BlueNoroff Phishing Kit Checks Crypto Wallets Before Deploying Malware

A North Korea-linked threat group known as BlueNoroff is using a phishing platform that imitates Zoom and Microsoft Teams to profile cryptocurrency users before delivering malware, according to resear...

A North Korea-linked threat group known as BlueNoroff is using a phishing platform that imitates Zoom and Microsoft Teams to profile cryptocurrency users before delivering malware, according to research from JUMPSEC.

The campaign combines compromised Telegram accounts, trusted-contact impersonation and ClickFix-style social engineering. Attackers reportedly take over accounts belonging to people in the cryptocurrency sector and use them to contact executives or other high-value targets. Victims may receive a Calendly invitation that redirects to a domain designed to resemble a legitimate Zoom or Teams meeting link.

The counterfeit meeting site can request webcam access and relay the video to an operator-controlled panel through WebRTC. After the victim enters a staged meeting, the operator can display prompts claiming that the microphone is malfunctioning and instruct the target to install an urgent application or SDK update. That interaction ultimately delivers a malicious command.

JUMPSEC said the kit also fingerprints the browser and searches for cryptocurrency wallet extensions before the malware is deployed. This reconnaissance allows operators to prioritize targets who may control valuable digital assets. The fake meeting may include a prerecorded participant video, with AI-generated faces placed over real body movements captured from earlier victims, creating a more convincing impersonation.

Separate Windows and macOS attack chains

On Windows, the ClickFix command launches a PowerShell loader that retrieves a VBScript. The script attempts to weaken Microsoft Defender, checks browser data associated with Telegram, and inventories extensions across several Chromium- and Firefox-based browsers. Wallet extensions such as MetaMask can then be identified, while Telegram-related data may help attackers steal sessions and spread the campaign through additional contacts.

On macOS, a shell command downloads a counterfeit Zoom or Teams installer. The associated stealer collects system information and Chrome master keys stored through iCloud Keychain, then sends data to the attackers through Telegram and can install further payloads.

Researchers observed distinct Zoom and Teams versions, with the Teams implementation including more advanced wallet checks and additional meeting features. Infrastructure analysis identified five kit versions released between May 31 and July 14, 2026, suggesting continued development. The campaign’s emphasis on Zoom and Teams also supports the “outdated desktop client” pretext, which is less plausible for browser-first services such as Google Meet.