North Korea’s BlueNoroff Targets Crypto Users with Fake Meetings
North Korea’s BlueNoroff Targets Crypto Users with Fake Meetings
In a striking cybersecurity development, the North Korea-linked hacking group known as BlueNoroff is leveraging fake Zoom and Microsoft Teams meetings to profile cryptocurrency users. This tactic is being employed to deliver malware effectively, as they identify high-value targets through their browser wallets.
Phishing Campaigns Using Trusted Contacts
According to cybersecurity firm JUMPSEC, the attack process typically begins with a hijacked account on Telegram, a platform that often hosts crypto discussions. Hackers gain access to a trusted contact’s account and send out Calendly invitations leading to a fake meeting domain. This setup allows attackers to establish credibility with potential victims by using names and accounts they recognize, effectively creating a ‘repeatable victim pipeline.’
Wallet Scanning Mechanism
Once the target joins the fake meeting, the phishing page activates and begins scanning for connected cryptocurrency wallets, including Ethereum and Solana tools. The scan utilizes various techniques to extract wallet data without raising alarms, forwarding this information directly to the attackers’ control panel.
Advanced Techniques to Build Trust
The compelling fake meeting pages ask users for their name and camera access, displaying a “waiting for participants” screen while the attack unfolds. This might include AI-generated headshots mimicking familiar figures or fabricated video feeds to maintain an air of authenticity. The attackers may prompt for a false software update to further disguise their intentions, capitalizing on the urgent appearance of such updates to increase compliance from the victims.
Sources of Compromised Data
Malware deployed during these attacks is multifaceted, targeting both Windows and macOS systems. On Windows, for instance, attackers use a PowerShell loader to gather information, while macOS attacks involve the installation of fake Zoom or Teams applications designed to download additional malicious payloads.
Ongoing Threat and Preventive Measures
The scope of BlueNoroff’s operations is extensive; prior research has indicated they have successfully targeted over 80 lookalike meeting domains used to scam cryptocurrency professionals. As part of their advice to organizations, JUMPSEC warns recognized meeting links from trusted contacts must be approached with caution, as they could already be compromised.
To defend against such attacks, it is crucial for crypto teams to verify unusual invitations via alternate communication channels, remain vigilant about commands or updates suggested during calls, and review any system activities post-meeting.
Source: crypto.news