Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bitcoin Telegram accounts targeted by North Korean hackers

    August 7, 2026

    Sam Bankman-Fried was planning Tucker Carlson interview for years

    August 7, 2026

    Best Practices for Managing Digital Asset Portfolios

    August 7, 2026
    X (Twitter) Instagram YouTube LinkedIn
    X (Twitter) Instagram YouTube LinkedIn
    Block Hub News
    • Lithosphere News Releases
    • Crypto
    • Ethereum
    • Bitcoin
      • Litecoin
      • Altcoins
      • Coinbase
    • Blockchain
    Block Hub News
    Home » Bitcoin Telegram accounts targeted by North Korean hackers
    Crypto

    Bitcoin Telegram accounts targeted by North Korean hackers

    James WilsonBy James WilsonAugust 7, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram accounts and funnels cryptocurrency professionals into fake Zoom or Microsoft Teams meetings. 

    Summary

    • BlueNoroff is hijacking Telegram accounts and using fake Zoom or Teams meetings against crypto professionals.
    • JUMPSEC found the phishing kit profiles cryptocurrency wallets before operators selectively deliver malware to victims.
    • Security Alliance attributed 164 blocked domains to UNC1069 between February and early April 2026 alone.
    • Mandiant observed compromised Telegram accounts, fake Zoom calls, ClickFix commands and malware targeting crypto organizations.
    • FBI guidance recommends independent identity verification and keeping wallet secrets off internet-connected devices whenever possible.

    Lightning News raised the alarm on Aug. 7, citing recent accounts from Bitcoin community members. Independent security research confirms the core attack chain, though not every claim has been verified.

    JUMPSEC said in July that it obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The researchers found a victim-acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and delivers malware to selected targets on Windows and macOS systems. JUMPSEC said identified campaign infrastructure remained active as of July 22.

    Telegram accounts under attack, source: X
    Telegram accounts under attack, source: X

    BlueNoroff turns trusted Telegram contacts into lures

    The attack begins with trust rather than a blockchain vulnerability. JUMPSEC found operators using compromised Telegram accounts belonging to real industry contacts to invite targets to fake video meetings. Because messages arrive from genuine accounts and can reference existing relationships, sender recognition alone provides limited protection.

    Google Mandiant independently documented a similar UNC1069 intrusion in February. A victim received messages from a compromised crypto executive’s Telegram account, scheduled a meeting and was redirected to a spoofed Zoom domain. The victim reported seeing what appeared to be an AI-generated video of another crypto executive during the staged call.

    Attribution needs precision. Mandiant tracks the actor as UNC1069 and says it overlaps with BlueNoroff. U.S. Treasury has formally designated BlueNoroff, also known as APT38, as a North Korean state-sponsored group controlled by the Reconnaissance General Bureau. Security Alliance likewise attributes the fake-meeting campaign to UNC1069, or BlueNoroff.

    Fake meetings push ClickFix commands and malware

    JUMPSEC’s reconstructed kit shows a staged meeting interface asking for webcam access before an operator joins with prerecorded video. The victim then sees a supposed audio problem and a fake software update. The displayed troubleshooting text is deceptive: copying it places an attacker-controlled ClickFix command onto the clipboard.

    On Windows, JUMPSEC observed PowerShell and VBScript components capable of disabling defenses, conducting reconnaissance and supporting follow-on access. On macOS, researchers found shell scripts and Mach-O payloads designed to steal credentials and other sensitive data. The kit also scans for browser wallet providers before malware delivery, helping operators identify valuable targets.

    That means the claim that merely opening a meeting link automatically drains a wallet is too broad. In the documented chains, compromise requires another action, such as running a copied command or malicious update. However, once malware executes, Mandiant found tooling capable of stealing browser data, Keychain credentials and Telegram user data.

    As previously reported, Martin Kuchař said his Telegram account was compromised and used in a similar attack. Earlier victim coverage also documented crypto executives being approached through trusted contacts before fake meeting prompts attempted to install malware.

    Security researchers say the campaign remains broad

    Security Alliance reported that it attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7. Its advisory described multi-week social engineering through Telegram, LinkedIn and Slack before fraudulent Zoom or Teams links were delivered. JUMPSEC later expanded the infrastructure picture and said high- and medium-confidence infrastructure remained active in late July.

    The FBI has warned separately that North Korean actors conduct highly tailored social engineering against cryptocurrency and DeFi employees. Its guidance specifically flags requests to execute code, install unfamiliar applications, run scripts to fix video calls or move conversations between communication platforms.

    The FBI recommends verifying identities through an independent channel and keeping wallet credentials, seed phrases and private keys off internet-connected devices. Two-factor authentication remains useful, but infected devices can expose session data, so compromised sessions should also be revoked from a clean device.

    What Bitcoin and crypto users should watch next

    The most important correction to the Aug. 7 warning is that researchers have not established one universal method for the initial Telegram takeover. Claims that expired or temporary phone numbers are the main cause remain unverified in the material reviewed. Researchers confirm compromised accounts, but the takeover mechanism can vary.

    In separate Telegram platform coverage, Apple briefly removed the messaging app from its App Store over a CSAM policy review before restoring it after Telegram removed the flagged content and banned the responsible user.

    Users should treat unexpected meeting requests, domain changes, audio-fix prompts and requests to paste commands as high-risk signals. If suspicious code has already run, the FBI advises disconnecting the affected device from the internet while leaving it powered on for potential forensic recovery, then contacting incident-response specialists and law enforcement.

    The campaign is therefore best described as an ongoing, North Korea-linked social-engineering operation targeting the human layer around crypto custody. Its effectiveness comes from exploiting trusted identities and familiar workplace tools, not from breaking Bitcoin itself.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    CleanSpark reports $239M quarterly loss as revenue falls 30.5%, misses estimates

    August 7, 2026

    Upbit parent Dunamu to custody seized crypto for South Korean police

    August 7, 2026

    Sui targets 2027 mainnet rollout for native quantum safe account authentication

    August 7, 2026
    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Thai police want Interpol to track alleged KuCoin money launderer

    June 8, 2026

    Why the crypto crash has nothing to do with stocks

    June 8, 2026

    Odds swing wildly as Polymarket bets on Iran’s successor collapse

    June 8, 2026

    Strategy can survive Bitcoin at $30k, BTCTOP CEO says

    June 8, 2026
    Don't Miss

    Bitcoin Telegram accounts targeted by North Korean hackers

    By James WilsonAugust 7, 2026

    Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram…

    Sam Bankman-Fried was planning Tucker Carlson interview for years

    August 7, 2026

    Best Practices for Managing Digital Asset Portfolios

    August 7, 2026

    CleanSpark reports $239M quarterly loss as revenue falls 30.5%, misses estimates

    August 7, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Bitcoin Telegram accounts targeted by North Korean hackers

    August 7, 2026

    Sam Bankman-Fried was planning Tucker Carlson interview for years

    August 7, 2026

    Best Practices for Managing Digital Asset Portfolios

    August 7, 2026
    Most Popular

    Thai police want Interpol to track alleged KuCoin money launderer

    June 8, 2026

    Why the crypto crash has nothing to do with stocks

    June 8, 2026

    Odds swing wildly as Polymarket bets on Iran’s successor collapse

    June 8, 2026

    Type above and press Enter to search. Press Esc to cancel.