BlueNoroff Uses Fake Zoom and Teams Calls to Scan Crypto Wallets Before Malware Delivery
Key Takeaways
- •BlueNoroff uses fake Zoom and Microsoft Teams pages to identify cryptocurrency wallets before escalating attacks with malware.
- •Attackers often approach victims through compromised Telegram accounts belonging to trusted cryptocurrency industry contacts.
- •JUMPSEC found Windows and macOS malware paths, including wallet extension checks, Telegram file searches, Defender exclusions, and Keychain data collection.
- •The phishing kit gives operators control over fake meeting interactions, including prepared video, messages, and fraudulent update prompts.
- •JUMPSEC advised crypto teams to verify unusual meeting invitations through separate channels and avoid installing updates or running commands during calls.

North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before deciding whether to deliver malware, according to cybersecurity firm JUMPSEC.
JUMPSEC said it recovered and analyzed source code from an active phishing kit after the operators exposed JavaScript source maps on live infrastructure. The files showed separate Zoom and Teams lures, wallet-scanning functions, operator controls, and malware delivery paths for both Windows and macOS.
Damn – the North Koreans can really put together effective campaigns to steal crypto currency – pic.twitter.com/Qxh1VAemCk — Tyson Benson (@tysonbenson) July 25, 2026
The campaign often starts with a Telegram account the target already trusts. Attackers compromise accounts belonging to cryptocurrency industry contacts and use them to send Calendly invitations that redirect victims to lookalike meeting domains. JUMPSEC described the setup as a repeatable victim pipeline, because one stolen Telegram session can be used to approach the next group of targets.
BlueNoroff scans wallets before sending malware
When a user enters the fake meeting site, the phishing page begins scanning the browser. It looks for Ethereum wallet connections through EIP-6963 and older browser methods, and also checks for non-EVM wallets, including Solana tools. EIP-6963 is used by Ethereum wallets to announce themselves to web applications, which means a malicious page can also use those signals to identify installed or connected wallet tools. The results are sent to an operator panel without notifying the victim.
That process allows the attackers to identify which wallets are present and select higher-value targets before triggering the next stage. On Windows, the implant also lists extension IDs across Chrome, Edge, Brave, Opera, Vivaldi, and Firefox variants. Operators can compare those IDs with known wallet extensions such as MetaMask.
JUMPSEC described the activity as a system that profiles wallets “before malware delivery.” The approach differs from broad phishing campaigns because the attackers collect wallet data first and then decide how far to continue the intrusion.
Fake Zoom and Teams pages build credibility
Victims initially see a convincing meeting page that asks for their name and webcam access. The site then sends the camera stream to the attacker’s control panel. After the victim joins, the screen displays a “waiting for other participants” message.
An operator can then enter the session using prepared video, send messages such as “your mic isn’t working,” and trigger a fake “Zoom SDK Update” prompt. JUMPSEC found that the participant video shown to the victim was not live. The attackers combined AI-generated headshots with body movements captured during earlier meetings, allowing them to display a familiar-looking person while using a Telegram account belonging to a real contact.
The Teams version contained emoji reactions, device settings, background effects, and broader wallet checks, making it more polished than the Zoom kit. The source code also included an unfinished Google Meet option. JUMPSEC said Zoom and Teams are effective lures because both services use desktop clients, making an urgent software update request appear more credible.
Malware supports Windows and macOS
On Windows, the copied ClickFix command runs a small PowerShell loader. It downloads a VBScript, adds a Microsoft Defender exclusion, and restarts Defender so the change takes effect. The implant collects system details, checks browsers for wallet extensions, and searches for Telegram Web files.
The Windows implant can also receive later payloads from the operators, although JUMPSEC did not recover every final-stage file. The phishing kit’s Windows path therefore gives operators a way to assess the target environment and continue the compromise after the fake meeting prompt.
On macOS, the attack path downloads a fake Zoom or Teams installer while a stealer runs in the background. Researchers found versions that collected system information and Chrome master keys from Apple’s Keychain. Chrome master keys can be used to access protected browser data on a compromised device, making Keychain access a notable part of the macOS infection path. The malware sent data through a Telegram bot and could download another payload.
JUMPSEC traced four macOS variants between April 22 and July 15, indicating that the operators continued changing the toolkit during the campaign.
Findings build on earlier fake meeting campaigns
The findings expand earlier research into BlueNoroff’s fake meeting operations. In April, Arctic Wolf reported more than 80 lookalike Zoom and Teams domains and identified 100 additional targets whose media appeared on attacker infrastructure. Arctic Wolf said 80% of the identified targets worked in crypto, blockchain finance, or related investment sectors, while founders and chief executives accounted for 45%.
North Korean attackers had already used compromised Telegram accounts, spoofed meeting invitations, and fake software updates to target crypto executives. Another crypto.news report described a related macOS campaign that asked victims to run commands during fake calls. Earlier coverage of NimDoor malware also linked fake Zoom updates to attempts to steal browser credentials, wallet data, and Telegram files.
JUMPSEC said the latest kit gives operators direct control over the pace of each meeting and the malware prompt. The firm advised organizations to treat meeting links from trusted accounts cautiously, because the sender’s account may already be compromised.
Crypto teams can verify unusual invitations through another channel, avoid running commands or installing updates presented during calls, revoke exposed Telegram sessions, and isolate any device that ran the requested script. Teams should also review PowerShell activity, Defender exclusions, Keychain access, and new Telegram logins after any suspicious call. A password reset alone may not remove stolen sessions or malware already running on affected systems.