Skip to content
Back to Guavy Wire
Crypto

BlueNoroff Uses Fake Zoom Calls to Steal Crypto Wallets

Instruments
ETH SOL
Share

A North Korea-linked hacking group called BlueNoroff is using fake Zoom and Microsoft Teams meetings to identify cryptocurrency wallets before infecting them with malware.

The attackers compromise a Telegram account belonging to a genuine industry contact, which sends a meeting invitation to the victim. The victim then lands on a typosquatted Zoom or Teams page, enters their name, and grants webcam access, allowing the site to send the live camera feed to the attacker's control panel.

The attackers use this information to search for browser wallets through EIP-6963, window.ethereum, and non-EVM integrations such as Solana. They then transmit detected extensions and wallet providers to the operator before displaying a fake Zoom software development kit update.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc