EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

North Korea's BlueNoroff organization uses fake Zoom and Teams to launch a phishing attack to targe

2026-07-27 00:30:22
Bookmark

Low-tech links in the high-tech industry are becoming more dangerous. Cybersecurity company JUMPSEC has found that the North Korea-linked BlueNoroff group launched an operation to target cryptocurrency professionals using weaponized conference links disguised as invitations from Zoom and Microsoft Teams. Rather than cracking blockchain, the attacker undermined interpersonal trust-hijacking Telegram accounts, sending malicious meeting links to contacts, and then tricking victims into installing fake "SDK updates," opening the door to full-scale intrusion into the system.

Attack patterns and effects

The operation started with a hijacked Telegram account. A trusted contact receives a seemingly legitimate message, often referring to a call about an investment, token issuance or partnership. The link directs the target to a website that mimics the Zoom or Teams login page and prompts them to update SDK components. Fake updates can implant malicious payload. By abusing Telegram's own infrastructure and victims 'existing trust networks, attackers circumvented typical phishing defense mechanisms. JUMPSEC's disclosure shows that even skilled cryptocurrency professionals can be deceived.

What really increases the threat level is its cross-platform capabilities. Both Windows and macOS are targets, which means there is no operating system security by default. The malware focuses on browser-stored keys and hot wallet extensions, which means that even users using hardware wallets are still at risk if their session token is stolen if they interact with the dApp through the browser. This highlights a harsh reality in the industry: Despite billions of dollars invested in smart contract audits and infrastructure security, human terminals remain the weakest link.

State-sponsored cryptocurrency theft enters a new phase

The BlueNoroff module has historically been linked to multiple large-scale thefts, including attacks on centralized exchanges and the DeFi protocol. Today, the organization is increasingly targeting individuals-developers, traders and project founders-who hold keys or influence financial decisions. This shift in precision strikes coincides with a resurgence of speculation in the market. For example, SUI rose 18% earlier this year due to institutional pledges and ecosystem demand, reminding everyone that active wallets is a fat goal. At the same time, the value of tokenized real-world assets has exceeded US$20 billion, with a large amount of value concentrated behind the access credentials that such malware is designed to steal.

This centralization makes individual users a more attractive target. A compromised developer's wallet may not only expose personal assets, but also reveal agreement funds or multiple signer keys. The timing also coincides with U.S. lawmakers debating a landmark cryptocurrency bill that banks are trying to delay. Amid policy debates, state-backed groups such as BlueNoroff operate amid loopholes, proving that regulatory clarity alone cannot deter a determined opponent.

Missing information and concerns

The JUMPSEC report did not disclose the number of victims or the total value of assets stolen to date. This lack of detail leaves an unsolved mystery: How widely did this particular operation spread? Has it affected institutional goals? The company pointed out that the action is still ongoing, which means the full impact may not be felt for weeks. The first step for users is to treat any unsolicited meeting link-especially from Telegram-as malicious until its authenticity is verified through other channels. For exchanges and custodians, the risk extends to employees, who may inadvertently download malicious payload to machines with high privileges.

The action also highlighted structural weaknesses in the industry's safety culture. Despite millions of dollars invested in formal audits and penetration testing, the social dimension-how teams share links, manage Telegram administrator privileges, and verify meeting identities-remains under-resourced. As long as cryptocurrencies continue to attract the attention of national threat actors, the easiest entry point will never be a zero-day vulnerability, but a fake meeting invitation that looks real enough to make people can't resist clicking.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP