A North Korea-linked hacking group, BlueNoroff, is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before deploying malware. According to ChainCatcher, the attackers first take over trusted crypto industry contacts, then send seemingly normal meeting links through services such as Calendly that direct victims to fake Zoom or Teams domains.
After users open the fake meeting page, it quietly scans browser wallets and uses wallet value to decide whether to continue the attack. The page then prompts users to update Zoom or Teams, or to run commands that download malware for Windows and macOS.
The malware is designed to steal browser keys, system data, and Telegram sessions.
BlueNoroff Uses Fake Zoom and Teams Meetings to Target Crypto Users
2026-07-26 07:23:39
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
Previous article:
IRGC Says It Controls 240,000 Square Kilometers in the Persian Gulf and Strait of HormuzNext article:
伊朗称美军多处基地失去作战能力