The record
Written from the 1 report below. Nothing here is unsourced.
- North Korean-linked hacking group BlueNoroff is running phishing campaigns that impersonate Zoom and Microsoft Teams to steal from people in the cryptocurrency industry.
- The attackers hijack trusted Telegram accounts to send fake meeting links, then use a fake meeting page to trick victims into running malicious commands.
- Before delivering malware, the kit scans the victim's browser for cryptocurrency wallets, allowing the group to target only high-value victims.
- Stolen Telegram sessions let each compromise fuel attacks on new victims, making the scheme self-propagating.
What to watch next
- The report notes the exact nature of next-stage payloads delivered by the Windows implant remains unknown
- Five distinct versions of the phishing kit were observed between May 31 and July 14, suggesting continued development
- The operator behind the exfiltration bot, "John" (@alchemy_john_mac), was active as recently as May 2026 in cryptocurrency groups
Coverage1
1 report
English national1
All filed from India
Named North Korea · MAIV · MetaMask · Microsoft Teams · Zoom · BlueNoroff · John · JUMPSEC · OpenAI · Sean Moran · Sekoia · Telegram
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
