Skip to content
Back to Guavy Wire
Crypto

North Korea's BlueNoroff Hackers Use Fake Meetings to Target Crypto Users

Instruments
ETH SOL
Share

A North Korean hacking group has been using fake Zoom and Microsoft Teams meetings to target cryptocurrency users. The group, known as BlueNoroff, uses hijacked Telegram accounts to send meeting invites that lead to a phishing operation.

The attackers use the meetings to scan victims' browsers for wallet extensions tied to Ethereum, Solana, and other blockchain networks. They then prompt victims to install a fake 'SDK update' for Zoom or Teams, which triggers a ClickFix attack. This allows the attackers to gather system details and search specifically for Telegram data and browser wallet extensions.

The malware pulls a wide range of information from the infected device, including browser credentials, Chrome master keys, and full Telegram sessions. The attackers can potentially reuse the hijacked account to target victims' own contacts next.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc