A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts. Those stolen identities then send fake Zoom and Microsoft Teams meeting links to senior staff at cryptocurrency and Web3 firms. The motive is financial. Operators scan browsers for crypto wallets before they deliver malware, then aim to steal credentials and funds that can support state-backed goals. The effort works less like a simple fake page and more like a repeatable pipeline that grows each time a new contact is compromised. Analysts from Jumpsec identified the operation after operators...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!