CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Manta Co-Founder ‘Targeted’ by Lazarus Group in Zoom Phishing Attempt
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Manta Co-Founder ‘Targeted’ by Lazarus Group in Zoom Phishing Attempt
News

Manta Co-Founder ‘Targeted’ by Lazarus Group in Zoom Phishing Attempt

CoinRSS
Last updated: April 18, 2025 9:09 pm
CoinRSS Published April 18, 2025
Share

Contents
North Korea’s phishing and hacking campaignDaily Debrief Newsletter

Armed with fake Zoom calls, stolen identities, and malware, North Korea’s Lazarus Group has allegedly expanded its crypto infiltration strategy, and the industry is starting to feel it.

Kenny Li, co-founder of Ethereum layer-2 project Manta Network, said he was “targeted” in an elaborate Zoom phishing attempt by Lazarus Group in a tweet Thursday.

🚨 Just got targeted by Lazarus.

A known contact on TG reached out to me to ask for a chat. Scheduled a Zoom call. When I got on the Zoom, it asked me for camera access which I found a bit odd because I have used Zoom many times.

Even crazier, the team members had their…

— 🤓Kenny.manta (@superanonymousk) April 17, 2025

A known contact of Li arranged a Zoom call where familiar faces appeared on camera, only no one spoke. Then a prompt appeared urging Li to download a script to fix his audio.

“I could see their legit faces. Everything looked very real,” he wrote on Thursday. “But I couldn’t hear them… it asked me to download a script file. I immediately left.”

To verify the contact, Li asked to continue the conversation on Google Meet instead. The impersonator refused, and moments later, all messages were erased, and Li was blocked.

“Lazarus social engineering is getting pretty good,” he added in a follow-up tweet, adding that the phishing attempt could have used either deepfakes or “recordings from previous calls where they infected/hacked the other people.”

Li noted that he was “not certain” the phishing attempt was the work of Lazarus Group, but that according to security researchers, it matched the hacking group’s MO. Decrypt has reached out to Li, and will update this story should he respond.

North Korea’s phishing and hacking campaign

The incident is one of several recent attacks attributed to Lazarus, the North Korean state-backed hacking unit responsible for some of the largest crypto heists in history.

The group, already linked to February’s $1.4 billion Bybit hack, is reportedly changing its strategy by blending deepfake video, malware, and social engineering to deceive even experienced crypto executives.

According to new research from Paradigm security researcher Samczsun and Google’s Threat Intelligence Group (GTIG), Lazarus is just one arm of the DPRK’s sprawling cyber apparatus.

The regime now deploys a web of hacker subgroups like AppleJeus, APT38, and TraderTraitor, using tactics that range from fake job offers and Zoom calls to malware-laced npm packages and extortion.

Nick Bax of the Security Alliance (SEAL), a collective of white hat hackers and security researchers, issued a warning in March, “Having audio issues on your Zoom call? That’s not a VC, it’s North Korean hackers.”

He described the playbook in which chat messages cite audio issues, familiar faces appear on video, and the victim is redirected to download malware. “They exploit human psychology,” he wrote. “Once you install the patch, you’re rekt.”

Giulio Xiloyannis, co-founder of the Web3 platform for on-chain games and IPs MON Protocol, shared a similar experience. A hacker impersonating a project lead asked him to switch to a Zoom link mid-call.

“The moment I saw a Gumicryptos partner speaking and a Superstate one, I realized something was off,” he tweeted, sharing screenshots to warn others.

According to a recent GTIG report, North Korean IT workers are now infiltrating teams across the U.S., UK, Germany, and Serbia, masquerading as developers, using fake resumes and forged documents.

“DPRK hackers are an ever-growing threat against our industry,” Samczsun wrote, urging firms to adopt basic defenses, least privilege access, 2FA, device segregation, and to contact groups like SEAL 911 in the event of a breach.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

B3 Ethereum Gaming Chain Launching Token Airdrop on Base Next Week

FLOKI confirms a ‘double-top’ pattern: Is it the right time to buy?

Hyperliquid’s $4M culprit bags $177K in fresh gains – Details

Metropolis Aims To Make It Cheap And Easy To Build Small Blockchains For AI Agents to Flourish

FARTCOIN faces short-term dip, yet bulls retain control – How?

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Examining TRX’s price targets after altcoin loses 2.7% and whales sell
Next Article As Bitcoin Mining Companies Slump, Tether Loads Up on Bitdeer
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
How HYPE Surged on Hyperliquid’s Growing Perpetual Futures Stardom
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?