The North Korean hacker group BlueNoroff uses fake Zoom and Teams meetings to scan cryptocurrency wallets and deploy malware
According to Crypto.news, the hacker organization BlueNoroff, linked to North Korea, uses fake Zoom and Microsoft Teams meetings to analyze cryptocurrency users before deploying malware.
The hackers first take control of accounts belonging to trusted contacts in the cryptocurrency industry, then send seemingly normal meeting links via Calendly and other platforms, directing users to counterfeit Zoom/Teams domains. Once users enter the fake meeting page, it quietly scans the wallets in their browsers and decides whether to continue the attack based on the wallet's value. The fake meeting will prompt users to "update Zoom/Teams" or run commands, which actually download malware (supporting Windows and macOS). The malware will steal browser keys, system data, and Telegram sessions.






