BlueNoroff scans cryptocurrency wallets in fake Zoom calls before dropping malware


A North Korean hacking crew scans cryptocurrency wallets before striking them. The group tricks victims into making fake calls via Zoom and Microsoft Teams.

British security firm JUMPSEC released an analysis of the source code this week. Operation BlueNoroff targets people with private keys. It only takes one person to click on the wrong claim.

BlueNoroff vets cryptocurrency wallets before choosing who to hit

JUMPSEC was able to recover the group’s real source code after its operators left JavaScript source maps exposed on the live infrastructure.

The files describe a workflow that scans the target’s browser once they reach the fake meeting page. JUMPSEC finds the group searching for them Ethereum EIP-6963 connections and legacy browser technologies.

He also looks for non-EVM wallets like Solana tools. Results are pushed directly to the operator’s dashboard. The calling person never receives any alert or warning.

The malware on Windows computers contains a list of browser extension IDs for Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. Hackers then use these IDs to verify known wallet extensions such as MetaMask.

Attackers can verify each wallet, determine which ones are worthy of full compromise, and then send payloads to those targets. The lure is based on the victim’s existing trust in another person.

Attackers take over an encrypted contact’s Telegram account and send a disguised Calendly invitation to a fake meeting domain. Each hijacked account leads to that contact’s encrypted contacts, which become the next round of targets.

Once the video call starts, the page asks for your name and webcam access. It then sends the camera feed to the attacker’s panel in the background.

BlueNoroff scans cryptocurrency wallets in fake Zoom calls before dropping malware.
A screenshot from a victim saying his Telegram account was hacked. source: jambsic.

Victims then see a screen that says “Waiting for other participants.” The operator then plays a pre-recorded video and says to the victim: “Your microphone isn’t working.” After that, a fake message titled “Zoom SDK Update” will appear.

The face on the call is not real, according to JUMPSEC. Attackers stitch AI-generated headshots over body movements captured in previous meetings.

The fake Teams meeting page includes emoji interactions, device settings, background effects, and wallet scanning. JUMPSEC also found an incomplete version of Google Meet inside the exposed code.

Every operating system has its own specific malware payloads

On Windows, the copied ClickFix command launches a small PowerShell loader that downloads VBScript. Then Microsoft Defender exclusion adds and restarts Defender to make the change permanent.

The payload collects system information and searches for wallet extensions in browsers. It also searches for Telegram Web files. It could receive later payloads that researchers were unable to completely recover.

Hackers drop fake Zoom or Teams installer on macOS while silently running the stealer. It steals system data and Chrome master keys from Apple Keychain and sends them via Telegram.

Security researchers found four macOS releases from April 22 to July 15: Arctic Wolf and JUMPSEC Found Five versions of the phishing kit were shipped between May 31 and July 14, with full penetration in less than five minutes.

Arctic Wolf’s research identified more than 100 victims in more than 20 countries, including 41% in the United States. In April, Arctic Wolf counted more than 80 meeting ranges that had been registered since late 2025.

About 80% of these targets work in cryptocurrency or blockchain finance, and 45% are founders or CEOs. The timing of the attacks also coincided with North Korea’s business hours.

BlueNoroff is a subset of the Lazarus group. Cryptopolitan I mentioned Earlier, Lazarus targeted banks and cryptocurrency companies with the fileless RemotePE Trojan, using similar Telegram and fake scheduling lures.

Don’t just read cryptocurrency news. Understand that. Subscribe to our newsletter. It’s free.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *