Back to news

North Korean Hackers Profile Crypto Wallets via Fake Zoom; LG Bans TV Proxy Apps

Two separate threat vectors emerged this week: a North Korean phishing operation targeting crypto holders through spoofed video-call platforms, and a widespread residential proxy scheme hiding inside LG smart TV apps.

North Korean Hackers Profile Crypto Wallets via Fake Zoom; LG Bans TV Proxy Apps

What happened

BlueNoroff, a financially motivated hacking group linked to North Korea, has been running a structured phishing kit that impersonates Zoom and Microsoft Teams through lookalike domains registered with deliberate typosquatting. The operation goes beyond generic credential theft — attackers first profile targets' cryptocurrency wallet holdings before deploying malware, using compromised industry contacts to make initial outreach appear legitimate. Separately, security researchers disclosed that more than 42 percent of apps available on LG's webOS smart TV store were quietly routing user internet traffic through residential proxy networks on behalf of unknown third parties. LG has since announced it will suspend any application on its platform found to operate this way.

Why it matters for your business

The BlueNoroff campaign is notable for its pre-attack reconnaissance: by sizing up a target's wallet before dropping malware, the group maximizes return per victim and avoids burning infrastructure on low-value targets — a level of operational discipline that raises the threat ceiling for crypto-adjacent businesses, DAOs, and treasury managers. Any organization holding digital assets should treat unsolicited Zoom or Teams meeting invitations with heightened skepticism, verify domain spelling before entering credentials, and enforce endpoint detection capable of catching post-exploitation activity. The LG proxy story is a reminder that consumer hardware in office break rooms, lobbies, or executive suites can become silent relay nodes — a practical reason to segment IoT and smart-display devices from core corporate networks.

What to watch next

Regulators and platform operators have begun scrutinizing app-store ecosystems beyond mobile devices, and LG's enforcement action could pressure rival smart TV vendors — Samsung, Sony, and Roku among them — to audit their own stores for similar proxy SDK behavior. On the threat-actor side, BlueNoroff's targeting of crypto wallets tracks with broader DPRK efforts to fund state programs through digital-asset theft, a trend unlikely to slow as sanctions tighten. Organizations should monitor whether additional videoconferencing brands appear in BlueNoroff's spoofed-domain infrastructure as the campaign continues to evolve.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp