
North Korean hack group BlueNoroff hacked Canadian iGaming service via fake Zoom
North Korean cyber group BlueNoroff continues its global hunt for cryptocurrency and financial companies. This time, they targeted a Canadian iGaming operator. The attack, which began in the spring of 2025, was part of a large-scale campaign that affected companies around the world.
How the attack went
Everything looked as plausible as possible. The victim was informed about an alleged technical problem with sound during communication and was offered to install a fix through a special link on Zoom. But instead of the usual application, the person downloaded a malicious script disguised as a secure utility.
This script quietly installed spyware on the computer. The malware could steal logins, passwords, and access to crypto wallets, as well as open stable "backdoors" for further control over the system. At the same time, the software automatically deleted traces of its activity after the task was completed, which made it extremely difficult to detect the attack.
When and who else was attacked
The attack on the Canadian iGaming service began in March 2025. At the same time, experts have recorded similar schemes in the United States, South Korea, Japan, and several European countries.
Who is BlueNoroff
BlueNoroff is one of the key APT (Advanced Persistent Threat) groups associated with the DPRK government. Their main task is cyber espionage and the theft of digital assets to finance government projects, including weapons development programs. Previously, BlueNoroff has already been involved in a number of major attacks, including on banks and crypto exchanges.
This case in Canada is another confirmation that the iGaming industry, especially with elements of working with cryptocurrencies, is becoming an increasingly attractive target for international cybercriminals.




celese Haha, classic! First they screwed over the players, then the license turned out to be fake, and now they’re trying to undo everything. A total circus. Yeah, everything will just get bought. They’ll pay whoever they need in Curaçao and get a new license. Money rules everything, especially in this industry.



Mangarin4ik The section about how casinos fire VPNs is a gun. I've never thought about WebRTC and the time zone. Author, thank you, you may have just saved my next deposit.

I've read about them before. These guys are not joking, they have a whole cyber army on funding.
Haha, BlueNoroff sounds like the name of a rave band, not a hacker.
I wish at least once these hackers hacked something useful, like they wrote off everyone's loans.
In general, I'm always afraid to open left-wing links. And then there's Zoom, which seems to be a normal thing.
Horrible.