The North Korean hacking group BlueNoroff, a subgroup of the infamous Lazarus Group, has targeted over 100 victims across more than 20 countries using domains impersonating video conferencing platforms like Zoom and Microsoft Teams. The attack combines webcam footage exfiltration and a technique called ClickFix that hijacks the clipboard to steal cryptocurrency wallet credentials such as MetaMask. Approximately 80% of victims work in cryptocurrency or blockchain finance, and 45% are CEOs or company founders. Complete system compromise has been observed in under five minutes, and the group has created over 80 fraudulent domains since late 2025.
Source: Read the original article

