BlueNoroff Uses Fake Zoom Calls to Steal Crypto Wallets
A North Korea-linked hacking group called BlueNoroff is using fake Zoom and Microsoft Teams meetings to identify cryptocurrency wallets before infecting them with malware.
The attackers compromise a Telegram account belonging to a genuine industry contact, which sends a meeting invitation to the victim. The victim then lands on a typosquatted Zoom or Teams page, enters their name, and grants webcam access, allowing the site to send the live camera feed to the attacker's control panel.
The attackers use this information to search for browser wallets through EIP-6963, window.ethereum, and non-EVM integrations such as Solana. They then transmit detected extensions and wallet providers to the operator before displaying a fake Zoom software development kit update.