North Korea's BlueNoroff hijacks Zoom calls to drain crypto wallets

NewsMon, 27 Jul 2026 02:44:13 UTC5 hours ago
North Korea's BlueNoroff hijacks Zoom calls to drain crypto wallets

A North Korean hacking crew screens crypto wallets before it strikes. The group tricks victims into fake Zoom and Microsoft Teams calls.

UK security firm JUMPSEC released the source code analysis this week. BlueNoroff’s operation targets the people who hold private keys. It just needs one person to click the wrong prompt.

BlueNoroff screens crypto wallets before choosing who to infect

JUMPSEC was able to retrieve the kit’s true source code after its operators left JavaScript source maps exposed on live infrastructure.

The files describe a workflow that scans a target’s browser as soon as they land on the fake meeting page. JUMPSEC found that the kit looks for Ethereum connections with the EIP-6963 standard and with legacy browser techniques.

It also probes for non-EVM wallets like Solana tools. The results are pushed directly to an operator dashboard. And the person on the call never gets a prompt or warning.

The malware on Windows computers has a list of browser extension IDs for Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. Hackers then use these IDs to check against known wallet extensions like MetaMask.

… Continue reading the full article at the original source below.

Read from Source · cryptopolitan.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptopolitan.com).

Related