North Korean hacker group BlueNoroff uses fake Zoom and Teams meetings to scan crypto wallets and deploy malware

robot
Abstract generation in progress

PANews July 26 news: According to Crypto.news, the hacker group BlueNoroff, which is associated with North Korea, uses fake Zoom and Microsoft Teams meeting invites to analyze cryptocurrency users and then deploy malware. The hackers first take over the accounts of trusted cryptocurrency industry contacts of the victims, then use services such as Calendly to send seemingly normal meeting links that lead to spoofed Zoom/Teams domains. After users enter the fake meeting page, the page quietly scans wallets in the browser, deciding whether to continue the attack based on the wallet’s value. The fake meeting prompts users to “update Zoom/Teams” or to run commands, which actually download malware (supports Windows and macOS). The malware steals browser keys, system data, and Telegram sessions.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned