North Korea's BlueNoroff Hackers Use Fake Meetings to Target Crypto Users
A North Korean hacking group has been using fake Zoom and Microsoft Teams meetings to target cryptocurrency users. The group, known as BlueNoroff, uses hijacked Telegram accounts to send meeting invites that lead to a phishing operation.
The attackers use the meetings to scan victims' browsers for wallet extensions tied to Ethereum, Solana, and other blockchain networks. They then prompt victims to install a fake 'SDK update' for Zoom or Teams, which triggers a ClickFix attack. This allows the attackers to gather system details and search specifically for Telegram data and browser wallet extensions.
The malware pulls a wide range of information from the infected device, including browser credentials, Chrome master keys, and full Telegram sessions. The attackers can potentially reuse the hijacked account to target victims' own contacts next.