Analysis of North Korean Hackers’ Targeted Phishing Scams on Telegram

2023-12-06 Slowmist

https://slowmist.medium.com/analysis-of-north-korean-hackers-targeted-phishing-scams-on-telegram-872db3f7392b

Thumbnail for Analysis of North Korean Hackers’ Targeted Phishing Scams on Telegram

SlowMist attributes a Telegram phishing operation targeting cryptocurrency and DeFi project teams to Lazarus-linked North Korean hackers active since 2022. The attackers impersonate reputable investment institutions with fake Telegram accounts, build trust with project teams, and then steer victims toward malicious meeting workflows. One infection path uses meeting domains such as group-meeting-themed sites to persuade targets to run a location-modifying AppleScript that fetches a remote script, while another abuses Calendly custom links to place malicious URLs inside otherwise familiar scheduling pages. The activity matters for Web3 defenders because it combines social engineering, investor impersonation, and meeting-tool abuse to gain control of team systems and potentially steal funds or wallet-related access.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 104.168.137.21 2023-12-06 2024-07-15
URL https://support.group-meeting.o… 2023-12-06 2023-12-06
DOMAIN support.group-meeting.online 2023-12-06 2023-12-06

Related Reports

« Back