BlueNoroff phishing kit scans crypto wallets before deploying malware
Security & Exploits ยท
A North Korea-linked threat group is running a self-sustaining phishing operation that inventories victims' cryptocurrency wallets before delivering malware through fake Zoom meetings and hijacked Telegram accounts.
The activity, tied to the threat actor BlueNoroff, has been detailed in a report from JUMPSEC shared with The Hacker News, which describes the campaign as an "operator-driven victim acquisition platform" that chains together compromised contacts, social engineering, wallet reconnaissance and malware delivery into what it calls a repeatable pipeline. Attackers use hijacked Telegram accounts belonging to individuals already known to the target in the cryptocurrency space to message high-ranking employees at major companies and share a Calendly link, exploiting existing trust rather than cold outreach.
The Calendly link redirects to a typosquatted domain impersonating Zoom. Victims are asked to enter their name and grant webcam access; once permissions are given, the webcam stream is quietly routed to the operators' panel via mediasoup WebRTC. The victim is then shown a screen indicating they are alone in the meeting, "waiting for other participants," while the browser is fingerprinted to catalog which cryptocurrency wallets are installed. An "admin" subsequently joins the fake call, but the video shown to the victim is not live โ it is a pre-edited composite using AI-generated headshots made with OpenAI's ChatGPT, layered over body movements recorded from previous meetings, meaning each successful attack supplies material for the next one.
Once inside, operators can manipulate the fake meeting to send prompts such as a fabricated microphone error and trigger a "Zoom SDK Update," which ultimately delivers the ClickFix-style payload. JUMPSEC notes that any victim who runs that payload while Telegram Web is open or Telegram Desktop is installed becomes a candidate for their own Telegram session to be stolen and reused against their contacts, allowing the chain to propagate from one compromised account to the next.
The activity builds on ClickFix-style lures using typosquatted Zoom and Microsoft Teams domains that have been tracked since early 2025, with Sekoia separately following a related North Korea-aligned cluster it calls ClickFake Interview using similar camera-or-audio-issue pretexts. A related account of the campaign, corroborated via wublockchain.xyz, similarly describes BlueNoroff targeting crypto professionals through fake Zoom and Teams meetings to extract wallet keys and system data.
Not yet detailed is the scale of victims compromised through this specific kit, how many wallets or how much value may have been exposed, or whether platforms like Zoom, Calendly and Telegram have moved to disrupt the infrastructure involved.