BlueNoroff scans crypto wallets in fake Zoom calls before dropping malware
From cryptopolitan.com
A North Korean hacking crew screens crypto wallets before it strikes. The group tricks victims into fake Zoom and Microsoft Teams calls. UK security firm JUMPSEC released the source code analysis this week. BlueNoroff’s operation targets the people who hold private keys. It just needs one person to click the wrong prompt. JUMPSEC was able to retrieve the kit’s true source code after its operators left JavaScript source maps exposed on live infrastructure. The files describe a workflow that scans a target’s browser as soon as they land on the fake meeting page. JUMPSEC found that the kit looks for Ethereum connections ...
(full story)