BitcoinWorld Lazarus Group Targets Crypto Investors on Telegram With Stealthy Malware The North Korean-linked Lazarus Group is actively targeting cryptocurrencyBitcoinWorld Lazarus Group Targets Crypto Investors on Telegram With Stealthy Malware The North Korean-linked Lazarus Group is actively targeting cryptocurrency

Lazarus Group Targets Crypto Investors on Telegram With Stealthy Malware

2026/05/26 09:40
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

BitcoinWorld

Lazarus Group Targets Crypto Investors on Telegram With Stealthy Malware

The North Korean-linked Lazarus Group is actively targeting cryptocurrency investors through sophisticated social engineering attacks on Telegram, according to a recent report. The hackers are deploying memory-based malware that leaves minimal forensic traces, making detection exceptionally difficult for victims and security teams alike.

How the Attacks Unfold

Lazarus Group operatives pose as employees of legitimate trading firms on Telegram, initiating direct conversations with potential victims. They guide targets to phishing websites that mimic popular scheduling platforms such as Calendly and PicTime. Once a victim interacts with these fake sites and grants approval, the attackers install malware in multiple stages, bypassing traditional security measures.

The operation relies on a “human-in-the-loop” approach, where attackers build trust through direct, personalized interaction. This social engineering layer is critical to persuading victims to execute malicious files, which then compromise their systems and cryptocurrency holdings.

Memory-Based Malware: A Stealthy Threat

The malware used in these campaigns resides solely in the computer’s memory, leaving no permanent files on the hard drive. This technique allows it to evade signature-based antivirus tools and forensic analysis that relies on disk-based artifacts. For crypto investors, the risk is significant: funds can be drained without any obvious signs of intrusion.

Security researchers have noted that the Lazarus Group has refined its tactics over time, moving from more detectable exploits to these memory-resident attacks. The group is known for targeting high-value individuals and organizations in the cryptocurrency space, often netting millions of dollars per operation.

Why This Matters for Crypto Investors

The cryptocurrency industry has long been a prime target for North Korean cyber operations, which provide a crucial source of revenue for the regime. These attacks underscore the importance of verifying the identity of anyone requesting sensitive actions, even on trusted platforms like Telegram. Investors should be wary of unsolicited messages from individuals claiming to represent trading firms, especially when they request file downloads or access to scheduling platforms.

Security experts recommend using hardware wallets for large holdings, enabling multi-factor authentication on all accounts, and never executing files from unknown sources. Regular system scans with memory-analysis tools can also help detect memory-resident threats.

Conclusion

The Lazarus Group’s latest campaign on Telegram represents a significant evolution in social engineering tactics, combining trust-building with stealthy malware to target crypto investors. As these attacks grow more sophisticated, awareness and proactive security measures remain the best defense. The broader cryptocurrency community must remain vigilant against such state-sponsored threats.

FAQs

Q1: What is the Lazarus Group?
The Lazarus Group is a cybercrime organization linked to the North Korean government. It is known for conducting high-profile hacks and thefts, particularly targeting financial institutions and cryptocurrency exchanges to generate revenue for the regime.

Q2: How can I protect myself from these Telegram scams?
Never trust unsolicited messages from supposed trading firm employees. Verify identities through official channels, avoid clicking on links from unknown senders, and never execute files or grant permissions to scheduling platforms without confirming legitimacy. Use hardware wallets and enable multi-factor authentication.

Q3: What is memory-based malware?
Memory-based malware runs entirely in a computer’s RAM without writing files to the hard drive. This makes it harder to detect with traditional antivirus software and forensic tools, as it leaves no persistent traces. It can be removed by rebooting the system, but the damage may already be done.

This post Lazarus Group Targets Crypto Investors on Telegram With Stealthy Malware first appeared on BitcoinWorld.

AI Strategy: Powered 24/7

AI Strategy: Powered 24/7AI Strategy: Powered 24/7

Generate automated strategies using natural language

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Crypto selloff deepens with $400 million liquidations and rising short interest

Crypto selloff deepens with $400 million liquidations and rising short interest

The post Crypto selloff deepens with $400 million liquidations and rising short interest appeared on BitcoinEthereumNews.com. Bitcoin BTC$66,444.55 gave back a
Share
BitcoinEthereumNews2026/04/02 19:02
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Gold Spot Volume on Binance Surges to $80M as Demand Extends Beyond Futures

Gold Spot Volume on Binance Surges to $80M as Demand Extends Beyond Futures

TLDR: Gold spot trading on Binance reached nearly $80M shortly after launch, showing rapid market adoption. Despite a 15% correction, gold continues attracting
Share
Blockonomi2026/04/02 18:18

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!