North Korean Hackers Hijack Telegram Accounts to Target Crypto Professionals
A North Korean-linked hacking group known as BlueNoroff has been identified hijacking Telegram accounts and using them to lure cryptocurrency and Bitcoin professionals into fake video meetings. Victims are invited to what appear to be legitimate Zoom or Microsoft Teams calls, but the links instead deliver malware designed to compromise their devices and accounts.
This tactic relies on trust: because the invitation comes from a hijacked, familiar Telegram contact, targets are more likely to click through without suspicion. Once installed, the malware can be used to steal credentials, access cryptocurrency wallets, or gain further footholds into a victim's systems.
While this campaign is aimed at crypto professionals, the technique — hijacking a trusted communication channel to push fake meeting links — is a growing pattern used against businesses of all kinds. Small businesses using Telegram, Zoom, or Teams for client communication should be aware that meeting invitations, even from known contacts, can be spoofed or sent from compromised accounts.