NewsCryptoNorth Korea-Linked Hackers Target Crypto Users With Fake Zoom Calls as Separate Group Allegedly Breaches Banks

North Korea-Linked Hackers Target Crypto Users With Fake Zoom Calls as Separate Group Allegedly Breaches Banks

Author: LiveBitcoinNews·

Key Takeaways

  • •JUMPSEC said BlueNoroff uses hijacked Telegram accounts to send trusted contacts fake Zoom and Microsoft Teams meeting links.
  • •The phishing platform checks browsers for cryptocurrency wallet extensions before prompting victims to install a fake SDK update.
  • •The malware can steal browser credentials, Chrome master keys, Telegram sessions, cryptocurrency wallet data, and system information.
  • •JUMPSEC found signs the phishing kit remains under development, including multiple versions and an unfinished Google Meet variant.
  • •Daily NK reported that North Korean authorities raided a Pyongyang site linked to an alleged scheme targeting domestic banks and moving stolen funds through cryptocurrency.
North Korea-Linked Hackers Target Crypto Users With Fake Zoom Calls as Separate Group Allegedly Breaches Banks

North Korea-linked hackers are using fake video meetings to target cryptocurrency wallets, while a separate group has reportedly been caught hacking North Korea’s own financial institutions.

Cybersecurity firm JUMPSEC said it uncovered a phishing operation run by BlueNoroff, a hacking group linked to North Korea. The campaign targets crypto professionals by luring them into fake Zoom and Microsoft Teams meetings.

The attackers first compromise Telegram accounts belonging to people the victims already trust. They then use those accounts to send meeting invitations. After entering the fake call, victims are prompted to turn on their webcam, without realizing the meeting environment has been staged. The use of trusted contacts is central to the scheme because it moves the attack beyond a cold phishing message and into a communication channel the victim may already rely on for work.

JUMPSEC said BlueNoroff accidentally exposed its own JavaScript source code, giving researchers an unusually detailed view of how the phishing system operates.

How the Fake Meeting Scheme Works

According to JUMPSEC, the attack begins when a trusted Telegram contact sends a meeting link. The link directs the target to a lookalike domain designed to imitate Zoom or Microsoft Teams.

Victims who join the call may see pre-recorded participants on screen, while an operator monitors the victim’s live camera feed. JUMPSEC found that the Microsoft Teams version of the phishing kit is more convincing than the Zoom version, with fake device settings, emoji reactions, and virtual backgrounds used to strengthen the illusion.

Before malware is delivered, the platform silently scans the victim’s browser. It checks for wallet extensions connected to Ethereum, Solana, and other blockchain networks. JUMPSEC said this allows BlueNoroff to filter out lower-value targets and concentrate on victims worth pursuing further. That browser-level screening also shows the campaign is not just imitating workplace software, but actively looking for signs that a target has access to crypto assets.

North Korea-Linked BlueNoroff Uses Fake Zoom and Teams Meetings to Target Crypto Users

Cybersecurity firm JUMPSEC said North Korea-linked hacking group BlueNoroff is targeting crypto professionals through fake Zoom and Microsoft Teams meetings. Attackers use hijacked Telegram… pic.twitter.com/Tz1hcbjlRE

— Wu Blockchain (@WuBlockchain) July 26, 2026

Wallet Scans Lead to a Fake Software Update

After the browser scan is complete, victims are asked to install a fake “SDK update” for Zoom or Teams. Clicking the prompt triggers what researchers describe as a ClickFix attack, in which the victim is tricked into running commands they believe will resolve a technical issue.

JUMPSEC documented separate infection paths for Windows and macOS users. On Windows devices, the fake update launches PowerShell scripts that download additional malware. The scripts also collect system information and specifically search for Telegram data and browser wallet extensions.

On macOS, users download what appears to be a normal Zoom or Teams installer. While the fake application appears to install as expected, a second-stage stealer loads quietly in the background.

Malware Collects Wallets, Credentials, and Telegram Sessions

Once active, the malware extracts a wide range of data from the infected device. JUMPSEC said it can capture browser credentials, Chrome master keys, full Telegram sessions, cryptocurrency wallet data, and general system information.

The theft of Telegram sessions creates an additional risk because attackers may be able to reuse the compromised account to target the victim’s own contacts. In that way, one successful compromise can supply both stolen data and a new trusted identity for follow-on phishing attempts.

JUMPSEC said the phishing kit remains under active development. Researchers found multiple versions of the platform hosted on the same infrastructure. They also discovered an unfinished Google Meet variant, suggesting BlueNoroff may be preparing to expand the campaign beyond Zoom and Microsoft Teams.

The continued improvements to the Teams interface indicate ongoing refinement. JUMPSEC characterized the activity as a sustained campaign rather than a one-time operation.

The findings add to a broader pattern of social engineering campaigns by North Korea-linked groups against the crypto sector. Previous tactics have included fake job interviews and fake investor outreach. JUMPSEC’s report shows how video-conferencing impersonation has become another entry point for these attacks, particularly as remote meetings remain a routine part of crypto industry business development and hiring.

Separate Report Says North Korean IT Workers Hacked Domestic Banks

North Korea’s own financial system has also become a target, according to a separate Daily NK report. The outlet said a criminal organization allegedly hacked internal networks at the Central Bank of Korea and the Foreign Trade Bank.

The group is accused of converting stolen state funds into cryptocurrency before smuggling the assets across border regions. Authorities reportedly dismantled the operation during a raid in Pyongyang on the 12th.

A source told Daily NK that the ringleaders were former soldiers from a cyber operations unit under the General Reconnaissance and Intelligence Bureau. After leaving the military, they allegedly recruited students from Kim Chaek University of Technology and Pyongyang University of Science.

The group reportedly used Chinese wireless equipment and encrypted messaging services to avoid detection. Stolen funds were allegedly divided into small units and transferred to overseas crypto wallets. Daily NK reported that the coins were later converted back into cash through Chinese brokers, and the cash was exchanged for U.S. dollars and yuan near Sinuiju and Hyesan.

Investigators reportedly uncovered the scheme after identifying irregular transaction records and unusual overseas IP access. The National Intelligence Agency traced heavy crypto-related traffic to a house in Pyongyang, Daily NK said. The house was raided on the night of the 12th.

According to the report, ringleaders and IT personnel were arrested at the site, and authorities seized computer equipment and burner phones. Taken together, the JUMPSEC and Daily NK reports describe separate cases in which cryptocurrency appears in different roles: as the target of external social-engineering attacks and, in the domestic bank case, as an alleged vehicle for moving stolen funds.