Lazarus Group Targets Crypto Investors on Telegram With Stealthy Malware
North Korea-linked Lazarus Group is conducting targeted social-engineering attacks on Telegram to compromise cryptocurrency investors, deploying memory-resident malware that leaves minimal forensic traces. Operators impersonate trading-firm staff and direct victims to phishing pages (mimicking Calendly, PicTime) to gain approvals and execute multi-stage, in-memory payloads that can drain wallets. The stealthy nature of these attacks increases the risk to large crypto holdings and could weigh on market sentiment and investor confidence—particularly for Bitcoin (BTCUSD) and other major tokens—if high-value thefts continue. Security recommendations include hardware wallets, MFA, careful identity verification, and memory-analysis scans. Overall, the campaign represents a direct security threat to crypto users and a potential negative catalyst for market sentiment.