NewsCryptoBlueNoroff Uses Fake Zoom and Teams Calls to Scan Crypto Wallets Before Deploying Malware

BlueNoroff Uses Fake Zoom and Teams Calls to Scan Crypto Wallets Before Deploying Malware

Author: crypto.news·

Key Takeaways

  • •JUMPSEC found that BlueNoroff’s phishing kit scans browser wallets before operators decide whether to deliver malware.
  • •The campaign uses compromised Telegram accounts and fake meeting invitations to reach targets through trusted contacts.
  • •The toolkit includes separate Zoom and Microsoft Teams lures, with Windows and macOS malware delivery paths.
  • •The malware can collect system information, browser keys, Telegram session data, and wallet-related indicators.
  • •JUMPSEC advised organizations to verify unusual meeting links through separate channels and investigate suspicious scripts, updates, and logins.
BlueNoroff Uses Fake Zoom and Teams Calls to Scan Crypto Wallets Before Deploying Malware

North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware, according to cybersecurity firm JUMPSEC.

In a report, JUMPSEC said it recovered and analyzed source code from an active phishing kit after the operators exposed JavaScript source maps on live infrastructure. The recovered files showed separate Zoom and Teams lures, wallet-scanning tools, operator controls, and malware delivery paths for both Windows and macOS.

The kit scans browser wallets before attackers decide which fake meeting targets should receive a malware payload. It also supports the theft of browser keys, system data, and Telegram sessions. Hijacked Telegram accounts help the attackers contact trusted industry peers and extend the campaign through victims.

Damn – the North Koreans can really put together effective campaigns to steal crypto currency – pic.twitter.com/Qxh1VAemCk — Tyson Benson (@tysonbenson) July 25, 2026

Damn – the North Koreans can really put together effective campaigns to steal crypto currency – pic.twitter.com/Qxh1VAemCk

The attack often starts with a Telegram account the target already trusts. The hackers take over accounts belonging to cryptocurrency contacts and then send a Calendly invitation that redirects the victim to a lookalike meeting domain. JUMPSEC described the system as a repeatable victim pipeline, because one stolen Telegram session can be used to contact the next group of targets.

BlueNoroff scans wallets before malware delivery

When a user enters the fake meeting, the phishing page begins scanning the browser. It looks for Ethereum wallet connections through EIP-6963 and older browser methods, and it also checks for non-EVM wallets, including Solana tools. The results are sent to an operator panel without alerting the victim.

That process allows the attackers to identify wallets and select higher-value targets before moving to the next stage of the intrusion. On Windows, the implant also lists extension IDs across Chrome, Edge, Brave, Opera, Vivaldi, and Firefox variants. Operators can compare those IDs with known wallet extensions such as MetaMask.

JUMPSEC called the process a system that profiles wallets “before malware delivery.” The approach differs from broader phishing campaigns because attackers collect wallet information before deciding how far to escalate the compromise. It also means a user may be evaluated for wallet exposure before seeing the more obvious request to install an update or run a command.

Fake Zoom and Teams pages are used to build trust

Victims first encounter a convincing meeting page that asks for their name and webcam access. The site then sends the camera stream to the attacker’s control panel. After the victim joins, the screen displays a “waiting for other participants” message.

An operator can enter the fake meeting with a prepared video, send messages such as “your mic isn’t working,” and trigger a fake “Zoom SDK Update” prompt. JUMPSEC found that the participant video shown to the victim was not live. The attackers combined AI-generated headshots with body movements captured in earlier meetings, allowing them to show a familiar-looking person while using a Telegram account that belonged to a real contact.

The Teams version of the kit included emoji reactions, device settings, background effects, and broader wallet checks, making it more polished than the Zoom kit. The source code also contained an unfinished Google Meet option. JUMPSEC said Zoom and Teams are well suited to the lure because both products use desktop clients, making an urgent software update appear more plausible.

Malware paths target Windows and macOS

On Windows, the copied ClickFix command runs a small PowerShell loader. It downloads a VBScript, adds a Microsoft Defender exclusion, and restarts Defender so the change takes effect. The implant collects system details, checks browsers for wallet extensions, and searches for Telegram Web files.

The Windows implant can also receive later payloads from the operators, although JUMPSEC did not recover every final-stage file.

On macOS, the attack path downloads a fake Zoom or Teams installer while a stealer runs in the background. Researchers found versions that collected system information and Chrome master keys from Apple’s Keychain. The malware sent data through a Telegram bot and could download another payload.

JUMPSEC traced four macOS variants between April 22 and July 15, indicating that the operators continued changing the toolkit during the campaign.

Campaign extends earlier fake meeting scams targeting crypto

The findings expand earlier research into BlueNoroff’s fake meeting operations. In April, Arctic Wolf reported more than 80 lookalike Zoom and Teams domains and identified 100 additional targets whose media appeared on attacker infrastructure. Arctic Wolf said 80% of the identified targets worked in crypto, blockchain finance, or related investment sectors, while founders and chief executives accounted for 45%.

North Korean attackers had already used compromised Telegram accounts, spoofed meeting invitations, and fake software updates to target crypto executives. Another crypto.news report described a related macOS campaign that asked victims to run commands during fake calls. Earlier coverage of NimDoor malware also linked fake Zoom updates to attempts to steal browser credentials, wallet data, and Telegram files.

The latest kit gives operators direct control over the pace of each meeting and over when the malware prompt appears. JUMPSEC advised organizations to treat meeting links sent from trusted accounts with caution because the sender’s account may already be compromised.

Crypto teams can verify unusual invitations through another channel, avoid commands or updates presented during calls, revoke exposed Telegram sessions, and isolate any device that ran the requested script. Teams should also review PowerShell activity, Defender exclusions, Keychain access, and new Telegram logins after any suspicious call. A password reset alone may not remove stolen sessions or malware that is already running on affected systems.