North Korean Hackers Use Fake Video Meetings to Attack Crypto Professionals
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- JUMPSEC exposed BlueNoroff phishing code using fake Zoom and Teams meetings to target Web3 professionals.
- Hackers hijack trusted Telegram accounts, then trick victims into running malicious commands that install malware.
- The campaign scans crypto wallets, steals browser data, and remains active across dozens of malicious domains.
Cybersecurity firm JUMPSEC has uncovered the source code behind an active phishing system linked to BlueNoroff, a North Korean state-backed hacking group known for targeting cryptocurrency businesses. In a July 24 report, JUMPSEC said the campaign uses fake Zoom and Microsoft Teams meetings to trick Web3 professionals into installing malware on Windows and macOS devices.
The attack often begins with a Telegram message from a trusted industry contact. However, the sender’s account has already been compromised. The hacker then invites the target to a video meeting through a link that looks similar to a real Zoom or Teams address.
North Korea-Linked BlueNoroff Uses Fake Zoom and Teams Meetings to Target Crypto Users
Cybersecurity firm JUMPSEC said North Korea-linked hacking group BlueNoroff is targeting crypto professionals through fake Zoom and Microsoft Teams meetings. Attackers use hijacked Telegram… pic.twitter.com/Tz1hcbjlRE
— Wu Blockchain (@WuBlockchain) July 26, 2026
BlueNoroff Uses Trusted Telegram Accounts
JUMPSEC found that the campaign is more advanced than a basic phishing page. The attackers use stolen Telegram sessions to contact senior employees and other valuable targets. Because the message comes from a real contact, the victim is more likely to trust the meeting invitation.
After opening the link, the target sees a realistic meeting page. The fake platform can request webcam access, show a waiting room and display a recorded video that appears to be a live participant. The operator can also send messages claiming that the victim’s microphone is not working or that the meeting software needs an update.
The page then uses a method called ClickFix. It shows what appears to be a normal repair command and asks the victim to copy and run it. However, the copied text is secretly replaced with a malicious command. Once executed, it downloads malware and gives the attackers access to the device.
Attackers Check Crypto Wallets Before Delivering Malware
The phishing kit also scans the victim’s browser for cryptocurrency wallets. It can detect browser wallet extensions and check systems connected to networks such as Ethereum and Solana. The results are quietly sent to the operator, allowing the group to identify targets that may control valuable digital assets.
On Windows, the malicious command downloads a PowerShell loader and a VBScript implant. JUMPSEC said one recovered sample was identified as NukeSped, a malware family previously associated with the wider Lazarus Group. The malware can collect system information, examine browser extensions and receive further commands from its control server.
The macOS version uses a fake Zoom or Teams installer while malicious activity runs in the background. Researchers found versions designed to access the Chrome master key stored in Apple Keychain and send stolen data through a Telegram bot. Some later-stage payloads could not be recovered.
Exposed Code Reveals Wider Attack Infrastructure
JUMPSEC gained detailed access to the operation because the attackers mistakenly left JavaScript source map files on live servers. These files allowed researchers to reconstruct the original code behind both the Zoom and Teams versions.
The investigation began with 11 domains found in the source code. Researchers later expanded the network to more than 60 observed hostnames across 10 IP addresses. JUMPSEC said high- and medium-confidence infrastructure remained active as of July 24.
The report advised crypto and Web3 professionals to verify unexpected meeting invitations through another communication channel, even when they come from a familiar contact. Users should also carefully check the full domain name and avoid copying terminal commands from meeting pages or software update prompts.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







