logo

The Billion-Dollar Invite: How UNC1069’s Fake Meetings Hijack Crypto Fortunes

ID: 38087c7d-5f72-5d18-b1fe-4fb07ed35877

STIX ID: report--38087c7d-5f72-5d18-b1fe-4fb07ed35877

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Between Feb 6 and Apr 7, 2026, SEAL documented and blocked 164 domains tied to UNC1069 (BlueNoroff) that conducted slow-burn social engineering via Telegram, LinkedIn, and Slack to lure crypto/Web3 victims into fraudulent browser-based Zoom/Teams meeting UIs which install a modular post-exploitation implant; modules steal browser-stored credentials and seed phrases, harvest Telegram session tokens, replace browser extensions with malicious versions, and exfiltrate SSH/AWS credentials, with operators remaining dormant post-compromise to maximize theft. Recommended mitigations include verifying meeting links, auditing browser extensions, and hardening session tokens (hardware keys and monitoring for unusual Telegram sessions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.