Over 100 people across 20 countries have fallen victim to BlueNoroff, a North Korean hacking group using fake Zoom and Microsoft Teams meetings to steal cryptocurrency wallet credentials. Nearly half of the targets, 41%, are based in the United States, while 80% work in crypto or blockchain finance.
The attackers employ typosquatted domains that closely mimic legitimate meeting platforms, with more than 80 such domains registered since late 2025. Victims receive seemingly normal invites via compromised Telegram accounts or Calendly, but clicking the link leads to counterfeit meeting pages that secretly record video and launch clipboard hijacking attacks.
This technique, known as a ClickFix clipboard attack, injects malicious commands to harvest data from wallet extensions like MetaMask. In multiple cases, full compromise was achieved in under five minutes, illustrating the attack’s swift and efficient nature.
BlueNoroff’s campaign evolves rapidly, with five new phishing kit versions released between May and July 2026. The group uses AI-generated avatars and deepfake composites to enhance the authenticity of fake meetings, constantly refining tactics based on harvested victim data.
Unlike attacks targeting smart contracts or blockchains directly, this operation depends on social engineering to acquire wallet access, meaning traditional on-chain security measures offer no protection. This highlights the ongoing risks faced by crypto professionals, especially individuals in leadership roles, as nearly 45% of victims are CEOs or founders.



