North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to identify cryptocurrency wallets before choosing which victims receive malware.
JUMPSEC recovered the source code behind an active phishing kit after its operators left JavaScript source maps exposed on live infrastructure. The files revealed an operator-controlled system combining hijacked Telegram accounts, fake meeting pages, wallet reconnaissance and malware delivery.
The campaign begins when a compromised Telegram account belonging to a genuine industry contact sends a meeting invitation. The victim lands on a typosquatted Zoom or Teams page, enters a name and grants webcam access, allowing the site to send the live camera feed to the attacker’s control panel.
The page silently searches for browser wallets through EIP-6963, window.ethereum and non-EVM integrations such as Solana. Detected extensions and wallet providers are transmitted to the operator before a fake Zoom software development kit update is displayed.
AI Faces And Stolen Sessions Extend The Campaign
Arctic Wolf previously found that the group used synthetic faces generated through ChatGPT’s GPT-4o image model and placed them over recorded human body movements. The videos were assembled with Adobe Premiere Pro and FFmpeg to create meeting participants who nod, smile and gesture during the call.
Researchers identified more than 950 files on attacker-controlled infrastructure, including media tied to at least 100 targets. About 80% worked in crypto, blockchain finance or related investment sectors, while founders and chief executives accounted for 45%.
Compromised devices can also expose Telegram Web or desktop sessions. Those accounts are then reused to contact people who already know and trust the victim, extending the same attack through existing professional relationships.
The method builds on daily fake Zoom and Teams attempts targeting crypto professionals, where stolen accounts, familiar meeting participants and fake connection fixes were used to distribute wallet-stealing malware.
Malware Targets Windows And macOS
The Windows attack chain uses a PowerShell loader to download a VBScript implant, add a Microsoft Defender exclusion and restart Defender before delivering later payloads. The malware inventories browser extensions across Chrome, Edge, Brave, Firefox and other browsers to identify wallets such as MetaMask.
The macOS version downloads a decoy Zoom or Teams application while running a separate binary in the background. Recovered commands targeted browser credentials, Apple Keychain data and Telegram session files.
North Korean access campaigns have also reached crypto companies through employment channels, including a DPRK-linked contractor removed from MetaMask after gaining code access.
JUMPSEC expanded the latest infrastructure cluster to more than 60 hostnames across 10 IP addresses, with high- and medium-confidence systems still active on July 24.



Be the first to comment