Close Menu
    Facebook X (Twitter) Instagram
    Thursday, July 3
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » Manta Network co-founder targeted by Lazarus in Zoom phishing attack
    Crypto

    Manta Network co-founder targeted by Lazarus in Zoom phishing attack

    James WilsonBy James WilsonApril 18, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Manta Network co-founder Kenny Li narrowly escaped a Zoom phishing attack, suspected to be orchestrated by Lazarus.

    In his April 17 X post, Kenny Li said that he had been targeted by Lazarus in a Zoom meeting. It started with a known contact asking Li for a chat via Zoom. When Li got on Zoom, the meeting looked legitimate, with the other party having their camera on and their face visible. However, there was no audio on the call, and Li was prompted to download a suspicious script file under the guise of a Zoom update.

    🚨 Just got targeted by Lazarus.

    A known contact on TG reached out to me to ask for a chat. Scheduled a Zoom call. When I got on the Zoom, it asked me for camera access which I found a bit odd because I have used Zoom many times.

    Even crazier, the team members had their…

    — 🤓Kenny.manta (@superanonymousk) April 17, 2025

    Suspecting something was off, Li tried to verify the participant’s identity by suggesting they switch to Google Meet or speak on Telegram. The impersonator refused, then quickly deleted all messages and blocked him.

    Li later confirmed that the real person whose identity was used in the video call had their accounts compromised by Lazarus.

    This isn’t the first time Lazarus has used Zoom as a phishing vector. Nick Bax from the Security Alliance highlighted this scam in a March 11 X post. He explained that it usually starts with a few “VCs” on the call, who claim to have audio issues and claim the victim cannot hear them. If the victim falls for it, they’re directed to a new Zoom room via a fake link, where they’re prompted to download a “patch” to resolve the audio/video problem. Bax noted that this method has been used by threat groups to steal millions of dollars, and other hackers are now replicating these tactics.

    Having audio issues on your Zoom call? That’s not a VC, it’s North Korean hackers.

    Fortunately, this founder realized what was going on.

    The call starts with a few “VCs” on the call. They send messages in the chat saying they can’t hear your audio, or suggesting there’s an… pic.twitter.com/ZnW8Mtof4F

    — Nick Bax.eth (@bax1337) March 11, 2025

    In the thread, several crypto founders shared similar experiences to Kenny Li of Manta Network (MANTA), recounting how they too narrowly avoided falling victim to these Zoom phishing scams.

    Giulio Xiloyannis, co-founder of the blockchain gaming firm Mon Protocol, recounted an attempted scam where the hacker posed as the project lead from Story Protocol (IP) to lure him and his marketing lead into a fake meeting. The deception became clear when he was abruptly asked to join a new Zoom link that faked audio issues in an attempt to get him to download malware.

    David Zhang, co-founder of the stablecoin platform Stably, also faced a similar attack. Initially, the scammers joined his Google Meet call but then fabricated a reason to switch to a different meeting link. Zhang took the call on his tablet, which may have prevented the malware from functioning properly. He suspects the phishing attempt was designed to identify the user’s operating system and adapt accordingly, but the setup wasn’t optimized for mobile devices.

    Melbin Thomas, founder of Devdock AI, also fell victim to the Zoom scam but didn’t enter his password during the fake installation process. Then, he went offline and did a factory reset. However, he’s still not sure whether the files are safe, as he transferred them to a hard drive that hasn’t been reconnected to his system.

    The same thing happened to me. But didnt give my password while the install was happening.
    Disconnecte my laptop and I reset to factory settings. But transferred my files to a hard drive. I have not connected the hard drive back to my laptop. Is it still infected? @_SEAL_Org

    — Melbin (melbin.eth) (@melbint04) March 12, 2025

    This surge in attacks follows a joint warning from the US, Japan, and South Korea in January about the increasing threat of the Lazarus Group targeting the crypto industry. The Lazarus Group, known for its involvement in high-profile cyber thefts like the Bybit and Ronin network hacks, is suspected to be behind these attacks.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHashKey Capital launches Asia’s first XRP Tracker Fund
    Next Article Crypto exchange Kraken to add support for Binance-backed BNB token
    James Wilson

    Related Posts

    Move over Dogecoin — 7 picks under $0.50 to watch

    July 3, 2025

    No crypto wins in Trump’s ‘big beautiful bill,’ but market eyes liquidity boost

    July 3, 2025

    Under‑$0.002 gem could 500x before Cardano reclaims $3

    July 3, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Move over Dogecoin — 7 picks under $0.50 to watch

    No crypto wins in Trump’s ‘big beautiful bill,’ but market eyes liquidity boost

    Under‑$0.002 gem could 500x before Cardano reclaims $3

    Telegram’s blockchain developer joins unicorn ranks at $1b valuation

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    Move over Dogecoin — 7 picks under $0.50 to watch

    July 3, 2025

    No crypto wins in Trump’s ‘big beautiful bill,’ but market eyes liquidity boost

    July 3, 2025

    Under‑$0.002 gem could 500x before Cardano reclaims $3

    July 3, 2025
    Lithosphere News Releases

    Imagen AI (IMAGE) Developer to Enable Ripple Labs Stablecoin RLUSD for Service Payments

    July 3, 2025

    Imagen Network Begins Strategic Expansion with Bitcoin-Funded AI Infrastructure Rollout

    July 2, 2025

    AGII Enhances Real-Time Protocol Safety With Predictive Automation Models

    July 2, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.