North Korea-affiliated group BlueNoroff has launched a sophisticated scheme using counterfeit Zoom and Microsoft Teams meetings to identify and attack cryptocurrency users. The campaign begins by hijacking trusted Telegram accounts within the crypto community, then sending fake meeting invites that lead victims into phishing traps.

How the Scam Works

Once a victim joins the fake meeting, their browser is scanned for connected crypto wallets. The malware looks for Ethereum wallets using EIP-6963 and other methods, as well as non-EVM wallets like those on Solana. This information is quietly sent to an operator panel, allowing attackers to prioritize high-value targets before deploying malware.

The phishing kit supports both Windows and macOS, stealing browser wallet keys, system data, and Telegram session details. On Windows devices, it even checks installed browser extensions across multiple browsers to detect popular wallet tools like MetaMask. This profiling step distinguishes the attack from typical broad phishing attempts by tailoring the malware delivery based on wallet presence.

Building Trust with Fake Meetings

Victims are greeted with realistic fake meeting pages that ask for their name and webcam access. The attackers stream the victim’s camera feed to their control panel and simulate waiting for other participants. They use AI-generated headshots combined with real video snippets to impersonate familiar faces. Operators can send messages such as “your mic isn’t working” and prompt fake software updates to keep the target engaged.

In many cases, the initial contact comes through a Telegram account previously compromised by BlueNoroff, which helps the group reach trusted contacts and expand their victim pool. This creates a chain reaction where each hacked account leads to more targets.

Cybersecurity firm JUMPSEC analyzed leaked source code from the phishing infrastructure, revealing the detailed mechanisms behind the wallet scanning and malware deployment. The precision of this operation marks a significant escalation in how state-linked hackers are targeting cryptocurrency holders.

This material is for informational purposes and does not constitute financial advice.