North Korean Hackers Use Fake Video Meetings to Target Crypto Investors
A North Korean state-sponsored hacking group has developed a sophisticated campaign to target cryptocurrency investors. The BlueNoroff subgroup of the Lazarus Group uses fake video meetings to silently profile digital wallets before deploying malware.
The operation was detailed in a report by UK-based cybersecurity firm JUMPSEC, which gained rare visibility into the attack's inner workings after the threat actors inadvertently exposed JavaScript source maps on live command-and-control infrastructure.
The attackers hijack Telegram accounts belonging to genuine cryptocurrency professionals and use those compromised identities to send meeting invitations to the victim's existing contacts. The invitation directs targets to counterfeit Zoom or Microsoft Teams pages that look indistinguishable from the real platforms.