{"id":35464,"date":"2026-07-26T05:05:41","date_gmt":"2026-07-26T05:05:41","guid":{"rendered":"https:\/\/bitunikey.com\/news\/north-korea-hackers-scan-crypto-wallets-through-fake-zoom-calls\/"},"modified":"2026-07-26T05:05:53","modified_gmt":"2026-07-26T05:05:53","slug":"north-korea-hackers-scan-crypto-wallets-through-fake-zoom-calls","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/north-korea-hackers-scan-crypto-wallets-through-fake-zoom-calls\/","title":{"rendered":"North Korea hackers scan crypto wallets through fake Zoom calls"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware.\u00a0<\/p>\n<div id=\"cn-block-summary-block_973e09fbc1521f1fe164d420b9039142\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>BlueNoroff scans browser wallets before deciding which fake meeting targets should receive its malware payload.<\/li>\n<li>Hijacked Telegram accounts help attackers contact trusted industry peers and extend the campaign through victims.<\/li>\n<li>The phishing kit supports Windows and macOS, stealing browser keys, system data, and Telegram sessions.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Cybersecurity firm <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.jumpsec.com\/guides\/inside-a-dprk-bluenoroff-clickfix-kit\/\" target=\"_blank\" rel=\"nofollow\">JUMPSEC<\/a> said it recovered and analysed source code from an active phishing kit after its operators exposed JavaScript source maps on live infrastructure. The files showed separate Zoom and Teams lures, wallet-scanning tools, operator controls and malware delivery paths for Windows and macOS.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Damn \u2013 the North Koreans can really put together effective campaigns to steal crypto currency \u2013 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/QRZ6UlAiCK\">https:\/\/t.co\/QRZ6UlAiCK<\/a> <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/Qxh1VAemCk\">pic.twitter.com\/Qxh1VAemCk<\/a><\/p>\n<p>\u2014 Tyson Benson (@tysonbenson) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/tysonbenson\/status\/2081046857019469862?ref_src=twsrc%5Etfw\">July 25, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The attack often begins through a Telegram account that the target already trusts. The hackers take over accounts belonging to crypto contacts, then send a Calendly invitation that leads to a lookalike meeting domain. JUMPSEC described the system as a repeatable victim pipeline because one stolen Telegram session can help the attackers contact the next group of targets.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>BlueNoroff checks crypto wallets before sending malware<\/strong><\/h2>\n<p>The phishing page starts scanning the browser when a user enters the fake meeting. It looks for Ethereum wallet connections through EIP-6963 and older browser methods. It also checks for non-EVM wallets, including Solana tools. The results reach an operator panel without alerting the victim. This lets the attackers identify wallets and choose higher-value targets before pushing the next stage.<\/p>\n<p>On Windows, the implant also lists extension IDs across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants. Operators can compare those IDs with known wallet extensions such as MetaMask. JUMPSEC called this a system that profiles wallets \u201cbefore malware delivery.\u201d The method differs from broad phishing campaigns because the attackers gather wallet data before deciding how far to take the intrusion.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Fake Zoom and Teams calls build trust<\/strong><\/h2>\n<p>Victims first see a convincing meeting page that requests their name and webcam access. The site then sends the camera stream to the attacker\u2019s control panel. After the victim joins, the screen shows \u201cwaiting for other participants.\u201d An operator can enter with a prepared video, send messages such as \u201cyour mic isn\u2019t working,\u201d and trigger a fake \u201cZoom SDK Update\u201d prompt.<\/p>\n<p>JUMPSEC found that the displayed participant video was not live. The attackers combined AI-generated headshots with body movements captured in earlier meetings. They could then show a familiar-looking person while using a Telegram account that belonged to a real contact. The Teams version included emoji reactions, device settings, background effects and wider wallet checks, making it more polished than the Zoom kit. The source code also contained an unfinished Google Meet option. JUMPSEC said Zoom and Teams suit the lure because both use desktop clients, making an urgent software update appear more credible.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Malware targets both Windows and macOS<\/strong><\/h2>\n<p>On Windows, the copied ClickFix command runs a small PowerShell loader. It downloads a VBScript, adds a Microsoft Defender exclusion and restarts Defender so the change takes effect. The implant gathers system details, checks browsers for wallet extensions and looks for Telegram Web files. It can also receive later payloads from the operators, although JUMPSEC did not recover every final-stage file.<\/p>\n<p>The macOS path downloads a fake Zoom or Teams installer while a stealer runs in the background. Researchers found versions that collected system information and Chrome master keys from Apple\u2019s Keychain. The malware sent data through a Telegram bot and could download another payload. JUMPSEC traced four macOS variants between April 22 and July 15, showing that the operators kept changing the toolkit during the campaign.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Campaign builds on earlier crypto meeting scams<\/strong><\/h2>\n<p>The findings expand earlier research into BlueNoroff\u2019s fake meeting operations. In April,<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arcticwolf.com\/resources\/blog\/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector\/\" target=\"_blank\" rel=\"nofollow\"> Arctic Wolf<\/a> reported more than 80 lookalike Zoom and Teams domains and identified 100 additional targets whose media appeared on attacker infrastructure. It said 80% of the identified targets worked in crypto, blockchain finance or related investment sectors, while founders and chief executives made up 45%.<\/p>\n<p>North Korean attackers had already used compromised Telegram accounts, spoofed meeting invitations and fake software updates to target crypto executives. Another crypto.news report described a related macOS campaign that asked victims to run commands during fake calls. Earlier coverage of NimDoor malware also linked fake Zoom updates to theft attempts against browser credentials, wallet data and Telegram files.<\/p>\n<p>The latest kit gives operators direct control over the pace of each meeting and the malware prompt. JUMPSEC advised organisations to treat meeting links from trusted accounts with care because the sender\u2019s account may already be compromised. Crypto teams can verify unusual invitations through another channel, avoid commands or updates presented during calls, revoke exposed Telegram sessions and isolate any device that ran the requested script. Teams should also review PowerShell activity, Defender exclusions, Keychain access and new Telegram logins after any suspect call. A password reset alone may not remove stolen sessions or malware already running on the device across affected systems.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korea-linked hacking group BlueNoroff is using fake Zoom and Microsoft Teams meetings to profile cryptocurrency users before delivering malware.\u00a0 Summary BlueNoroff scans browser wallets before deciding which fake meeting&hellip;<\/p>\n","protected":false},"author":1,"featured_media":34798,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35464","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=35464"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35464\/revisions"}],"predecessor-version":[{"id":35465,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35464\/revisions\/35465"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/34798"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=35464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=35464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=35464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}