North Korea’s Crypto Hacks Hit Zoom Users and Its Own Bank
Crime

North Korea’s Crypto Hacks Hit Zoom Users and Its Own Bank

By Samuel

BlueNoroff hackers use fake Zoom calls to drain crypto wallets, as another North Korean group is caught hacking its own central bank.

North Korean hackers have found a new way into crypto wallets, and it starts with a video call. 

Cybersecurity firm JUMPSEC uncovered a phishing operation run by BlueNoroff, a North Korea-linked hacking group. The scheme lures crypto professionals into fake Zoom and Microsoft Teams meetings. 

The attackers hijack Telegram accounts belonging to people victims already trust, then send meeting invites through those accounts. Once inside the fake call, victims are asked to turn on their webcam, unaware the entire setup is staged. 

JUMPSEC says the group accidentally exposed its own JavaScript source code. That mistake gave researchers a rare look at how the scheme works.

How The Fake Meeting Scam Works

According to JUMPSEC, the attack begins the moment a trusted Telegram contact sends a meeting link. That link leads to a lookalike domain built to mimic Zoom or Teams. 

Victims who join the call may see pre-recorded participants on screen while an operator watches their live camera feed. 

JUMPSEC found that the Teams version of the kit looks more convincing than the Zoom one. It includes fake device settings, emoji reactions, and virtual backgrounds to sell the illusion.

Before any malware gets involved, the platform quietly scans the victim’s browser. It checks for wallet extensions tied to Ethereum, Solana, and other blockchain networks. 

This step lets BlueNoroff filter out low-value targets and focus only on people worth attacking further, according to JUMPSEC’s findings.

Wallet Scanning Leads To A Fake Software Update

Once the scan finishes, victims are prompted to install a fake “SDK update” for Zoom or Teams. Clicking it triggers what researchers call a ClickFix attack. 

The victim is tricked into running commands they believe will fix a technical glitch. JUMPSEC documented separate infection paths for Windows and macOS users.

On Windows machines, the update launches PowerShell scripts that pull down more malware. Those scripts also gather system details and search specifically for Telegram data and browser wallet extensions. 

Mac users instead download what looks like a normal Zoom or Teams installer. A second-stage stealer then loads quietly in the background while the fake app appears to install normally.

Stolen Data Includes Wallets And Telegram Sessions

Once active, the malware pulls a wide range of information from the infected device. JUMPSEC reports it can capture browser credentials, Chrome master keys, and full Telegram sessions. 

Cryptocurrency wallet data and general system information are also swept up in the process. Because Telegram sessions are stolen too, attackers can potentially reuse the hijacked account to target the victim’s own contacts next.

JUMPSEC noted the phishing kit is still being actively built out. Researchers found multiple versions of the platform sitting on the same infrastructure. 

An unfinished Google Meet variant was also discovered, suggesting BlueNoroff plans to expand beyond Zoom and Teams. 

The continued upgrades to the Teams interface suggest ongoing refinement. This looks like a sustained campaign, not a one-off effort, JUMPSEC said.

The findings add to a long list of social engineering tactics North Korea-linked groups have used against the crypto industry

Fake job interviews, fake investors, and now fake meeting hosts have all served as entry points for these campaigns. JUMPSEC’s report gives defenders a clearer picture of how convincing these fake calls have become.

North Korean IT Workers Caught Hacking Their Own Central Bank

North Korea’s own financial system has become a target too, according to a separate Daily NK report. A criminal organization allegedly hacked internal networks at the Central Bank of Korea and the Foreign Trade Bank. 

The group is accused of converting stolen state funds into cryptocurrency before smuggling it across border regions. Authorities reportedly dismantled the operation in a Pyongyang raid on the 12th.

A source told Daily NK the ringleaders were former soldiers from a cyber operations unit. The unit falls under the General Reconnaissance and Intelligence Bureau. 

After leaving the military, they allegedly recruited students from Kim Chaek University of Technology and Pyongyang University of Science. The group reportedly used Chinese wireless equipment and encrypted messengers to avoid detection.

Stolen funds were reportedly split into small units and moved to overseas crypto wallets. Daily NK reports the coins were later converted back into cash through Chinese brokers. The cash was then exchanged for US dollars and yuan near Sinuiju and Hyesan. 

Investigators traced the scheme after spotting irregular transaction records and unusual overseas IP access.

The National Intelligence Agency reportedly traced heavy crypto traffic to a house in Pyongyang. The house was raided on the night of the 12th, according to the report. 

Ringleaders and IT personnel were arrested on site, and computer equipment and burner phones were seized.

Samuel

About the Author

Samuel

Leave a Reply