North Korean Hackers Impersonate Zoom to Breach Online Gambling Firm

This guide provides a comprehensive overview of the world of online gambling, detailing the essential steps and platforms required to navigate the digital betting landscape.

North Korean Hackers Attempt to Breach an Online Gambling Firm

  • Hackers used deepfakes in a spoofed Zoom meeting
  • Victim ran fake support script that installed malware
  • Attackers stole credentials, crypto data, and messaging info

A representative from a Canadian online gambling provider was duped into believing they were on a routine Zoom call. In reality, they were communicating with North Korean hackers using a spoofed version of the communications platform.

online gaming
Image by vinsky2002 from Pixabay

This attack, which originated on May 28, was executed by BlueNoroff, a subgroup of the infamous North Korea-backed hacking group, Lazarus Group, as reported by analysts from Field Effect Analysis.

BlueNoroff is known as a financially motivated threat actor, typically targeting banks, cryptocurrency exchanges, and businesses in the gaming and fintech sectors to generate revenue for North Korea. Since 2017, they have amassed over US$1.3 billion through various tactics, including SWIFT banking thefts and cryptocurrency heists.

Deep Fake Technology in Action

According to Field Effect, the hackers designed a counterfeit website masquerading as an official Zoom support page to ensnare the targeted gambling company. By using deepfake technology, they successfully imitated a legitimate business contact to arrange the Zoom meeting.

During the meeting, the attackers created the illusion of audio problems, prompting the victim to run a supposed “Zoom audio repair script.” However, this script was in fact a form of malware.

Once activated, the malware initiated a series of downloads and commands that ultimately prompted the victim for their system credentials, silently installing multiple malicious payloads. This breach allowed the hackers access to a wide range of sensitive personal and system-related data, focusing heavily on cryptocurrency assets and messages.

This specific incident appears to be a part of a larger Zoom spoofing campaign, which was first documented in March 2025 and has predominantly targeted cryptocurrency firms, as highlighted by Field Effect.

“This demonstrates an ongoing trend where profit-driven hackers refine their methods, embedding malice within trusted business environments and exploiting user reliance as a key attack point,” the analysts reported.

Historical Context: The Bangladesh Bank Heist

BlueNoroff’s most notorious operation occurred in February 2016, wherein they successfully infiltrated the Bangladesh Bank’s servers. This breach granted them the credentials necessary to authorise 35 fraudulent transfer requests from the New York Federal Reserve, amounting to nearly $1 billion.

Of the 35 payments, US$101 million was processed before suspicions arose at the New York Fed, effectively stopping any further transactions.

Approximately $20 million was recovered and returned to Sri Lanka, but the majority of the funds were laundered through multiple accounts at the Philippine bank RCBC, swiftly opened under fictitious names, and subsequently converted into cash at VIP casino gaming tables, ultimately disappearing without a trace.

This troubling trend raises significant concerns about the security measures in place across the online gambling sector, particularly as cybercriminals continue to evolve and adapt their strategies.

For online gambling companies, staying informed about the latest cyber threats and implementing robust cybersecurity measures is crucial. Cybersecurity resources, continuous employee training, and incident response plans can help mitigate potential attacks.

In summary, this case highlights the increasing sophistication of cyber threats facing the online gaming industry, showcasing the need for ongoing vigilance and proactive measures to protect sensitive information.