North Korea’s Crypto Hacks Hit Zoom Users and Its Own Bank

North Korea’s Crypto Hacks Hit Zoom Users and Its Own Bank

Hackers linked to BlueNoroff are using deceptive Zoom meetings to steal cryptocurrency. Meanwhile, a separate North Korean hacking group has been discovered targeting their country’s own national bank.

North Korean hackers have found a new way into crypto wallets, and it starts with a video call. 

JUMPSEC, a cybersecurity company, has discovered a phishing scam orchestrated by BlueNoroff, a hacking group believed to be connected to North Korea. This scam targets people who work with cryptocurrency, tricking them into attending bogus meetings set up on Zoom and Microsoft Teams.

Attackers are taking over Telegram accounts of people that others already know and trust. They then use these compromised accounts to send invitations to video calls. When victims join the call, they’re asked to turn on their webcams without realizing it’s a trap.

According to JUMPSEC, the attackers unintentionally revealed their own JavaScript code. This accidental exposure gave security researchers a unique opportunity to understand how the attack operates.

How The Fake Meeting Scam Works

JUMPSEC reports that this type of cyberattack starts when someone you trust on Telegram shares a meeting link with you. This link actually directs you to a fake website designed to appear like the legitimate Zoom or Microsoft Teams.

People who participate in the call might see videos of others already on the screen, while a support person views their live camera feed.

JUMPSEC discovered that the fake meeting kit appears more realistic when used with Microsoft Teams compared to Zoom. It creates a convincing deception by featuring fabricated device settings, simulated emoji reactions, and virtual backgrounds.

Before any harmful software acts, the system subtly checks the victim’s web browser for cryptocurrency wallet extensions connected to networks like Ethereum and Solana.

According to research from JUMPSEC, this process helps BlueNoroff identify and prioritize potential victims, concentrating their efforts on those most likely to be valuable targets.

North Korea-Linked BlueNoroff Uses Fake Zoom and Teams Meetings to Target Crypto Users

According to cybersecurity company JUMPSEC, a North Korean hacking group called BlueNoroff is now targeting people who work with cryptocurrency. They’re doing this by setting up phony meetings on platforms like Zoom and Microsoft Teams, and using compromised Telegram accounts to connect with victims.

— Wu Blockchain (@WuBlockchain) July 26, 2026

Wallet Scanning Leads To A Fake Software Update

After the scan is complete, users are tricked into installing a phony update for Zoom or Teams, claiming it’s an “SDK update.” This download initiates a type of attack called ClickFix.

The victim is fooled into running commands, thinking they’re solving a technical problem. JUMPSEC has detailed how the infection works differently for Windows and macOS users.

On Windows computers, the update starts malicious programs using PowerShell scripts. These scripts download additional harmful software, collect information about your system, and specifically look for Telegram data and cryptocurrency wallet extensions in your web browser.

People using Macs think they’re downloading Zoom or Teams, but they’re actually getting a disguised malicious program. This program secretly installs itself in the background while making it seem like the real application is installing as usual.

Stolen Data Includes Wallets And Telegram Sessions

After infecting a device, this malware steals various types of information. According to JUMPSEC, it can grab saved usernames and passwords from web browsers, Chrome’s main security key, and complete access to Telegram accounts.

Attackers don’t just steal messages; they also grab data from cryptocurrency wallets and other system details. Plus, by taking over Telegram accounts, they can use the victim’s account to spread the attack to their friends and family.

JUMPSEC observed that the phishing kit is still under development, with researchers discovering several versions of the platform hosted on the same servers.

Researchers also found an early version of a fake Google Meet, indicating the BlueNoroff hacking group is looking to target more video conferencing platforms, not just Zoom and Microsoft Teams.

JUMPSEC notes that Microsoft Teams is receiving frequent updates, indicating a long-term plan for improvement rather than just a single set of changes.

In my research, I’ve found yet another example of how groups connected to North Korea are targeting the crypto industry with social engineering attacks. This adds to a growing pattern of these types of tactics they’ve been using.

These attacks often start with deceptive tactics like phony job interviews, fake investors, or now, imposters posing as meeting hosts. A recent report from JUMPSEC shows just how realistic and convincing these fraudulent calls have become, giving security professionals a better understanding of the threat.

North Korean IT Workers Caught Hacking Their Own Central Bank

North Korea’s banking system has also been targeted by hackers, according to a report from Daily NK. The report claims that a criminal group successfully broke into the computer networks of both the Central Bank of Korea and the Foreign Trade Bank.

As a researcher following this case, I’ve learned that this group is alleged to have stolen state funds and then converted them into cryptocurrency. They then reportedly attempted to move the funds across borders. Authorities acted on the 12th, conducting a raid in Pyongyang that apparently shut down the operation.

According to a source, the individuals behind the scheme were previously members of a cyber warfare unit within North Korea’s General Reconnaissance and Intelligence Bureau.

Following their time in the military, the team is said to have hired students from two North Korean universities: Kim Chaek University of Technology and Pyongyang University of Science. They apparently relied on Chinese-made radio technology and secure messaging apps to keep their activities hidden.

It appears the stolen money was broken down into smaller amounts and sent to cryptocurrency wallets located outside the country. According to Daily NK, these coins were then exchanged for cash with the help of brokers in China. This cash was ultimately converted into US dollars and Chinese yuan near the border cities of Sinuiju and Hyesan.

Detectives uncovered the fraud by noticing strange patterns in financial transactions and logins from unexpected international locations.

Intelligence officials say they tracked a large amount of cryptocurrency activity to a home in Pyongyang. The home was searched on the night of the 12th.

The authorities raided the operation and arrested the key people involved, including the tech folks running things. They took all their computers and temporary phones too.

2026-07-26 15:11