BlueNoroff's Fake Meetings Scam Targets Crypto Professionals Worldwide
North Korea's BlueNoroff hacking unit is targeting crypto professionals with fake Zoom and Microsoft Teams meetings. The operation, which has already compromised over 100 victims across more than 20 countries, uses a technique called typosquatting to create domains that look almost identical to legitimate meeting platforms.
The attackers send spear-phishing messages through compromised Telegram accounts or Calendly invitations that appear routine. When the victim clicks on the link, they are directed to a counterfeit meeting page that exfiltrates webcam footage and launches a ClickFix clipboard attack, which hijacks the victim's clipboard to inject malicious commands.
The malicious site then harvests credentials from cryptocurrency wallet extensions like MetaMask in under five minutes. According to research, 80% of victims work in crypto or blockchain finance, and 45% are CEOs or founders.