The campaign, linked by Mandiant and the U.S. Treasury to the North Korean state-sponsored group BlueNoroff—also known as APT38—uses compromised accounts to initiate contact. Victims report receiving invitations from genuine industry peers, which makes the deception difficult to spot. Once a target joins a spoofed meeting, they are often confronted with AI-generated video or fake troubleshooting prompts. These prompts instruct users to copy and paste malicious ClickFix commands into their systems, which then trigger the installation of malware on Windows or macOS devices.
In section Cryptocurrency
North Korean Hackers Exploit Trusted Telegram Contacts to Target Crypto
Cryptocurrency professionals are facing a sophisticated social-engineering campaign where attackers hijack trusted Telegram accounts to lure victims into fake Zoom or Microsoft Teams meetings. Security researchers warn that these North Korean-linked actors are bypassing traditional defenses by exploiting existing professional relationships rather than blockchain vulnerabilities.

JUMPSEC researchers who analyzed a leaked phishing kit found that the software specifically profiles cryptocurrency wallets before delivering tailored payloads. On desktop systems, these scripts are designed to disable security defenses, harvest browser credentials, and steal sensitive data. The scale of the operation is significant; the Security Alliance documented 164 unique domains tied to the actor, known as UNC1069, between February and April alone. The FBI has issued guidance urging professionals to verify meeting requests through independent channels and to keep private keys and seed phrases on air-gapped, non-networked devices. While two-factor authentication provides a layer of security, researchers emphasize that compromised sessions can bypass these protections, making vigilance against unexpected technical prompts the primary defense.
Comments (0)
No comments yet. Be the first!