North Korea's BlueNoroff group hijacked Telegram accounts of crypto professionals and lured them into fake Zoom and Teams meetings to deploy wallet-draining malware.
North Korea's BlueNoroff group hijacked Telegram accounts of crypto professionals and lured them into fake Zoom and Teams meetings to deploy wallet-draining malware.

North Korea's BlueNoroff group hijacked Telegram accounts of crypto professionals and used fake Zoom and Teams meetings to deploy malware, with 164 blocked domains tied to the campaign since February.
"This looks like a sustained campaign, not a one-off effort," JUMPSEC researchers said in a July report that reconstructed the phishing kit from exposed JavaScript source maps.
The kit scans browsers for wallet extensions tied to Ethereum, Solana and other networks before selectively deploying malware to high-value targets. On Windows machines, PowerShell scripts disable defenses and pull down additional payloads; on macOS, a fake installer loads a second-stage stealer in the background while the app appears to install normally.
The campaign shows how Pyongyang's state-sponsored crews have shifted from exploiting software flaws to exploiting human trust. North Korean groups stole $2.02 billion in digital assets during 2025, a 51% jump from the prior year, according to CrowdStrike, pushing Pyongyang's running total past $6 billion since 2017.
The attack chain begins when a compromised Telegram account belonging to a trusted industry contact sends a meeting link. The link leads to a lookalike domain built to mimic Zoom or Microsoft Teams. Victims who join the call may see pre-recorded participants on screen while an operator watches their live camera feed.
Before any malware is deployed, the platform quietly scans the victim's browser for wallet extensions. This profiling step lets BlueNoroff filter out low-value targets and focus only on people worth attacking further, according to JUMPSEC.
Once the scan finishes, victims are prompted to install a fake "SDK update" for Zoom or Teams. Clicking it triggers what researchers call a ClickFix attack — the victim is tricked into running commands they believe will fix a technical glitch.
The malware captures browser credentials, Chrome master keys, full Telegram sessions and cryptocurrency wallet data. Because Telegram sessions are stolen, attackers can reuse the hijacked account to target the victim's own contacts next.
Google Mandiant independently documented a similar intrusion in February, tracking the actor as UNC1069 and confirming overlap with BlueNoroff. The U.S. Treasury has formally designated BlueNoroff, also known as APT38, as a North Korean state-sponsored group controlled by the Reconnaissance General Bureau.
Security Alliance attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7, describing multi-week social engineering through Telegram, LinkedIn and Slack before fraudulent meeting links were delivered. JUMPSEC said campaign infrastructure remained active as of July 22.
The threat extends beyond fake meetings. Kaspersky researchers linked the March 2026 supply chain attack on the Axios JavaScript library — which averages more than 100 million weekly downloads on npm — to BlueNoroff, citing shared technical fingerprints with the GhostCall and GhostHire campaigns.
The FBI has warned that North Korean actors conduct highly tailored social engineering against cryptocurrency and DeFi employees. Its guidance flags requests to execute code, install unfamiliar applications or run scripts to fix video calls, and recommends verifying identities through an independent channel.
This article is for informational purposes only and does not constitute investment advice.