North Korean Hackers Hijack Telegram Accounts to Target Bitcoin and Crypto Firms
Key Takeaways
- •North Korean hackers are compromising trusted Telegram accounts to impersonate crypto industry executives and employees, then using those identities to deceive colleagues and partners into installing malware.
- •The campaign progresses through hijacking accounts, building credibility through routine conversation, scheduling fake video meetings, and convincing victims to run malicious software disguised as technical fixes.
- •Multiple malware families have been deployed to steal credentials, browser data, and cryptocurrency wallet information while maintaining long-term access to infected systems.
- •UN sanctions monitors report that North Korean cyber operatives have stolen billions of dollars in cryptocurrency over recent years, with some proceeds helping to fund the country's weapons programs.
- •Security professionals advise verifying unexpected meeting requests through separate communication channels and enabling strong account protections to reduce the risk of compromise.

North Korean state-linked hackers are expanding their attacks on the cryptocurrency industry by compromising Telegram accounts and using them to trick Bitcoin and crypto professionals into installing malware. Security researchers describe the campaign as another evolution in Pyongyang's long-running effort to steal digital assets and sensitive credentials that can help finance the country's sanctioned activities. According to United Nations sanctions monitors and blockchain analytics firms such as Chainalysis and TRM Labs, North Korean cyber operatives have stolen billions of dollars in cryptocurrency over the past several years, with UN panels reporting that some of these proceeds have helped fund the country's weapons programs.
According to the latest findings, attackers first gain control of legitimate Telegram accounts belonging to executives or employees in the crypto and fintech sectors. They then use those trusted identities to contact colleagues, investors, and business partners, eventually inviting them to seemingly legitimate online meetings. During these fabricated sessions, victims are instructed to install software or run commands to resolve invented technical issues, ultimately infecting their devices with malware. Telegram has become a central communications tool across the cryptocurrency industry, widely used for deal-making, project coordination, and community management, which makes compromised accounts on the platform especially potent for reaching targets who routinely conduct sensitive business there.
Trusted Accounts Become the Entry Point
Researchers note that the attackers rely primarily on social engineering rather than technical exploits. By hijacking authentic Telegram accounts, they bypass the skepticism that typically greets unsolicited messages. This human-centric approach reflects a broader trend documented across the industry: as exchanges, wallet providers, and custodians have strengthened their technical defenses, threat actors have increasingly pivoted toward tricking individual employees who hold privileged access rather than breaking through code.
The campaign generally proceeds through several stages:
- Compromise a trusted Telegram account.
- Build credibility through routine conversations.
- Schedule a fake Zoom or video meeting.
- Convince the victim to install a supposed audio or software fix.
- Deploy malware designed to steal credentials, browser data, and cryptocurrency wallet information.
Investigators have identified multiple malware families engineered to maintain long-term access while collecting sensitive data from infected systems. The operation primarily targets cryptocurrency companies, software developers, venture capital firms, and other organizations that manage or invest in digital assets.
Growing Threat to the Crypto Industry
Cybersecurity experts warn that North Korean threat groups continue to refine their techniques by combining compromised messaging accounts, sophisticated social engineering, and, in some cases, AI-generated deepfake videos to bolster credibility. Rather than attacking blockchain networks directly, the hackers increasingly concentrate on employees with privileged access to wallets, cloud infrastructure, and internal systems. Analysts note that the tactic mirrors prior North Korean operations documented by firms including Google's Mandiant and Slow Mist, where fake recruiters and business contacts lured crypto engineers into running malicious code under the guise of coding tests or collaboration tools.
The campaign underscores the growing importance of verifying unexpected meeting requests, even when they appear to come from familiar Telegram contacts. Security professionals recommend confirming invitations through separate communication channels, avoiding unknown software downloads, and enabling strong account protections to reduce the risk of compromise.