Web3: North Korean-linked hackers use fake video conferences to screen crypto wallet targets.
crypto.news
07-26 13:40
Ai Focus
JUMPSEC claims that BlueNoroff scans for crypto wallets by using fake Zoom and Teams meeting pages, then delivers malware to high-value targets, with attacks covering both Windows and macOS.
Helpful
No.Help

Cybersecurity firm JUMPSEC reports that the North Korean-affiliated hacking group BlueNoroff is using fake Zoom and Microsoft Teams meeting pages to first identify whether victims possess cryptocurrency wallets before deciding whether to proceed with malware distribution. These attacks often originate from hijacked Telegram accounts and primarily target individuals in the crypto industry and those involved in investment.

Check the wallet first, then poison.

JUMPSEC reports that researchers have recovered the source code from a phishing tool still in use. The code reveals that attackers prepared spoofed pages for Zoom and Teams, complete with wallet scanning, control panels, and two delivery paths for Windows and macOS.

Once a victim clicks on the fake meeting page, the webpage scans the browser environment in the background to check for a connected Ethereum wallet and also identifies some non-EVM wallets, including Solana-related tools. The scan results are sent directly to the attacker's backend, and the victim usually receives no notification.

In Windows environments, the attack program also enumerates extension IDs in Chrome, Edge, Brave, Opera, Vivaldi, and Firefox variants, then compares them with common wallet extensions like MetaMask. JUMPSEC believes this means attackers assess the target's value before proceeding with further intrusions, rather than indiscriminately deploying attacks on a large scale.

Using acquaintances' accounts to increase credibility

These types of attacks typically begin with Telegram. Hackers first gain control of the victim's trusted industry contacts' accounts, then send meeting links with Calendly invitations, directing the target to a spoofed domain. JUMPSEC believes this method can create a continuous proliferation, as a stolen Telegram session can continue to help attackers reach the next batch of targets.

The fake meeting page prompts users to enter their names and turn on their cameras, transmitting the video feed back to the attacker's control panel. Once the victim joins the meeting, the page displays "Waiting for other participants to join." At this point, the attacker can play a pre-prepared video, send notifications such as "microphone malfunction," and trick the user into clicking on a so-called "Zoom SDK update."

Researchers discovered that the attendee videos on the page were not live. Attackers combined AI-generated avatars with body language captured from previous meetings to impersonate familiar contacts. Compared to the Zoom version, the Teams version is more feature-rich, including facial feedback, device settings, background effects, and more extensive wallet checks. An unfinished version of Google Meet was also found in the code.

Covers both Windows and macOS

On Windows devices, once a victim executes the command prompted by the page, a PowerShell loader may be triggered. This program downloads VBScript, adds a Microsoft Defender exclusion, and restarts Defender to make the settings take effect. Subsequently, the malware collects system information, checks browser wallet extensions, and looks for Telegram web files.

On macOS, the malware downloads fake Zoom or Teams installation packages while running a stealing program in the background. JUMPSEC found that some samples extract system information and Chrome master keys, and attempt to read data from the Apple Keychain. This data is then transmitted back via a Telegram bot, and the malware can continue downloading subsequent payloads.

JUMPSEC tracked four macOS variants spanning from April 22 to July 15, indicating that the tool is constantly being tweaked. Researchers also mentioned that Arctic Wolf had previously discovered over 80 counterfeit Zoom and Teams domains and identified 100 additional targets, approximately 80% of which originated from the crypto, blockchain finance, and related investment sectors.

Additional information:JUMPSEC recommends that encryption teams should double-check meeting links sent by acquaintances through other channels; avoid executing commands or installing temporary updates during calls; and if a Telegram session is suspected of being compromised, promptly revoke the relevant logins and isolate any devices that have executed scripts.

Tip
$0
Like
0
Save
0
Views 791
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Samsung Wallet will add stablecoin support; USDC appears in the demo screen.
Samsung has announced that Samsung Wallet will support stablecoins, with USDC appearing in the demo. However, the specific launch date and on-chain solution have not yet been announced.
Decrypt
·2026-07-25 04:08:52
359
Web3: Apple faces $1.835 million lawsuit over fake Bitcoin wallet app.
Three users have filed a lawsuit against Apple, alleging that a fake Sparrow Wallet app on the App Store caused them to lose approximately $1.835 million in Bitcoin. The case has been filed in a U.S. federal court.
crypto.news
·2026-07-28 17:12:25
377
web3: Upbit adds MORPHO and EUL (Korean Won) trading pairs
Upbit launched the MORPHO and EUL Korean Won trading pair. EUL surged before the market opened, prompting the exchange to set price limits and trading restrictions.
crypto.news
·2026-07-26 13:00:55
499
Web3: Robinhood CEO X account hacked, fake tokens used as cover.
The hacking of Robinhood's CEO's social media account and the subsequent deletion of fake token promotional messages have brought to light the risks of meme coin speculation and fraud on the Robinhood Chain.
Decrypt
·2026-07-24 04:17:25
450
Web3: Samsung Wallet plans to add stablecoin functionality.
Samsung plans to add stablecoin support to Samsung Wallet, but has not yet disclosed the currency, timeline, or partners.
crypto.news
·2026-07-24 19:18:54
435