A representative from a Canadian online gambling firm thought they were having a standard Zoom call with a familiar contact but was, in fact, conversing with North Korean hackers on a fake version of the platform. 

Field Effect Analysis reported that on May 28, the unnamed company was targeted by BlueNoroff, a subgroup of the infamous Lazarus Group, which is supported by North Korea. 

BlueNoroff is a financially driven threat actor that usually focuses on banks and cryptocurrency exchanges, along with gaming and entertainment sectors, and financial technology firms, to generate income for North Korea. 

The gang has taken over US$1.3 billion since 2017, primarily via SWIFT banking thefts and cryptocurrency heists. 

 

Deepfake 

Field Effect reported that BlueNoroff set up a fraudulent website mimicking an authentic Zoom support page to attack the gaming firm. The assailants impersonated an actual business associate and arranged a Zoom meeting with the target utilizing deepfake technology. 

In the Zoom meeting, the hackers pretended to have "audio issues," and the victim was instructed to execute a "Zoom audio repair script" to resolve the situation. However, the script was malicious software. 

Upon execution, the script initiated a series of downloads and commands, asking the user for system credentials and quietly installing several malicious payloads. This enabled the attackers to obtain various sensitive personal and system information, particularly targeting cryptocurrency-related assets and messaging data. 

According to Field Effect, the assault seems to be a component of a wider Zoom impersonation effort initially detected in March 2025 that has primarily focused on cryptocurrency firms. 

“It exemplifies an evolving pattern in which financially motivated threat actors continue refining their tradecraft, embedding malicious activity within legitimate business workflows and exploiting user trust as the primary attack surface,” the analysts wrote.

 

Bangladesh Bank Robbery 

BlueNorroff achieved its most infamous milestone in February 2016, when the group effectively implanted malware into the servers of Bangladesh Bank. This enabled them to secure credentials allowing 35 transfer requests from the New York Fed to accounts in the Philippines and Sri Lanka, amounting to nearly $1 billion. 

Out of the 35 payments, five, amounting to US$101 million, were executed before an employee at the New York Fed noticed something suspicious and halted additional transactions. 

Approximately $20 million flowed into Sri Lanka and was swiftly reclaimed. The remainder was moved to four accounts at the Philippine bank RCBC, which had been opened that same day using fake identities. From that point, it found its way into the loosely regulated Philippine casino sector, where it was washed at VIP gaming tables, before vanishing without a sign. 

image
Check Out Other Casino Offers
Crystal Slots
Crystal Slots

Bonus

up to 500 Free Spins

  • Over 600 slots
  • Fun loyalty trophy scheme
  • Fantastic selection of games
18+. T&C’s Apply

New players only, £10+ fund, 10x bonus wagering requirements, max bonus conversion to real funds equal to lifetime deposits (up to £250), 18+ GambleAware.org. Full T&Cs apply

Fruity King
Fruity King

Welcome Bonus

100% up to £100 +50 Free Spins on

  • Unique Loyalty Scheme
  • Lighting Fast Payouts
  • Top Gaming Providers
18+. T&C’s Apply

New Players Only. Wager from real balance first. 10X wager the bonus money within 30 days, and 10x wager any winnings from the free spins within 7 days. Contribution varies per game. Available on selected games only. Wager calculated on bonus bets only. Bonus offer and any winnings from the offer are valid for 30 days / Free spins and any winnings from the free spins are valid for 7 days from receipt. Max conversion: 1 time the bonus amount or from free spins: £20. Limited to 5 brands within the network. Withdrawal requests void all active/pending bonuses. Excluded Skrill and Neteller deposits. Full Terms apply

LuckyMe Slots
LuckyMe Slots

Bonus

50 Lucky Spins

  • Daily Promotions
  • Quick Cashouts
  • Daily Tournaments
18+. T&C’s Apply

Automatically credited on 1st Deposit (min £10). Game: Starburst, Spin Value: £0.1. WR 10x free spin winnings (only Slots count) in 30 days. Max bet is 10% (min £0.10) of the free spin winnings or £5 (lowest applies). Bonus Policy applies.