Connect with us

Cybersecurity Alerts

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Published

on

Cybersecurity researchers have uncovered an advanced phishing campaign linked to the North Korean threat group BlueNoroff, revealing a sophisticated attack platform that impersonates Zoom and Microsoft Teams to identify high-value cryptocurrency users before delivering malware.

A new report from cybersecurity firm JUMPSEC shows that the operation combines trusted contact hijacking, fake video meetings, cryptocurrency wallet reconnaissance, and malware deployment into a highly targeted attack chain aimed at organizations and individuals in the digital asset sector.

Trusted Telegram Contacts Used to Lure Victims

Unlike traditional phishing campaigns, the attackers begin by compromising legitimate Telegram accounts belonging to individuals within the cryptocurrency industry.

Using these trusted accounts, the threat actors send meeting invitations—often through Calendly links—to executives and employees at cryptocurrency firms. Because the invitations come from familiar contacts, victims are far more likely to trust and open them.

Researchers say every successful compromise creates additional opportunities, as stolen Telegram sessions can be reused to target the victim’s own professional contacts, allowing the campaign to spread organically.

Fake Zoom Meetings Hide the Real Attack

Victims who click the invitation are redirected to counterfeit Zoom or Microsoft Teams websites hosted on carefully crafted typosquatted domains.

The phishing page requests the user’s name and permission to access their webcam, making the meeting appear legitimate. Once permission is granted, the victim’s webcam feed is secretly transmitted to the attackers through WebRTC technology.

After entering the meeting, users see what appears to be an empty conference room displaying a “waiting for other participants” message. This delay gives attackers time to prepare the next stage of the operation.

AI-Generated Participants Increase Credibility

JUMPSEC found that attackers use an operator control panel to manage fake meetings in real time.

The platform can display fabricated messages such as microphone or audio problems before prompting victims to install a fake “Zoom SDK Update” or similar software update that delivers the malware.

Researchers also discovered that the video participants shown during these fake meetings are not live. Instead, attackers use AI-generated faces layered onto recordings of real people captured during previous video calls, creating convincing digital identities that appear natural and familiar.

This approach allows every successful attack to provide new video material that can be reused in future phishing attempts.

Crypto Wallets Profiled Before Malware Delivery

One of the campaign’s most distinctive features is its ability to inspect a victim’s browser before deploying malware.

The phishing kit scans installed browser extensions to determine whether cryptocurrency wallets are present. Supported targets include wallets such as MetaMask and other popular browser-based crypto extensions.

By identifying valuable cryptocurrency holdings before launching the final payload, attackers can prioritize high-value victims while avoiding unnecessary exposure.

Different Attack Chains for Windows and macOS

Researchers identified separate infection methods depending on the victim’s operating system.

Windows attacks

On Windows devices, victims are tricked into running malicious PowerShell commands that:

  • Download additional malware components
  • Modify Microsoft Defender settings
  • Add folder exclusions to reduce detection
  • Search browser profiles for Telegram session data
  • Enumerate installed cryptocurrency wallet extensions
  • Prepare systems for additional malware deployment

macOS attacks

Mac users receive a fake Zoom or Microsoft Teams installer that deploys an information-stealing malware capable of collecting:

  • System information
  • Browser data
  • Google Chrome encryption keys
  • Additional sensitive credentials

The stolen information is reportedly transmitted to attackers through Telegram infrastructure before additional malware can be installed.

Campaign Shows Active Development

JUMPSEC identified five separate versions of the phishing platform released between late May and mid-July 2026, suggesting the attackers are actively improving the toolkit.

The Microsoft Teams version currently includes more advanced capabilities than the Zoom variant, featuring mobile device detection, emoji reactions, and enhanced cryptocurrency wallet discovery features.

Researchers also found references to a Google Meet version within the source code. However, it has not yet been implemented, likely because Zoom and Teams remain the preferred communication platforms among cryptocurrency companies, venture capital firms, and financial organizations.

Security Experts Urge Increased Vigilance

The report highlights a growing trend in cybercrime where attackers focus on trusted relationships and communication platforms instead of relying solely on software vulnerabilities.

Security experts recommend that organizations verify meeting invitations received through messaging platforms, avoid running commands or software updates requested during unexpected video calls, enable multi-factor authentication on communication accounts, and educate employees about sophisticated social engineering tactics targeting cryptocurrency businesses.

Researchers warn that as digital assets continue to grow in value, threat actors are increasingly targeting the people who manage access to those assets rather than attacking the underlying infrastructure directly.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO