North Korea-linked hacking group BlueNoroff has launched an advanced phishing scheme targeting cryptocurrency professionals through fake Zoom and Microsoft Teams meetings, according to the cybersecurity firm JUMPSEC. This operation uses sophisticated social engineering techniques and malware designed to steal crypto wallets and personal data.
Phishing attacks target trusted contacts
BlueNoroff, known for its connections to North Korean state-sponsored cybercrime, reportedly infiltrates Telegram accounts belonging to trusted individuals. Through these compromised accounts, the attackers send meeting invitations for supposed Zoom or Teams calls to intended targets within the crypto industry.
Once the victim joins the video conference, they are asked to enable their webcam while interacting in what appears to be a legitimate call. However, much of the meeting is staged, and many of the “participants” are prerecorded videos designed to make the setup convincing.
JUMPSEC reported that a BlueNoroff error exposed critical parts of the campaign’s JavaScript source code. This exposure allowed analysts to study the mechanics behind the phishing operation and track how victims were identified and attacked.
JUMPSEC identified that attackers exploit trusted communications channels by hijacking familiar Telegram accounts, then direct victims to highly realistic counterfeit platforms mimicking Zoom or Teams. The group conducts initial browser scans to identify valuable crypto wallet targets before deploying malware.
The counterfeit Zoom or Teams sites incorporate fake device settings, emoji reactions, and virtual backgrounds, especially on the Teams version, to make the deception more convincing for unwitting participants.
Before introducing any malicious code, the sites conduct browser scans looking for wallet extensions used on blockchain networks such as Ethereum and Solana. JUMPSEC stated this process lets BlueNoroff prioritize high-value targets with significant assets at risk.
Mini dictionary: BlueNoroff, a North Korea-backed hacking group, is connected to the larger Lazarus Group and has been involved in high-profile attacks on cryptocurrency exchanges and fintech companies worldwide.
Malware deployment through fake updates
If the group determines a target is worth pursuing, the platform prompts the victim to install a supposed “SDK update” to resolve a technical issue within Zoom or Teams. This request marks the beginning of what JUMPSEC categorizes as a ClickFix attack.
Victims are led to believe the update will solve technical problems, but clicking it executes malicious commands. Separate infection paths are used depending on whether the device runs Windows or macOS.
On Windows devices, malicious PowerShell scripts are activated, which retrieve additional malware, collect detailed system information, and target both Telegram data and crypto wallet browser extensions.
On macOS, what appears to be a typical installer is provided. While it simulates a routine installation process, a second-stage data stealer is simultaneously deployed in the background.
Systematic data theft and campaign expansion
The deployed malware is capable of looting browser credentials, Chrome master keys, and entire Telegram sessions. Stolen data includes cryptocurrency wallet keys and extensive device information. Because Telegram credentials are also compromised, attackers can further exploit victims’ networks by targeting their contacts.
JUMPSEC discovered that the phishing kit remains under development. Analysts identified several versions on the same infrastructure, along with an incomplete Google Meet variant, indicating plans to broaden the attack surface beyond just Zoom and Teams video calls.
Continual upgrades to the Teams interface suggest that BlueNoroff’s campaign is active and evolving, reflecting a persistent threat to the cryptocurrency sector. Social engineering tactics like fake job interviews and fake investor outreach have now expanded to the realm of fake meeting hosts.
The comprehensive report by JUMPSEC highlights how North Korea-linked actors employ increasingly sophisticated methods to deceive and compromise cryptocurrency industry professionals. The adoption of fake video calls as a phishing vector marks an escalation in both technical and social manipulation.
Hackers also target North Korea’s central bank
Separate reporting from Daily NK revealed that North Korean hackers targeting financial systems are not limited to international crime. Internal actors allegedly breached the networks of the Central Bank of Korea and the Foreign Trade Bank, converting stolen state funds into cryptocurrency for cross-border transfer.
Authorities reportedly broke up the operation in a July 12th raid in Pyongyang. The suspected ringleaders, said to be former soldiers from a cyber operations unit under the General Reconnaissance and Intelligence Bureau, purportedly recruited advanced IT students from top North Korean universities.
The group is accused of using Chinese communication gear and encrypted messaging apps to hide their actions, splitting the funds into smaller amounts for transfer to overseas wallets. The cryptocurrency was then exchanged through Chinese brokers back into cash and subsequently converted into US dollars or yuan near Sinuiju and Hyesan, border cities adjacent to China.
Investigators linked the illicit crypto flows to a residence in Pyongyang via analysis of transaction irregularities and foreign IP access records. A raid led to the arrest of the main perpetrators and IT personnel, and authorities seized computer equipment and burner phones used in the operation.
Mini dictionary: Daily NK is a Seoul-based online newspaper covering North Korean affairs, known for its sources inside the country and its reporting on Pyongyang’s internal developments.




