The threat actor, tracked as BlueNoroff, targeted a legal executive at an international consulting firm with a Calendly calendar invite that contained a typo-squatted Zoom link. This led to exfiltration of meeting footage from live camera feeds, according to a Monday blog post from Arctic Wolf.   

The hackers targeted about 100 different executives spread across more than 20 countries. About 40% of the victims were based in the U.S., with Singapore and the U.K. also among the most targeted countries. The targets included decentralized finance founders, exchange operators, blockchain wallet developers and others, according to Arctic Wolf researchers.

Individuals were targeted due to their “direct access to private keys, wallet infrastructure, and exchange administration” panels, demonstrating the goal to be able to access to crypto wallets.

Researchers said the hackers conducted deep reconnaissance on selected targets to make the attacks more credible.

“The attackers appear to have conducted detailed investigative work prior to setting up each fake meeting,” Ismael Valenzuela, VP of threat intelligence at Arctic Wolf, told Cybersecurity Dive. “The attacker's ability to populate a fake Zoom or Teams call with recognizable industry figures, tailored to the specific target’s professional network, represents a potent social engineering capability on behalf of the threat actor.”

More than 80 typo-squatted Zoom or Teams domains were registered over a five-month period starting in late 2025. Researchers also analyzed about 950 files from the attacker infrastructure, which showed how stolen web footage was combined with AI-generated images to create fabricated content for future social engineering attacks.

The activity appears consistent with previously documented BlueNoroff activity. Researchers at Huntress and Kaspersky have researched earlier threat campaigns targeting Web3 organizations.

The Huntress blog documented a 2025 social engineering attack based on a single endpoint intrusion. Huntress officials said the campaign outlined by Arctic Wolf demonstrates a major escalation in capabilities. 

Jon Semon, principal security operations analyst at Huntress told Cybersecurity Dive, “I can say with confidence that BlueNoroff has grown substantially in the six to eight months since our [research], in terms of tooling, infrastructure, malware development, and overall attack volume.”