North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware.
Summary
- BlueNoroff scans browser wallets before deciding which fake meeting targets should receive its malware payload.
- Hijacked Telegram accounts help attackers contact trusted industry peers and extend the campaign through victims.
- The phishing kit supports Windows and macOS, stealing browser keys, system data, and Telegram sessions.
Cybersecurity firm JUMPSEC said it recovered and analysed source code from an active phishing kit after its operators exposed JavaScript source maps on live infrastructure. The files…







