The Billion-Dollar Invite: How UNC1069’s Fake Meetings Hijack Crypto Fortunes
ID: 38087c7d-5f72-5d18-b1fe-4fb07ed35877
STIX ID: report--38087c7d-5f72-5d18-b1fe-4fb07ed35877
Feed Name: securityonline.info
Between Feb 6 and Apr 7, 2026, SEAL documented and blocked 164 domains tied to UNC1069 (BlueNoroff) that conducted slow-burn social engineering via Telegram, LinkedIn, and Slack to lure crypto/Web3 victims into fraudulent browser-based Zoom/Teams meeting UIs which install a modular post-exploitation implant; modules steal browser-stored credentials and seed phrases, harvest Telegram session tokens, replace browser extensions with malicious versions, and exfiltrate SSH/AWS credentials, with operators remaining dormant post-compromise to maximize theft. Recommended mitigations include verifying meeting links, auditing browser extensions, and hardening session tokens (hardware keys and monitoring for unusual Telegram sessions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
