North Korea-Linked Hackers Target Bitcoin Professionals with Hijacked Telegram Accounts
North Korean hackers are behind a sophisticated social-engineering campaign that targets Bitcoin and cryptocurrency professionals through hijacked Telegram accounts.
The attack, attributed to UNC1069 (also known as BlueNoroff), involves compromised Telegram contacts inviting victims to fake video meetings on Zoom or Microsoft Teams.
JUMPSEC researchers found that the phishing kit profiles cryptocurrency wallets before delivering malware to selected targets on Windows and macOS systems.
The FBI warns that North Korean actors conduct highly tailored social engineering against crypto employees, advising them to verify identities through an independent channel and keep wallet credentials off internet-connected devices.
While there is no universal method for the initial Telegram takeover, researchers confirm compromised accounts, and users are advised to treat unexpected meeting requests as high-risk signals.