BlueNoroff-linked Telegram hijacks lure crypto targets into fake Zoom calls

A renewed warning to Bitcoin and cryptocurrency users centers on an active social-engineering campaign in which compromised Telegram accounts are used to steer professionals into fake Zoom or Microsoft Teams meetings that can lead to malware infection. Lightning News raised the alarm on Aug. 7, while JUMPSEC, Google Mandiant and Security Alliance described a broader operation linked to UNC1069, which overlaps with BlueNoroff. JUMPSEC said in July that exposed JavaScript source maps let it obtain source code from an active phishing kit that abuses Telegram contacts, profiles browser wallet providers and selectively delivers malware to Windows and macOS victims. The chain does not show that opening a meeting link alone drains a wallet; researchers said compromise typically requires an additional step such as running a copied ClickFix command or a fake software update. Security Alliance attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7, and JUMPSEC said campaign infrastructure was still active as of July 22. The FBI has separately warned that North Korean actors are targeting cryptocurrency and DeFi employees with tailored lures and advised independent identity checks and keeping seed phrases and private keys off internet-connected devices whenever possible. Researchers have not established a single takeover method for the initial Telegram compromises, and claims that expired or temporary phone numbers are the main cause remain unverified.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.