From February 6th to April 7th, 2026, the Security Alliance (SEAL) blocked 164 internet domains linked to a North Korean hacking group known as UNC1069, also tracked by the broader security community as BlueNoroff.
SEAL discovered that this group is aggressively tricking people in the cryptocurrency sector and open-source software community using fake Zoom and Microsoft Teams meetings.
The attackers are running a clever social engineering campaign to steal sensitive data and digital assets without requiring victims to install traditional software.
Social Engineering and Fake Meetings
UNC1069 hackers spend weeks building trust before launching their attacks. SEAL reports that the attackers use platforms like Telegram, LinkedIn, and Slack to contact their targets.
They either pretend to be well-known brands or use accounts they have already hacked to message people who think they are talking to a trusted contact.
Because the hackers can read past messages, they easily resume old conversations and make their new requests look completely normal.
After establishing this trust, the attackers schedule a business call, often using a real Calendly link, and set the meeting for a week or two later. This delay removes any sense of urgency and makes the victim feel safe.

Malware Delivery and Impact
Instead of tricking the victim into downloading a large program, the hackers use a much simpler method to deliver their malware. Depending on the attack, the victim is either asked to download a tiny script file or copy and paste a command into their computer terminal.

SEAL explains that once the victim runs this command, a hidden instruction reaches out to the hackers’ servers and downloads the actual malware.
| Domain | First Seen (UTC) | IP | ASN # | Hosting Provider | Registrar |
|---|---|---|---|---|---|
| micrusoft[.]us | 2026-04-07 13:13:13 | 68.65.123[.]117 | 22612 | NAMECHEAP-NET – Namecheap, Inc. | NameSilo, LLC |
| uk05live[.]us | 2026-04-06 17:33:40 | 66.29.141[.]223 | 22612 | NAMECHEAP-NET – Namecheap, Inc. | NAMECHEAP INC |
Once the security alliance hackers decide to strike, they have a wide range of powerful tools at their disposal. SEAL notes that the malware can steal passwords saved in web browsers, copy cryptocurrency wallet files, and record every key the victim presses.

The attackers also steal session tokens for apps like Telegram, which allows them to take over the victim’s accounts and target their friends and coworkers.
The malware can even replace safe browser extensions with malicious ones and steal cloud computing passwords across multiple operating systems, including macOS, Windows, and Linux.
Recently, the hackers used these stolen accounts to compromise a popular software package called “axios,” showing they are now trying to infect tools used by developers worldwide.
To help protect organizations, SEAL shared a list of blocked web domains used in these attacks, including web-meet. live, microcall.us, and teamsync. live.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.



