North Korea hackers scan crypto wallets through fake Zoom calls

1 hour ago 1



BlueNoroff scans browser wallets before deciding which fake meeting targets should receive its malware payload. Hijacked Telegram accounts help attackers contact trusted industry peers and extend the campaign through victims. The phishing kit supports Windows and macOS, stealing browser keys, system data, and Telegram sessions. North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware. Cybersecurity firm JUMPSEC said it recovered and analysed source code from an active phishing kit after its operators exposed JavaScript source maps on live infrastructure. The files showed separate Zoom and Teams lures, wallet-scanning tools, operator controls and malware delivery paths for Windows and macOS. The attack often begins through a Telegram account that the target already trusts. The hackers take over accounts belonging to crypto contacts, then send a Calendly invitation that leads to a lookalike meeting domain. JUMPSEC described the system as a repeatable victim pipeline because one stolen Telegram session can help the attackers contact the next group of targets. BlueNoroff checks crypto wallets b...

Read Entire Article