Cybersecurity firm JUMPSEC reported in July that North Korea-linked hacking group BlueNoroff is hijacking the Telegram accounts of cryptocurrency executives to lure victims into fake Zoom and Microsoft Teams meetings before installing wallet-draining malware.
The renewed warning over Bitcoin Telegram accounts emerged after Lightning News raised the alarm on Aug. 7, citing multiple reports from members of the Bitcoin community who had encountered suspicious invitations from seemingly legitimate Telegram contacts.
Independent cybersecurity investigations have since confirmed the core attack chain, although researchers caution that not every reported incident has been independently verified.
Bitcoin Telegram accounts exploited through trusted contacts
Unlike traditional cryptocurrency hacks that exploit blockchain vulnerabilities, this campaign targets human trust.
Researchers at cybersecurity firm JUMPSEC revealed in July that they had obtained source code from an active BlueNoroff phishing toolkit after exposed JavaScript source maps inadvertently revealed the attackers’ infrastructure.
According to JUMPSEC, compromised Bitcoin Telegram accounts belonging to genuine cryptocurrency executives, developers and investors are used to contact colleagues and schedule what appear to be legitimate business meetings.
Because the messages originate from authentic Telegram profiles with existing conversation histories, victims are far more likely to trust the invitation.
“Sender recognition alone provides limited protection when attackers compromise legitimate accounts,” JUMPSEC researchers explained in their technical analysis.
The firm’s investigation found that attackers profile victims’ cryptocurrency wallets before deciding whether to deploy malware, making the campaign highly selective and financially motivated. JUMPSEC added that the campaign infrastructure remained active as of July 22.
Bitcoin Telegram accounts fuel fake Zoom meeting scam
Evidence from Google Mandiant reinforces the growing threat surrounding Bitcoin Telegram accounts.
Earlier this year, Google’s threat intelligence team documented an intrusion campaign tracked as UNC1069.
Investigators described how a victim received Telegram messages from the compromised account of a well-known cryptocurrency executive before being invited to what appeared to be a routine Zoom meeting.
Instead of joining a legitimate conference call, the victim was redirected to a fraudulent Zoom website where they reportedly encountered what appeared to be an AI-generated video impersonating another respected crypto executive.
Google Mandiant stated that UNC1069 shares operational overlaps with BlueNoroff, the notorious North Korean hacking unit previously linked to large-scale cryptocurrency thefts.
BlueNoroff uses Bitcoin Telegram accounts to deliver malware
Researchers say the fake meetings are carefully staged.
After victims join, the interface requests webcam permissions before displaying a prerecorded video feed. Moments later, participants are informed that audio is not working and are instructed to install a software update.
In reality, the troubleshooting instructions secretly copy a malicious ClickFix command onto the user’s clipboard.
Once executed, the malware begins compromising the victim’s device.
JUMPSEC observed Windows payloads using PowerShell and VBScript to disable security protections, gather system intelligence and establish persistent access.
On macOS devices, attackers deployed shell scripts and Mach-O malware capable of stealing credentials and harvesting sensitive information.
The researchers also discovered that the toolkit scans browsers for cryptocurrency wallet extensions before deploying its final payload, enabling attackers to prioritize high-value Bitcoin Telegram accounts and cryptocurrency holders.
North Korean group officially linked to Bitcoin Telegram accounts campaign
Attribution remains one of the strongest aspects of this investigation.
Google Mandiant tracks the operation as UNC1069, while Security Alliance (SEAL) has independently linked the fake meeting campaign to the same threat actor.
Meanwhile, the U.S. Department of the Treasury has formally designated BlueNoroff—also known as APT38—as a North Korean state-sponsored cyber group operating under the Reconnaissance General Bureau.
Cybersecurity experts have long associated BlueNoroff with cryptocurrency exchange attacks, decentralized finance exploits and financial espionage campaigns aimed at generating revenue for North Korea.
“The campaign demonstrates how sophisticated social engineering continues to evolve,” Google Mandiant noted, warning that trusted communication platforms remain attractive targets for advanced persistent threat groups.
How to protect Bitcoin Telegram accounts
Security researchers urge cryptocurrency professionals to treat unexpected meeting invitations with extreme caution, even when they originate from familiar Bitcoin Telegram accounts.
Experts recommend confirming meeting invitations through secondary communication channels, avoiding unsolicited software updates during video calls, enabling two-factor authentication on Telegram, and verifying Zoom or Microsoft Teams URLs before joining any meeting.
The latest campaign serves as another reminder that attackers increasingly target people—not blockchains.
As Bitcoin Telegram accounts become trusted gateways into the cryptocurrency industry, protecting those accounts is becoming just as critical as safeguarding private keys and digital wallets.
With North Korean hacking groups continuing to refine their tactics, cybersecurity professionals warn that vigilance, verification and strong operational security remain the best defense against one of the industry’s fastest-growing social-engineering threats