00:00
The Financial Ways
The Financial Ways
USD/RUB
EUR/RUB
Cryptocurrency

BlueNoroff hackers use fake video calls to profile crypto wallets

A North Korea-linked hacking group is weaponizing fake Zoom and Microsoft Teams meetings to harvest cryptocurrency assets. By compromising trusted Telegram accounts, attackers lure industry professionals into meetings where they silently scan browser-based wallets for high-value targets before deploying custom malware payloads designed for Windows and macOS.

BlueNoroff hackers use fake video calls to profile crypto wallets

Cybersecurity firm JUMPSEC uncovered the operation after analyzing source code exposed on the group’s live infrastructure. The campaign relies on a sophisticated pipeline: hackers hijack Telegram accounts to send Calendly invitations, guiding victims to lookalike meeting domains. Once a user joins the fake call, the site automatically scans the browser for Ethereum and Solana wallet connections. This data is fed to an operator panel, allowing attackers to prioritize victims holding significant assets.

The attackers enhance credibility by using AI-generated avatars and recorded footage to simulate live participants, often prompting targets to install a fake "Zoom SDK Update." On Windows, this trigger executes a PowerShell loader that modifies Microsoft Defender settings to maintain persistence. The macOS variant focuses on exfiltrating Chrome master keys and system information via the Apple Keychain. Researchers identified four distinct macOS malware versions deployed between April and July, signaling a rapid, iterative development process.

This activity builds on previous campaigns where BlueNoroff targeted blockchain executives with similar lures. Because the attackers operate through compromised accounts, standard caution is often insufficient. Security experts recommend verifying meeting links through secondary channels and monitoring for suspicious PowerShell activity or unauthorized modifications to system security settings, as password resets do not neutralize existing session theft.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!