VYPR
researchPublished Jul 24, 2026· 1 source

BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery

North Korean threat actors, BlueNoroff, are employing a sophisticated phishing kit to impersonate Zoom and Microsoft Teams, profiling cryptocurrency wallets before delivering malware.

North Korean state-sponsored threat actors, operating under the moniker BlueNoroff, have been observed deploying a sophisticated phishing kit designed to impersonate popular collaboration platforms like Zoom and Microsoft Teams. This campaign, tracked by cybersecurity firm JUMPSEC, represents a highly operationalized victim acquisition pipeline that leverages compromised industry contacts, social engineering, and advanced reconnaissance to target high-value victims, particularly those involved in the cryptocurrency space.

The attackers' methodology begins with the abuse of trust, utilizing compromised Telegram accounts belonging to individuals within the cryptocurrency sector. These accounts are then used to send messages to high-ranking employees of major companies, often including a Calendly meeting link. This initial vector is designed to appear legitimate, leveraging existing professional networks to bypass initial security awareness measures. The self-propagating nature of the attack is amplified as each compromised account is used to target further contacts, creating a cascading effect.

Upon clicking the Calendly link, victims are directed to a fake domain that meticulously mimics the legitimate Zoom or Microsoft Teams login page. Here, they are prompted to enter their name and grant webcam permissions. Unbeknownst to the victim, this grants attackers the ability to stream their webcam feed to a control panel via WebRTC. The attackers then join the fake meeting, presenting a pre-recorded, AI-generated video of a familiar-looking individual to maintain the illusion, while simultaneously triggering a "Zoom SDK Update" lure that delivers the primary payload.

A critical component of this attack chain is the reconnaissance performed on the victim's cryptocurrency wallets. Before or during the fake meeting, the kit fingerprints the victim's web browser to identify installed cryptocurrency wallet extensions, such as MetaMask. This profiling allows the threat actors to selectively target individuals with significant digital assets, maximizing their potential return on investment from each successful compromise.

The campaign's payloads are designed to be stealthy and effective on both Windows and macOS. On Windows, a PowerShell loader executes a VBScript implant that disables Microsoft Defender exclusions and searches for Telegram session cookies within browser profiles. This allows attackers to hijack active Telegram accounts, further expanding their reach. On macOS, a shell script downloads a fake Teams or Zoom installer, which contains the main stealer payload designed to exfiltrate system metadata, Google Chrome master keys, and other sensitive data via a hard-coded Telegram channel.

Further analysis of the infrastructure linked to this operation has revealed a Telegram operator known as "John" (@alchemy_john_mac), who has been observed discussing cryptocurrency vesting contracts and fund withdrawals. This attribution provides a potential link to the individuals orchestrating these sophisticated attacks.

The sophistication of this phishing kit, including its use of AI-generated video lures and its ability to profile cryptocurrency wallets, highlights the evolving tactics of North Korean threat actors. The campaign's design as an "operator-driven victim acquisition platform" underscores the increasing professionalization and efficiency of cybercrime operations, posing a significant threat to individuals and organizations, especially those holding digital assets.

Synthesized by Vypr AI