Bitcoin Telegram accounts targeted by North Korean hackers

2 weeks ago 14



Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram accounts and funnels cryptocurrency professionals into fake Zoom or Microsoft Teams meetings. Summary BlueNoroff is hijacking Telegram accounts and using fake Zoom or Teams meetings against crypto professionals. JUMPSEC found the phishing kit profiles cryptocurrency wallets before operators selectively deliver malware to victims. Security Alliance attributed 164 blocked domains to UNC1069 between February and early April 2026 alone. Mandiant observed compromised Telegram accounts, fake Zoom calls, ClickFix commands and malware targeting crypto organizations. FBI guidance recommends independent identity verification and keeping wallet secrets off internet-connected devices whenever possible. Lightning News raised the alarm on Aug. 7, citing recent accounts from Bitcoin community members. Independent security research confirms the core attack chain, though not every claim has been verified. JUMPSEC said in July that it obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The researchers found a victim-acquisition platform that a...

Read Entire Article