The North Korean state-sponsored hacking group, BlueNoroff or APT38, is launching a social engineering campaign against crypto professionals. They operate under the Reconnaissance General Bureau. Their main method involves hijacking Telegram accounts belonging to trusted contacts and inviting victims to fake Zoom or Microsoft Teams meetings. In July 2026, cybersecurity firm JUMPSEC obtained the source code of an active phishing kit belonging to BlueNoroff - a platform specifically built to acquire victims by exploiting compromised Telegram contact lists.
This tactic is not just a visual scam, but a structured invasion directly into users’ wallets.
AI Video and Fake Updates
Google Mandiant documented the details of a similar incident last February. Victims received messages from the hacked Telegram accounts of crypto executives, directing them to a spoofed Zoom domain. On the site, victims saw an AI-generated video featuring another executive to make the meeting look authentic. As the meeting progressed, the website’s interface requested webcam access. Suddenly, a fake audio issue warning appeared, urging users to download a software update. This file injects malicious commands into the system clipboard using the ClickFix method.
What Happens in the Background?
The phishing kit actively scans crypto wallet extensions in the victim’s browser before delivering loader malware, ensuring their targets are high-value. On Windows systems, PowerShell and VBScript scripts immediately disable security defenses, initiate reconnaissance, and establish persistent access. On macOS devices, shell scripts along with Mach-O payloads are tasked with stealing login credentials and collecting sensitive data.
The Security Alliance blocked 164 domains associated with this UNC1069 operation between February and April 2026. Nevertheless, the hacking infrastructure was recorded to still be actively operating until late July.
Do Not Trust Your Screen
The Federal Bureau of Investigation (FBI) has warned the public to be wary of any requests to execute code or install unfamiliar applications. Requests to run scripts under the pretext of fixing broken video, or invitations to move from Telegram to another platform, serve as major red flags. The best protection is to verify the identity of contacts through a separate, independent channel. For crypto asset holders, the rule remains absolute: never store seed phrases or private keys on internet-connected devices.
Sourced from crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




