Mark RadarMARK RADAR
About
EN
Sign in

BlueNoroff Uses Fake Meetings to Steal Crypto Wallet Assets

1 reports · First detected 2026-07-30 · Last active 2026-07-30

BlueNoroff, a North Korean hacking group targeting the cryptocurrency sector, is exploiting the industry’s reliance on remote meetings conducted through Zoom and Microsoft Teams. Invitations sent from compromised accounts belonging to prominent crypto figures can appear credible, making social engineering an effective route into victims’ devices and digital wallets. The campaign highlights the persistent threat to an industry where a single compromised endpoint can expose assets that are difficult to recover.

Cybersecurity firm Jumpsec said BlueNoroff compromised accounts of well-known cryptocurrency figures and used them to distribute fake Zoom and Teams meeting invitations. The ClickFix phishing campaign prompts targets to perform malicious actions, allowing malware to be installed and wallet assets to be stolen. Jumpsec’s disclosure did not specify the date of the attacks, the number of victims or the total value of cryptocurrency taken, leaving the campaign’s financial impact unclear.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)