COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: BlueNoroff uses fake Zoom, Teams calls to target crypto wallets, North Korea bank hacked
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > BlueNoroff uses fake Zoom, Teams calls to target crypto wallets, North Korea bank hacked
Cryptocurrency News

BlueNoroff uses fake Zoom, Teams calls to target crypto wallets, North Korea bank hacked

In Brief

  • 🚨 BlueNoroff launches fake Zoom and Teams calls to steal crypto wallets.

  • 🔒 Hackers scan for wallet extensions and spread malware through fake updates.

  • 🕵️ Stolen Telegram accounts are used to target other crypto professionals in $ETH.

  • 🌏 North Korean hackers also breached their own central bank, converting funds into crypto.
Onur Atam
Onur Atam 3 hours ago
Share
SHARE

North Korea-linked hacking group BlueNoroff has launched an advanced phishing scheme targeting cryptocurrency professionals through fake Zoom and Microsoft Teams meetings, according to the cybersecurity firm JUMPSEC. This operation uses sophisticated social engineering techniques and malware designed to steal crypto wallets and personal data.

Contents
Phishing attacks target trusted contactsMalware deployment through fake updatesSystematic data theft and campaign expansionHackers also target North Korea’s central bank

Phishing attacks target trusted contacts

BlueNoroff, known for its connections to North Korean state-sponsored cybercrime, reportedly infiltrates Telegram accounts belonging to trusted individuals. Through these compromised accounts, the attackers send meeting invitations for supposed Zoom or Teams calls to intended targets within the crypto industry.

Once the victim joins the video conference, they are asked to enable their webcam while interacting in what appears to be a legitimate call. However, much of the meeting is staged, and many of the “participants” are prerecorded videos designed to make the setup convincing.

JUMPSEC reported that a BlueNoroff error exposed critical parts of the campaign’s JavaScript source code. This exposure allowed analysts to study the mechanics behind the phishing operation and track how victims were identified and attacked.

JUMPSEC identified that attackers exploit trusted communications channels by hijacking familiar Telegram accounts, then direct victims to highly realistic counterfeit platforms mimicking Zoom or Teams. The group conducts initial browser scans to identify valuable crypto wallet targets before deploying malware.

The counterfeit Zoom or Teams sites incorporate fake device settings, emoji reactions, and virtual backgrounds, especially on the Teams version, to make the deception more convincing for unwitting participants.

Before introducing any malicious code, the sites conduct browser scans looking for wallet extensions used on blockchain networks such as Ethereum and Solana. JUMPSEC stated this process lets BlueNoroff prioritize high-value targets with significant assets at risk.

Mini dictionary: BlueNoroff, a North Korea-backed hacking group, is connected to the larger Lazarus Group and has been involved in high-profile attacks on cryptocurrency exchanges and fintech companies worldwide.

Malware deployment through fake updates

If the group determines a target is worth pursuing, the platform prompts the victim to install a supposed “SDK update” to resolve a technical issue within Zoom or Teams. This request marks the beginning of what JUMPSEC categorizes as a ClickFix attack.

Victims are led to believe the update will solve technical problems, but clicking it executes malicious commands. Separate infection paths are used depending on whether the device runs Windows or macOS.

On Windows devices, malicious PowerShell scripts are activated, which retrieve additional malware, collect detailed system information, and target both Telegram data and crypto wallet browser extensions.

On macOS, what appears to be a typical installer is provided. While it simulates a routine installation process, a second-stage data stealer is simultaneously deployed in the background.

Systematic data theft and campaign expansion

The deployed malware is capable of looting browser credentials, Chrome master keys, and entire Telegram sessions. Stolen data includes cryptocurrency wallet keys and extensive device information. Because Telegram credentials are also compromised, attackers can further exploit victims’ networks by targeting their contacts.

JUMPSEC discovered that the phishing kit remains under development. Analysts identified several versions on the same infrastructure, along with an incomplete Google Meet variant, indicating plans to broaden the attack surface beyond just Zoom and Teams video calls.

Continual upgrades to the Teams interface suggest that BlueNoroff’s campaign is active and evolving, reflecting a persistent threat to the cryptocurrency sector. Social engineering tactics like fake job interviews and fake investor outreach have now expanded to the realm of fake meeting hosts.

The comprehensive report by JUMPSEC highlights how North Korea-linked actors employ increasingly sophisticated methods to deceive and compromise cryptocurrency industry professionals. The adoption of fake video calls as a phishing vector marks an escalation in both technical and social manipulation.

Hackers also target North Korea’s central bank

Separate reporting from Daily NK revealed that North Korean hackers targeting financial systems are not limited to international crime. Internal actors allegedly breached the networks of the Central Bank of Korea and the Foreign Trade Bank, converting stolen state funds into cryptocurrency for cross-border transfer.

Authorities reportedly broke up the operation in a July 12th raid in Pyongyang. The suspected ringleaders, said to be former soldiers from a cyber operations unit under the General Reconnaissance and Intelligence Bureau, purportedly recruited advanced IT students from top North Korean universities.

The group is accused of using Chinese communication gear and encrypted messaging apps to hide their actions, splitting the funds into smaller amounts for transfer to overseas wallets. The cryptocurrency was then exchanged through Chinese brokers back into cash and subsequently converted into US dollars or yuan near Sinuiju and Hyesan, border cities adjacent to China.

Investigators linked the illicit crypto flows to a residence in Pyongyang via analysis of transaction irregularities and foreign IP access records. A raid led to the arrest of the main perpetrators and IT personnel, and authorities seized computer equipment and burner phones used in the operation.

Mini dictionary: Daily NK is a Seoul-based online newspaper covering North Korean affairs, known for its sources inside the country and its reporting on Pyongyang’s internal developments.

You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

99 crypto projects shut down in 2026, RootData reports

Sberbank to launch crypto trading platform and digital depository by December 2026

US Treasury adds ZEDX DMCC, ZedPay, BZ Diamond to Babak Zanjani sanctions list

Massachusetts Senate approves crypto ATM ban in economic bill after $7 million scam losses

MoonPay adds Discover card support for crypto payments in the US

Onur Atam 26 July, 2026 - 3:08 pm 26 July, 2026 - 3:08 pm
Share This Article
Facebook Twitter
Share
Onur Atam
By Onur Atam
Follow:
The author, who is an attorney, specializes primarily in Information Technology Law and Commercial Law. His areas of interest include internet technologies, the cryptocurrency ecosystem, blockchain applications, and next-generation financial technologies.He closely follows developments in digital assets, cryptocurrency regulations, fintech applications, e-commerce, data security, and areas where technology intersects with the law. His goal is to provide a clear and accessible analysis of current developments in the fields of cryptocurrency and financial technologies from a legal perspective.
Previous Article Shiba Inu jumps 35% this week as SHIB short sellers face $2.3 million in liquidations
Next Article AVAX jumps 8% as short squeeze and altcoin inflows drive breakout
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Hyperliquid rises 2.25% as HYPE trades above key $50 support
Hyperliquid (HYPE)
XRP analyst EGRAG CRYPTO eyes $8.30 target after major breakout signal
Ripple (XRP)
1.16 trillion SHIB exits Coinbase wallets in record transfers, price unmoved
Coinbase
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?