BlueNoroff, a group linked to the the North Korean Lazarus Group, is targeting crypto professionals using fake Zoom and Microsoft Teams meetings sent via compromised Telegram accounts or Calendly links. The phishing kit scans installed wallet browser extensions to assess the wealth of each target before deploying malware tailored to the system, whether Windows or macOS. The macOS variants exfiltrate Chrome master keys stored in the Keychain and Telegram sessions in under five minutes via a Telegram bot. According to Chainalysis, North Korea stole a record of approximately 2 billion dollars in cryptocurrency in 2025, bringing cumulative loot since 2017 to over 6.75 billion dollars.
Source: Read the original article

