North Korea-Linked BlueNoroff Targets Crypto Professionals With Fake Zoom and Teams Meeting Links
Key Takeaways
- •The campaign relies on compromised Telegram accounts to send malicious meeting invitations to trusted contacts in the crypto industry.
- •Victims are directed to fake Zoom or Microsoft Teams pages that prompt installation of a fraudulent SDK update delivering malware.
- •The malware targets both Windows and macOS systems and can collect wallet credentials, Telegram session data, and system information.
- •JUMPSEC said the operation is ongoing but did not disclose the number of victims or the amount stolen.
- •The campaign reflects a shift toward targeting individuals such as developers, traders, and project founders who may control valuable credentials or treasury access.

Cybersecurity firm JUMPSEC has identified a phishing campaign attributed to the North Korea-linked BlueNoroff group that uses weaponized meeting links disguised as Zoom and Microsoft Teams invitations to compromise cryptocurrency professionals, according to an original report.
The campaign does not target blockchains directly. Instead, attackers exploit trust relationships by hijacking Telegram accounts, sending malicious meeting links to the compromised account’s contacts, and then prompting targets to install a fake “SDK update.” JUMPSEC said the installation can lead to a full system compromise.
Once deployed, the malware affects both Windows and macOS systems. It scans for wallet credentials stored in browsers, extracts Telegram session data, and collects system information. The apparent objective is to drain wallets and impersonate victims to continue spreading the attack.
BlueNoroff has long been described as a persistent subgroup of the Lazarus Group, which has been associated with financial and cryptocurrency theft. The latest campaign shows how social engineering remains a significant attack vector in an industry where a single private key may control substantial value, and where day-to-day business discussions often move quickly across messaging apps and video-call links.
Attack Pattern and Implications
The campaign typically begins with a hijacked Telegram account. Contacts who already trust the compromised account receive a message that appears legitimate, often referring to a call about an investment, token launch, or partnership.
The link sends the target to a page designed to resemble a Zoom or Microsoft Teams lobby. The page then asks the user to update an SDK component. That fake updater delivers the malware payload.
By abusing Telegram’s infrastructure and the victim’s existing trust network, the attackers can evade common phishing defenses. JUMPSEC’s disclosure indicates that even technically experienced crypto professionals have been caught by the tactic.
The dual-platform nature of the malware increases the risk. Both Windows and macOS users are targeted, meaning users are not protected simply by their choice of operating system. The malware’s focus on browser-stored keys and hot wallet extensions also means that hardware wallet users who interact with decentralized applications through browsers can remain exposed if session tokens or related credentials are compromised.
The campaign highlights a continuing weakness for the crypto industry. Large sums are spent on smart contract audits and infrastructure security, but individual endpoints and user workflows remain major points of exposure. In practice, a secure protocol can still face risk if a trusted team member’s device, messaging account, or browser environment is compromised.
State-Sponsored Crypto Theft Shifts Toward Individuals
BlueNoroff activity has historically been connected to large-scale thefts involving centralized exchanges and decentralized finance protocols. In this campaign, the group is increasingly focused on individuals, including developers, traders, and project founders who may hold private keys or influence treasury decisions.
The shift toward more targeted attacks comes as cryptocurrency markets have seen renewed speculative activity. SUI, for example, surged 18% earlier this year amid institutional staking and ecosystem demand. Tokenized real-world assets have also crossed $20 billion on-chain, placing significant value behind access credentials that malware campaigns seek to capture.
That concentration of value can make individual users attractive targets. A compromised developer wallet could expose not only personal holdings, but also protocol funds or multisignature signer keys.
The campaign also arrives as US lawmakers debate a major crypto bill that banks are trying to stall. The activity underscores that regulatory clarity alone cannot prevent attacks by determined state-linked threat actors.
Unknown Scope and Immediate Risks
JUMPSEC’s report did not disclose the number of victims or the total value stolen so far. As a result, it remains unclear how widely this specific campaign has spread or whether it has affected institutional targets. The firm said the operation is ongoing, meaning its full impact may not be known for weeks.
For users, any unsolicited meeting link, particularly one received through Telegram, should be treated as suspicious until verified through a separate communication channel. For exchanges and custodians, the risk extends to employees who may download the payload on machines with elevated access.
The campaign also points to a structural weakness in crypto security culture. While teams often allocate resources to audits and penetration testing, the social layer, including how teams share links, manage Telegram administrator permissions, and verify meeting identities, remains underprotected. The same workflows that help crypto teams coordinate quickly across jurisdictions can also create openings when identity checks depend mainly on familiar usernames and prior conversations.
As long as cryptocurrency remains a target for nation-state-linked threat actors, attackers may continue seeking the easiest entry point. In this case, the entry point is not a zero-day exploit, but a meeting invitation designed to appear legitimate enough to click.