North Korean Hackers BlueNoroff Use Fake Zoom and Teams Meetings to Scan Crypto Wallets

According to Crypto.news, the North Korean-affiliated hacking group BlueNoroff is exploiting fake Zoom and Microsoft Teams meeting links to scan cryptocurrency users' wallets before deploying malware. The group compromises trusted contacts in the crypto industry and sends seemingly legitimate meeting invitations via Calendly, redirecting to spoofed Zoom and Teams domains. Once victims access the fake meeting pages, hidden scripts scan browser-stored wallets and assess their value to determine attack priority. The fake meeting then prompts users to update Zoom or Teams or run system commands, downloading malware compatible with Windows and macOS. The malware steals browser private keys, system data, and Telegram session information.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments