North Korea-Linked BlueNoroff Uses Fake Zoom and Teams Calls to Profile Crypto Wallets
Key Takeaways
- •JUMPSEC recovered source code showing BlueNoroff’s phishing kit can detect wallet software before operators deliver malware.
- •The campaign often begins with a meeting invitation sent from a compromised Telegram account belonging to a trusted industry contact.
- •The fake meeting pages check for browser wallets using methods including EIP-6963, window.ethereum and Solana-related integrations.
- •Researchers found more than 950 files on attacker infrastructure, including media tied to at least 100 targets, most of them in crypto-related sectors.
- •The malware affects both Windows and macOS and targets browser extensions, credentials, Apple Keychain data and Telegram session files.

North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to identify cryptocurrency wallets before deciding which targets should receive malware.
JUMPSEC said it recovered the source code for an active phishing kit after the operators left JavaScript source maps exposed on live infrastructure. The recovered files showed an operator-controlled system that combines hijacked Telegram accounts, fake meeting pages, wallet reconnaissance and malware delivery. That design lets operators confirm whether a visitor has wallet software installed before escalating from social engineering to malware execution.
The campaign typically starts when a compromised Telegram account belonging to a real industry contact sends a meeting invitation. The victim is directed to a typosquatted Zoom or Teams page, enters a name and grants webcam access. That access allows the site to transmit the live camera feed to the attacker’s control panel.
At the same time, the page silently checks for browser wallets using EIP-6963, window.ethereum and non-EVM integrations such as Solana. Detected extensions and wallet providers are sent to the operator before the victim is shown a fake Zoom software development kit update. EIP-6963 is used by Ethereum wallets to announce themselves to web applications, making it useful for legitimate wallet discovery as well as hostile reconnaissance when abused on phishing pages.
AI Faces and Stolen Sessions Extend the Campaign
Arctic Wolf previously found that the group used synthetic faces generated through ChatGPT’s GPT-4o image model and placed them over recorded human body movements. The videos were assembled using Adobe Premiere Pro and FFmpeg to create meeting participants who appear to nod, smile and gesture during calls.
Researchers identified more than 950 files on attacker-controlled infrastructure, including media connected to at least 100 targets. About 80% of those targets worked in crypto, blockchain finance or related investment sectors, while founders and chief executives made up 45%.
Compromised devices can also expose Telegram Web or desktop sessions. Those accounts are then reused to contact people who already know and trust the victim, allowing the same attack to spread through existing professional relationships. For crypto teams, that abuse of trusted contacts is especially sensitive because hiring, fundraising, partnerships and over-the-counter deal discussions often begin in private messaging channels before moving to video calls.
The technique builds on daily fake Zoom and Teams attempts targeting crypto professionals, in which stolen accounts, familiar meeting participants and fake connection fixes were used to distribute wallet-stealing malware.
Malware Targets Windows and macOS
The Windows attack chain uses a PowerShell loader to download a VBScript implant, add a Microsoft Defender exclusion and restart Defender before delivering later payloads. The malware inventories browser extensions across Chrome, Edge, Brave, Firefox and other browsers to identify wallets such as MetaMask.
The macOS version downloads a decoy Zoom or Teams application while running a separate binary in the background. Recovered commands targeted browser credentials, Apple Keychain data and Telegram session files. The cross-platform tooling shows the campaign is not limited to one operating system commonly used by crypto workers.
North Korean access campaigns have also reached crypto companies through employment channels, including a DPRK-linked contractor removed from MetaMask after gaining code access.
JUMPSEC expanded the latest infrastructure cluster to more than 60 hostnames across 10 IP addresses, with high- and medium-confidence systems still active on July 24.