COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: JUMPSEC reveals BlueNoroff hacks crypto wallets through fake meetings, over 100 victims hit
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > JUMPSEC reveals BlueNoroff hacks crypto wallets through fake meetings, over 100 victims hit
Cryptocurrency News

JUMPSEC reveals BlueNoroff hacks crypto wallets through fake meetings, over 100 victims hit

In Brief

  • 🚨 BlueNoroff screens crypto wallets and targets victims through fake Zoom and Teams calls.

  • 🕵️ Hackers leveraged hijacked Telegram accounts to send realistic meeting invites across crypto networks.

  • 👾 The JUMPSEC report found over 100 victims and links BlueNoroff to Lazarus’ operations in $ETH and other crypto assets.

  • 🌍 Most targets are in the United States or work in blockchain finance and cybersecurity.
İlayda Peker
İlayda Peker 1 day ago
Share
SHARE

The UK cyber security firm JUMPSEC has uncovered a sophisticated scheme operated by BlueNoroff, a North Korean-linked hacking group. The attackers screen crypto wallets before choosing victims and use fake Zoom and Microsoft Teams calls to set their schemes in motion.

Contents
BlueNoroff targets crypto wallet holders through tailored attacksDedicated malware for Windows and macOS platformsAttack scale and targets

BlueNoroff targets crypto wallet holders through tailored attacks

BlueNoroff, identified as a subgroup of North Korea’s notorious Lazarus Group, focuses on individuals who hold private keys to cryptocurrency wallets. JUMPSEC published an analysis of the hackers’ full source code this week after source maps were accidentally left accessible on a live server.

The exposed code details how the attack kit immediately scans a visitor’s browser when they enter the counterfeit meeting page. The kit searches for Ethereum wallet connections, including those based on the EIP-6963 standard and older browser methods.

The workflow also probes for non-Ethereum wallets such as Solana and sends the findings to a remote dashboard controlled by the attackers. Victims see no warning during the process. The malware maintains a list of browser extension IDs associated with popular wallets like MetaMask, allowing attackers to check for valuable targets before proceeding further.

Once a suitable wallet is detected, attackers decide whether to deploy a full exploit. Entry often begins with the takeover of a trusted contact’s Telegram account, which is then used to send plausible meeting invites via Calendly, leading new victims to the fake platform. The attack is designed to exploit trust within cryptocurrency networks, rapidly expanding the pool of victims.

Victims are greeted with requests for their names and webcam access once they join the call, handing the video stream to the hackers without their knowledge.

Mini dictionary: BlueNoroff, a hacking unit tied to North Korea’s Lazarus Group, is known for cyber-attacks targeting banks, cryptocurrency firms, and fintech organizations, with a track record of using advanced social engineering and malware payloads.

Following this, victims typically encounter a “waiting for other participants” screen, after which the attackers play a pre-recorded video message. Attackers exploit additional deception by presenting a message about the victim’s microphone not functioning, followed by a fake “Zoom SDK Update” prompt.

JUMPSEC’s investigation showed that attackers used AI-generated faces stitched onto body movements captured in earlier meetings to further legitimize the fake calls.

The meeting interfaces closely mimic legitimate Zoom and Teams layouts, with options such as emoji reactions and device settings. JUMPSEC also discovered an incomplete Google Meet clone within the attack kit’s codebase.

Dedicated malware for Windows and macOS platforms

BlueNoroff customizes its payloads for different operating systems. On Windows, once victims run the downloaded file, a PowerShell script executes a VBScript, which adds a permanent Microsoft Defender exclusion to evade detection. The malware then collects system details, identifies wallet extensions in web browsers, and harvests Telegram Web data. Security researchers have not recovered all possible payloads, as the loader is designed for additional downloads during the attack.

On macOS, the hackers distribute counterfeit Zoom or Teams installers, which run a hidden infostealer. This malware extracts system data and decrypts Chrome master keys stored in Apple’s Keychain, then transmits the information through Telegram. Multiple macOS versions of the attack have been observed since late April.

Both JUMPSEC and US-based cybersecurity provider Arctic Wolf have identified several versions of BlueNoroff’s phishing kits, finding five new versions shipped between May 31 and July 14. These kits are capable of full compromise in under five minutes. The growing sophistication in targeting and automation is evident from these rapid iterations.

Operating SystemAttack MethodData Stolen
WindowsPowerShell/VBScript loader, fake updatesWallet extensions, system info, Telegram files
macOSFake installers, hidden stealerSystem data, Chrome master keys

Attack scale and targets

Arctic Wolf’s research found more than 100 victims of BlueNoroff’s campaign across over 20 countries, with 41% located in the United States. Between April and mid-2026, at least 80 typosquatted meeting domains were registered. Approximately 80% of victims work in crypto or blockchain finance, and 45% are identified as founders or CEOs. The timing of phishing attempts was consistent with North Korean working hours, suggesting direct operational links.

Earlier investigations have highlighted BlueNoroff’s connections to broader Lazarus Group operations. Lazarus has previously targeted banks and crypto companies using tailored malware, such as fileless RemotePE trojans, typically deployed through Telegram contacts and fraudulent meeting links.

One victim described how their Telegram account was taken over and used to lure colleagues within the cryptocurrency sector into the same scheme.

You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

New York Attorney General urges tighter federal crypto oversight, warns against weakening state powers

Sberbank targets December launch for digital crypto custody and wallet

EGRAG CRYPTO revisits XRP’s broadening wedge, targets 43% and 57% gains

BitMEX and BitMart closures highlight growing crypto exchange consolidation

ESMA adds 15 crypto providers, BNY Mellon and BitPay enter MiCA registry

İlayda Peker 27 July, 2026 - 6:10 am 27 July, 2026 - 6:10 am
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
The author, who holds a degree in International Relations and Political Science, has 10 years of experience as a writer and editor in the fields of cryptocurrency, blockchain technologies, and digital asset markets.While at COINTURK, he has published over 8,500 news articles, analyses, essays, and reports on Bitcoin, altcoins, cryptocurrency markets, the blockchain ecosystem, digital asset regulations, and global financial developments. Closely following market movements and industry developments, the author addresses the complex world of cryptocurrency in a clear and reader-friendly manner.An avid reader, the author also evaluates the impact of international developments on financial markets and the digital asset ecosystem.
Previous Article Solana price targets $100 as tokenized stocks on network hit record holders
Next Article Stellar launches real-time analytics dashboard, XLM eyes $0.681 target
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

KOSPI plunges 11% as Samsung and SK Hynix slump, Bitcoin down 2.8%
Bitcoin (BTC)
Dogecoin trades at $0.07199, eyes breakout as open interest hits $1.15 billion
Dogecoin (DOGE)
Japan signals next wave of XRP adoption with regulatory and banking moves
Ripple (XRP)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?