Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram accounts and funnels cryptocurrency professionals into fake Zoom or Microsoft Teams meetings. 

Summary

  • BlueNoroff is hijacking Telegram accounts and using fake Zoom or Teams meetings against crypto professionals.
  • JUMPSEC found the phishing kit profiles cryptocurrency wallets before operators selectively deliver malware to victims.
  • Security Alliance attributed 164 blocked domains to UNC1069 between February and early April 2026 alone.
  • Mandiant observed compromised Telegram accounts, fake Zoom calls, ClickFix commands and malware targeting crypto organizations.
  • FBI guidance recommends independent identity verification and keeping wallet secrets off internet-connected devices whenever possible.

Lightning News raised the alarm on Aug. 7, citing recent accounts from Bitcoin community members. Independent security research confirms the core attack chain, though not every claim has been verified.

JUMPSEC said in July that it obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The researchers found a victim-acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and delivers malware to selected targets on Windows and macOS systems. JUMPSEC said identified campaign infrastructure remained active as of July 22.

Telegram accounts under attack, source: X
Telegram accounts under attack, source: X

BlueNoroff turns trusted Telegram contacts into lures

The attack begins with trust rather than a blockchain vulnerability. JUMPSEC found operators using compromised Telegram accounts belonging to real industry contacts to invite targets to fake video meetings. Because messages arrive from genuine accounts and can reference existing relationships, sender recognition alone provides limited protection.

Google Mandiant independently documented a similar UNC1069 intrusion in February. A victim received messages from a compromised crypto executive’s Telegram account, scheduled a meeting and was redirected to a spoofed Zoom domain. The victim reported seeing what appeared to be an AI-generated video of another crypto executive during the staged call.

Attribution needs precision. Mandiant tracks the actor as UNC1069 and says it overlaps with BlueNoroff. U.S. Treasury has formally designated BlueNoroff, also known as APT38, as a North Korean state-sponsored group controlled by the Reconnaissance General Bureau. Security Alliance likewise attributes the fake-meeting campaign to UNC1069, or BlueNoroff.

Fake meetings push ClickFix commands and malware

JUMPSEC’s reconstructed kit shows a staged meeting interface asking for webcam access before an operator joins with prerecorded video. The victim then sees a supposed audio problem and a fake software update. The displayed troubleshooting text is deceptive: copying it places an attacker-controlled ClickFix command onto the clipboard.

On Windows, JUMPSEC observed PowerShell and VBScript components capable of disabling defenses, conducting reconnaissance and supporting follow-on access. On macOS, researchers found shell scripts and Mach-O payloads designed to steal credentials and other sensitive data. The kit also scans for browser wallet providers before malware delivery, helping operators identify valuable targets.

That means the claim that merely opening a meeting link automatically drains a wallet is too broad. In the documented chains, compromise requires another action, such as running a copied command or malicious update. However, once malware executes, Mandiant found tooling capable of stealing browser data, Keychain credentials and Telegram user data.

As previously reported, Martin Kuchař said his Telegram account was compromised and used in a similar attack. Earlier victim coverage also documented crypto executives being approached through trusted contacts before fake meeting prompts attempted to install malware.

Security researchers say the campaign remains broad

Security Alliance reported that it attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7. Its advisory described multi-week social engineering through Telegram, LinkedIn and Slack before fraudulent Zoom or Teams links were delivered. JUMPSEC later expanded the infrastructure picture and said high- and medium-confidence infrastructure remained active in late July.

The FBI has warned separately that North Korean actors conduct highly tailored social engineering against cryptocurrency and DeFi employees. Its guidance specifically flags requests to execute code, install unfamiliar applications, run scripts to fix video calls or move conversations between communication platforms.

The FBI recommends verifying identities through an independent channel and keeping wallet credentials, seed phrases and private keys off internet-connected devices. Two-factor authentication remains useful, but infected devices can expose session data, so compromised sessions should also be revoked from a clean device.

What Bitcoin and crypto users should watch next

The most important correction to the Aug. 7 warning is that researchers have not established one universal method for the initial Telegram takeover. Claims that expired or temporary phone numbers are the main cause remain unverified in the material reviewed. Researchers confirm compromised accounts, but the takeover mechanism can vary.

In separate Telegram platform coverage, Apple briefly removed the messaging app from its App Store over a CSAM policy review before restoring it after Telegram removed the flagged content and banned the responsible user.

Users should treat unexpected meeting requests, domain changes, audio-fix prompts and requests to paste commands as high-risk signals. If suspicious code has already run, the FBI advises disconnecting the affected device from the internet while leaving it powered on for potential forensic recovery, then contacting incident-response specialists and law enforcement.

The campaign is therefore best described as an ongoing, North Korea-linked social-engineering operation targeting the human layer around crypto custody. Its effectiveness comes from exploiting trusted identities and familiar workplace tools, not from breaking Bitcoin itself.



Source link