North Korean hacking group BlueNoroff is reportedly using fake Zoom and Microsoft Teams meetings to target wealthy cryptocurrency holders, according to a report cited by Cryptopoli. The campaign is designed to identify victims with browser-based crypto wallets and then deliver malware selectively.
How the scam works
The reported scheme begins with an invitation to what appears to be a legitimate video meeting. Once a target lands on the fake meeting page, BlueNoroff checks the victim’s browser for installed digital-asset wallets. Cryptopoli said the group looks specifically for MetaMask, which is used on Ethereum, and wallets tied to Solana.
The information gathered from those checks is then sent back to the attackers. Based on the detected wallets, the group is said to assess whether a person is a high-value target before deciding whether to move forward with malware deployment.
Selective targeting of wealthy users
Rather than infecting every visitor automatically, the campaign reportedly uses the wallet data to filter for high-net-worth individuals. That approach suggests the attackers are trying to focus their efforts on people likely to control substantial digital assets.
Victims are reportedly told that their microphone is not functioning during the supposed meeting. They are then prompted to install software presented as a fix. If the file is downloaded, the device becomes infected with malware.
Use of trusted contacts as bait
BlueNoroff has also allegedly relied on compromised accounts belonging to people known to the victim. According to the report, hacked Telegram, LinkedIn and other social media accounts have been used to send invitations to the fraudulent meetings, giving the approach an added layer of credibility.
Security researchers say this tactic fits a broader pattern. Huntress said BlueNoroff has consistently targeted participants in the digital-asset industry as well as investors through this type of social-engineering operation, and urged extra caution.
Scope of the campaign
Another cybersecurity company, Arctic Wolf, estimated that the activity has affected more than 100 victims in over 20 countries. The figure points to a campaign with international reach, though the full scale of the operation remains uncertain based on the available reporting.
The reported operation highlights a familiar tactic in crypto-related cybercrime: blending impersonation, compromised social accounts and fake software prompts to gain access to devices and, potentially, digital wallets. In this case, researchers say the attackers appear to be screening victims first, then reserving malware for targets judged most valuable.
Source: en.bloomingbit.io