North Korean Hackers Use Fake Video Calls to Target Wealthy Crypto Investors
Summary
- The North Korean hacking group BlueNoroff is using fake video meetings to target wealthy investors' digital-asset wallets.
- BlueNoroff checks whether MetaMask and Solana (SOL)-based wallets are installed, gathers that information and then selectively distributes malware.
- JumpSec and Arctic Wolf said the attack has hit digital-asset industry participants and investors, with more than 100 victims across more than 20 countries, and urged caution.
Forecast Trend Report by Period



A North Korean hacking group has attempted to breach digital-asset wallets belonging to wealthy investors by luring them into fake video meetings, Cryptopolitan reported on July 27.
Cybersecurity firm JumpSec said in a recent report that the North Korean hacking group BlueNoroff has been using fake Zoom and Microsoft Teams meetings to lure victims and detect digital-asset wallets installed in their browsers.
When a victim lands on a fake video-meeting page, BlueNoroff checks whether Ethereum-based wallet MetaMask or Solana-based wallets are installed. It then sends information on the identified digital-asset wallets to the hackers.
BlueNoroff then uses the data it collects to identify wealthy targets and selectively distribute malware. Victims receive a message saying their microphone is not working and are prompted to install fake software. If they download the file, their device is infected with malware.
BlueNoroff has also hacked Telegram, LinkedIn and other social media accounts belonging to people close to victims and then used those accounts to invite them to fake video meetings.
JumpSec said BlueNoroff has continued to target digital-asset industry participants and investors with the tactic and urged caution. Another security firm, Arctic Wolf, estimated that the campaign has so far resulted in more than 100 victims across more than 20 countries.
Bloomingbit Newsroom
news@bloomingbit.ioFor news reports, news@bloomingbit.io