Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

BlueNoroff Fake Zoom Phishing Targets Crypto Wallets Before Malware Drop

BlueNoroff fake Zoom phishing BlueNoroff fake Zoom phishing

JUMPSEC‘s recovery of live source code from an active phishing kit has exposed how BlueNoroff fake Zoom phishing operates: the kit scans a target’s browser for connected wallets before the operators decide whether to push malware at all.

The North Korea-linked group, described by Picus Security as the financial cybercrime arm of Lazarus and active since at least 2014, exposed JavaScript source maps on its own live infrastructure. That slip let JUMPSEC analysts pull down the full toolkit, map its operator panel, and trace 11 seed domains across passive DNS, VirusTotal, urlscan.io and reverse DNS records. All of that infrastructure remained active as of 24 July 2026.

BlueNoroff Fake Zoom Phishing Profiles Wallets Before the Payload Arrives

The phishing page begins scanning the moment a visitor loads the fake meeting. It queries Ethereum wallet connections via EIP-6963 and legacy injection methods, then sweeps for non-EVM wallets including Solana extensions. Results go straight to the operator panel without triggering any browser alert.

On Windows, the implant walks extension directories across Chrome, Chrome Beta, Chrome Dev, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi and Firefox variants, according to JUMPSEC’s full analysis. Operators compare those IDs against known wallet extensions such as MetaMask. JUMPSEC called this a system that profiles wallets “before malware delivery,” letting attackers rank targets by value before committing the next stage.

The Windows path runs a ClickFix prompt that executes a PowerShell loader, downloads a VBScript, adds a Microsoft Defender exclusion, then restarts Defender so the exclusion sticks. The macOS path drops a fake Zoom or Teams installer while a stealer harvests system data and Chrome master keys from Apple’s Keychain, exfiltrating via a Telegram bot. JUMPSEC traced four macOS variants between 22 April and 15 July, and The Hacker News reports five distinct kit versions across all variants between 31 May and 14 July 2026, pointing to continuous active development throughout the campaign.

Teams Kit Is a Full TypeScript Rewrite, Not a Reskin

The Zoom and Teams lures are not interchangeable copies. JUMPSEC found that the Teams version is a complete TypeScript rewrite built on a service-layer pattern. It includes MediaPipe background blur and virtual background support, mobile and tablet blocking, a post-meeting redirect page, and a LauncherPage that mimics the Teams ‘Continue on this browser’ flow.

The Zoom kit, by contrast, runs a prepared non-live video during the meeting, combining AI-generated headshots with body movements captured in earlier sessions. An operator can join with that footage, message the target that their mic is not working, then trigger a fake SDK update prompt. Sean Moran, head of threat research and enablement at JUMPSEC, told The Hacker News that Zoom and Teams suit the lure because both use desktop clients, making an urgent software update more credible and providing a wider typosquatting surface than Google Meet. The source code also contained an unfinished Google Meet option.

Access typically begins through a hijacked Telegram account belonging to a contact the target already recognises. A Calendly invitation routes them to a lookalike meeting domain. One stolen Telegram session seeds the next round of invitations, making the pipeline self-extending.

Target Demographics Point Squarely at Crypto Leadership

Arctic Wolf, which published its own analysis on 27 April 2026 attributing the campaign to BlueNoroff with high confidence, identified 100 targets. Of those, 76% held C-suite or senior leadership roles, with CEOs and co-founders specifically accounting for 45%. Sector breakdown: 54% operated directly in crypto and blockchain finance, with a further 26% in adjacent finance and investment, reaching the 80% figure across both groups.

Geographically, 41% of identified targets were US-based, 25% East Asian and 19% European, according to Arctic Wolf’s data. The same analysis found 121 confirmed intrusion events in March 2026 alone, with operator activity mapping to Korean Standard Time business hours, as reported by Decryption Digest in its summary of Arctic Wolf Labs’ findings.

Infosecurity Magazine reports that Arctic Wolf Labs first detected a BlueNoroff intrusion at a North American crypto firm beginning 23 January 2026, with more than 80 typosquatted Zoom and Teams domains registered between late 2025 and March 2026.

The practical advice from JUMPSEC is layered: verify any unusual meeting invitation through a second channel, refuse commands or software updates presented during calls, revoke exposed Telegram sessions, and isolate any device that executed the requested script. A password reset alone will not remove a session token already in the operator’s panel or malware already resident on the machine.

The campaign’s next move is already built into the kit: an unfinished Google Meet lure is waiting in the source code.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use