July 26, 2026 ChainGPT

N. Korea-linked BlueNoroff weaponizes fake Zoom/Teams to fingerprint crypto wallets, deploy malware

N. Korea-linked BlueNoroff weaponizes fake Zoom/Teams to fingerprint crypto wallets, deploy malware
Headline: North Korea-linked group uses fake Zoom and Teams calls to profile crypto wallets and deliver malware A North Korea-associated hacking crew, BlueNoroff, has been running a sophisticated phishing campaign that uses counterfeit Zoom and Microsoft Teams meetings to fingerprint cryptocurrency users before unleashing malware, cybersecurity researchers warn. The finding comes from JUMPSEC, which recovered JavaScript source maps from an active phishing kit and analyzed the attackers’ tooling and infrastructure. How the scheme works - The campaign often begins by compromising a trusted Telegram account belonging to someone in the crypto community. Attackers then send a Calendly-style meeting invitation that redirects victims to a convincing lookalike meeting domain. - When a victim “joins” the fake meeting, a malicious webpage immediately begins scanning the browser for wallets and other artifacts. It probes for Ethereum wallet connections using EIP‑6963 and older browser methods, checks for non‑EVM wallets (including Solana), and — on Windows — enumerates extension IDs across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants to match known wallet extensions such as MetaMask. - Scan results feed a live operator control panel. This lets attackers quietly profile wallets and select higher‑value targets before pushing the next stage of the intrusion — a far more targeted approach than scattergun phishing campaigns. Highly convincing social engineering Victims first see a realistic meeting page that requests a name and webcam access. The site streams the victim’s camera to the operator panel and then displays a “waiting for other participants” screen. From there, an operator can join with a pre-recorded video, send text prompts like “your mic isn’t working,” and prompt the user to install a fake “Zoom SDK Update.” JUMPSEC’s analysis revealed that the participant video often isn’t live: attackers stitch AI‑generated headshots to body movements captured in earlier calls, enabling them to impersonate familiar contacts while using a real compromised Telegram account. The Teams variant is even more polished (emoji reactions, device settings, background effects) and the kit included an unfinished Google Meet option. The researchers note Zoom and Teams are attractive lures because their desktop clients make urgent update prompts seem plausible. Windows and macOS infection chains - Windows: The kit deploys a ClickFix command that runs a small PowerShell loader. The loader fetches a VBScript, creates a Microsoft Defender exclusion, and restarts Defender to apply it. The implant harvests system details, checks for wallet extensions and Telegram Web files, and can receive further payloads from operators. - macOS: Victims are shown fake Zoom/Teams installers while a stealer runs in the background. JUMPSEC found variants that collected system information and extracted Chrome master keys from Apple’s Keychain. Infected data was exfiltrated via a Telegram bot, and JUMPSEC traced four macOS variants changing between April 22 and July 15 — evidence the operators actively refined their toolkit. Scale and context The JUMPSEC report expands on prior findings. In April, Arctic Wolf discovered more than 80 lookalike Zoom and Teams domains tied to similar operations and identified about 100 targets whose media appeared on attacker infrastructure. Arctic Wolf said roughly 80% of those targets were in crypto, blockchain finance or investment sectors, and founders and CEOs comprised 45% of the victims. BlueNoroff has already been linked to earlier campaigns using similar tactics — compromised Telegram accounts, spoofed meeting invites and fake software updates — to steal browser credentials, wallet data and Telegram files. Why this matters This campaign is notable because it profiles wallets and victims before deciding whether to deliver malware, enabling attackers to focus effort on high‑value targets and avoid noisy, low‑yield operations. The use of trusted, compromised Telegram accounts and convincing video impersonations increases the likelihood of success among insider networks. Mitigation advice for crypto teams - Treat meeting links with caution, even from trusted contacts. Verify unexpected invites via a separate channel (phone call, different messaging ID). - Never run commands, install software, or accept “urgent updates” prompted during a call without independent verification. - Revoke exposed Telegram sessions and isolate any device that executed a requested script. - For suspicious devices, review PowerShell activity and Microsoft Defender exclusion lists; on macOS, check Keychain access and Chrome master keys. - Monitor for new Telegram logins and reset credentials; but note that a password reset alone may not remove already stolen sessions or live malware. Bottom line: BlueNoroff’s operation demonstrates a step‑up in social engineering tailored to the crypto industry — combining account takeover, realistic fake meetings and pre‑attack wallet reconnaissance to pick off valuable targets. Crypto teams should assume meeting links can be weaponized and add verification and device hygiene to their routines. Read more AI-generated news on: undefined/news