North Korean Hackers Use Fake Meetings to Steal Crypto Wallets
North Korea-linked hackers have been using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware. The hacking group, BlueNoroff, has created a phishing kit that supports Windows and macOS, stealing browser keys, system data, and Telegram sessions.
The attack often begins through a trusted industry peer's hijacked Telegram account, which sends a Calendly invitation to the victim, leading them to a lookalike meeting domain. BlueNoroff scans the victim's browser wallets before deciding which targets should receive its malware payload.
Researchers at cybersecurity firm JUMPSEC recovered and analyzed source code from an active phishing kit, revealing separate Zoom and Teams lures, wallet-scanning tools, operator controls, and malware delivery paths for Windows and macOS. The attack has been ongoing since April 22, with the operators changing their toolkit during the campaign.
JUMPSEC advised organizations to treat meeting links from trusted accounts with care, as the sender's account may already be compromised. They also recommended verifying unusual invitations through another channel, revoking exposed Telegram sessions, and isolating any device that ran the requested script.