
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to harvest personal details and potentially compromise corporate access, especially targeting non-technical staff in crypto firms who can influence or authorize financial activity.
This campaign, attributed to a North Korea-linked group known as Famous Chollima or Wage Mole, begins with outreach on LinkedIn. Attackers pose as recruiters for a cryptocurrency company, either inventing an entirely fake business or impersonating a real one using convincing websites and typosquatted domains. Targets are told they are a strong fit for a high-paying role and are directed to complete a short online assessment as the next step.
The assessment itself is designed to look professional and legitimate. It asks applicants to fill in extensive personal and career details, including name, email, LinkedIn URL, phone number, and work history. In some versions, applicants are asked to turn on their webcam, framed as a way to ensure they are not cheating on a basic multiple-choice test. Every detail submitted is handed directly to the attackers.
The campaign works because it mirrors a normal, low-friction hiring experience. A recruiter reaching out unprompted, a slick assessment portal, and a request for standard application information all look ordinary on the surface. By impersonating real crypto firms or building believable fake ones, attackers reduce the skepticism a target might otherwise apply to an unsolicited job offer.
The targeting strategy also matters. Rather than focusing on developers or technical staff, the group prioritizes non-technical roles in finance, legal, compliance, and executive support, people who may have access to company funds or know people who do. This shifts the payoff from a technical compromise to a faster path toward financial access or influence.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a campaign tied to a North Korean-linked group (Famous Chollima, also known as Wage Mole) that creates fake companies or impersonates real crypto firms to lure job seekers into completing a fake online assessment that harvests personal and career details.
The campaign focuses on non-technical staff such as finance, legal, compliance, and HR/recruiting employees who may have access to company funds or influence over people who do, rather than developers.
Red flags include unsolicited recruiter messages that quickly push an assessment link, requests for extensive personal details early on, and pressure to enable a webcam during a basic multiple-choice test.
According to the source, attackers frame the webcam request as a way to prove the applicant is not cheating on the assessment, which is really a pretext to gather more information or verify identity for their scam.
Imagine this: LinkedIn ping, ‘We’ve decided you’re the person for this role. Just complete a short online assessment.’ That’s the “ClickFake interview” attack, linked to the Famous Chollima group. They spin up fake or typosquatted crypto companies and funnel you to a slick assessment site. You’re asked for name, email, LinkedIn URL, phone, work history, and even to turn on your webcam for a basic multiple-choice test. All of that flows straight to them, especially targeting finance, legal, and compliance staff. If a recruiter you don’t know pushes an instant assessment link, stop. Look up the company and recruiter yourself in a new tab, only use links you find, not the ones they send.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…