North Korea’s BlueNoroff Uses Fake Zoom and Teams Calls to Target Crypto Wallets
Key Takeaways
- •JUMPSEC recovered exposed source code showing BlueNoroff’s fake meeting pages scan browsers for cryptocurrency wallets before malware is delivered.
- •The phishing kit checks for Ethereum wallet connections, non-EVM wallets including Solana tools, and known browser wallet extensions such as MetaMask.
- •Attackers use hijacked Telegram accounts and fake Calendly invitations to direct targets to spoofed Zoom or Microsoft Teams meeting pages.
- •Windows payloads collect system and browser data, while macOS payloads use fake installers and steal Chrome master keys from Apple’s Keychain.
- •Arctic Wolf identified more than 100 victims in over 20 countries, with about 80% working in crypto or blockchain finance.

North Korean hacking group BlueNoroff is screening cryptocurrency wallets before deciding which victims to compromise, using fake Zoom and Microsoft Teams calls to deliver malware to people who hold private keys.
UK security firm JUMPSEC published a source-code analysis this week of the operation, which shows how the group’s phishing kit identifies crypto wallets, routes results to an operator panel, and uses social-engineering prompts to push malware onto selected targets. JUMPSEC’s analysis is available at
The campaign matters because browser wallets and messaging accounts often sit close to signing authority in crypto businesses. If an attacker can confirm that a target has wallet extensions or active wallet connections before delivering malware, the operation can reserve more intrusive payloads for people most likely to hold valuable access.
BlueNoroff scans wallets before selecting targets
JUMPSEC said it was able to recover the kit’s real source code after the operators left JavaScript source maps exposed on live infrastructure. The files detailed a workflow that begins scanning a target’s browser as soon as the person lands on the fake meeting page.
According to JUMPSEC, the kit searches for Ethereum wallet connections using the EIP-6963 standard as well as older browser-based techniques. It also probes for non-EVM wallets, including Solana tools. The results are sent directly to an operator dashboard without prompting or warning the person on the call.
On Windows machines, the malware includes a list of browser extension IDs for Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. The attackers use those IDs to check for known wallet extensions such as MetaMask.
That process allows operators to review detected wallets, decide which targets merit a full compromise, and send payloads only to those victims. The lure relies heavily on trust between crypto contacts, turning routine meeting invitations and familiar messaging accounts into part of the compromise chain.
The attackers first take over a crypto contact’s Telegram account, then send a convincing Calendly invitation to a fake meeting domain. Each hijacked account gives the operators access to more of that contact’s crypto network, creating the next group of targets.
When the fake video call begins, the page asks the victim to enter a name and allow webcam access. The camera feed is then sent silently to the attacker’s panel in the background.
The victim sees a screen stating that the call is “waiting for other participants.” The operator then plays a pre-recorded video and tells the victim, “Your mic isn’t working.” A fake “Zoom SDK Update” message appears afterward.
JUMPSEC said the face shown on the call is not real. The attackers stitch AI-generated headshots onto body movements captured during earlier meetings.
The fake Microsoft Teams meeting page includes emoji reactions, device settings, background effects, and wallet-scanning functions. JUMPSEC also found an unfinished Google Meet clone inside the exposed code.
Separate payloads target different operating systems
On Windows, the copied ClickFix command starts a small PowerShell loader that downloads a VBScript. The script then adds a Microsoft Defender exclusion and restarts Defender so the change remains in place.
The Windows payload collects system information, searches browsers for wallet extensions, and looks for Telegram Web files. It can also receive later-stage payloads, although researchers were not able to fully recover those components.
On macOS, the attackers drop a fake Zoom or Teams installer while a stealer runs silently in the background. The stealer collects system data and Chrome master keys from Apple’s Keychain, then sends the information through Telegram.
Security researchers identified four macOS versions dated from April 22 to July 15. Arctic Wolf and JUMPSEC found five phishing kit versions shipped between May 31 and July 14, with full compromise taking less than five minutes.
Arctic Wolf’s research identified more than 100 victims across more than 20 countries, including 41% in the United States. In April, Arctic Wolf counted more than 80 typosquatted meeting domains that had been registered since late 2025.
About 80% of the targets worked in crypto or blockchain finance, and 45% were founders or CEOs. The timing of the attacks also aligned with business hours in North Korea.
The exposed code and domain data give defenders concrete indicators to watch, including fake meeting infrastructure, unexpected wallet-enumeration behavior in browsers, and meeting pages that request updates outside official Zoom or Microsoft Teams channels.
BlueNoroff is a subgroup of the Lazarus Group. Cryptopolitan previously reported that Lazarus targeted banks and crypto firms with a fileless RemotePE trojan, using similar Telegram and fake-scheduler lures at https://www.cryptopolitan.com/north-korea-lazarus-target-crypto-banks/.