
Bitcoiners are facing a renewed warning over an active social-engineering campaign that hijacks trusted Telegram accounts and funnels cryptocurrency professionals into fake Zoom or Microsoft Teams meetings.
Lightning News raised the alarm on Aug. 7, citing recent accounts from Bitcoin community members. Independent security research confirms the core attack chain, though not every claim has been verified.
JUMPSEC said in July that it obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps. The researchers found a victim-acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and delivers malware to selected targets on Windows and macOS systems. JUMPSEC said identified campaign infrastructure remained active as of July 22.
The attack begins with trust rather than a blockchain vulnerability. JUMPSEC found operators using compromised Telegram accounts belonging to real industry contacts to invite targets to fake video meetings. Because messages arrive from genuine accounts and can reference existing relationships, sender recognition alone provides limited protection.
Google Mandiant independently documented a similar UNC1069 intrusion in February. A victim received messages from a compromised crypto executive’s Telegram account, scheduled a meeting and was redirected to a spoofed Zoom domain. The victim reported seeing what appeared to be an AI-generated video of another crypto executive during the staged call.
Attribution needs precision. Mandiant tracks the actor as UNC1069 and says it overlaps with BlueNoroff. U.S. Treasury has formally designated BlueNoroff, also known as APT38, as a North Korean state-sponsored group controlled by the Reconnaissance General Bureau. Security Alliance likewise attributes the fake-meeting campaign to UNC1069, or BlueNoroff.
JUMPSEC’s reconstructed kit shows a staged meeting interface asking for webcam access before an operator joins with prerecorded video. The victim then sees a supposed audio problem and a fake software update. The displayed troubleshooting text is deceptive: copying it places an attacker-controlled ClickFix command onto the clipboard.
On Windows, JUMPSEC observed PowerShell and VBScript components capable of disabling defenses, conducting reconnaissance and supporting follow-on access. On macOS, researchers found shell scripts and Mach-O payloads designed to steal credentials and other sensitive data. The kit also scans for browser wallet providers before malware delivery, helping operators identify valuable targets.
That means the claim that merely opening a meeting link automatically drains a wallet is too broad. In the documented chains, compromise requires another action, such as running a copied command or malicious update. However, once malware executes, Mandiant found tooling capable of stealing browser data, Keychain credentials and Telegram user data.
As previously reported, Martin Kuchař said his Telegram account was compromised and used in a similar attack. Earlier victim coverage also documented crypto executives being approached through trusted contacts before fake meeting prompts attempted to install malware.
Security Alliance reported that it attributed 164 blocked domains to UNC1069 between Feb. 6 and April 7. Its advisory described multi-week social engineering through Telegram, LinkedIn and Slack before fraudulent Zoom or Teams links were delivered. JUMPSEC later expanded the infrastructure picture and said high- and medium-confidence infrastructure remained active in late July.
The FBI has warned separately that North Korean actors conduct highly tailored social engineering against cryptocurrency and DeFi employees. Its guidance specifically flags requests to execute code, install unfamiliar applications, run scripts to fix video calls or move conversations between communication platforms.
The FBI recommends verifying identities through an independent channel and keeping wallet credentials, seed phrases and private keys off internet-connected devices. Two-factor authentication remains useful, but infected devices can expose session data, so compromised sessions should also be revoked from a clean device.
The most important correction to the Aug. 7 warning is that researchers have not established one universal method for the initial Telegram takeover. Claims that expired or temporary phone numbers are the main cause remain unverified in the material reviewed. Researchers confirm compromised accounts, but the takeover mechanism can vary.
In separate Telegram platform coverage, Apple briefly removed the messaging app from its App Store over a CSAM policy review before restoring it after Telegram removed the flagged content and banned the responsible user.
Users should treat unexpected meeting requests, domain changes, audio-fix prompts and requests to paste commands as high-risk signals. If suspicious code has already run, the FBI advises disconnecting the affected device from the internet while leaving it powered on for potential forensic recovery, then contacting incident-response specialists and law enforcement.
The campaign is therefore best described as an ongoing, North Korea-linked social-engineering operation targeting the human layer around crypto custody. Its effectiveness comes from exploiting trusted identities and familiar workplace tools, not from breaking Bitcoin itself.