The UK cyber security firm JUMPSEC has uncovered a sophisticated scheme operated by BlueNoroff, a North Korean-linked hacking group. The attackers screen crypto wallets before choosing victims and use fake Zoom and Microsoft Teams calls to set their schemes in motion.
BlueNoroff targets crypto wallet holders through tailored attacks
BlueNoroff, identified as a subgroup of North Korea’s notorious Lazarus Group, focuses on individuals who hold private keys to cryptocurrency wallets. JUMPSEC published an analysis of the hackers’ full source code this week after source maps were accidentally left accessible on a live server.
The exposed code details how the attack kit immediately scans a visitor’s browser when they enter the counterfeit meeting page. The kit searches for Ethereum wallet connections, including those based on the EIP-6963 standard and older browser methods.
The workflow also probes for non-Ethereum wallets such as Solana and sends the findings to a remote dashboard controlled by the attackers. Victims see no warning during the process. The malware maintains a list of browser extension IDs associated with popular wallets like MetaMask, allowing attackers to check for valuable targets before proceeding further.
Once a suitable wallet is detected, attackers decide whether to deploy a full exploit. Entry often begins with the takeover of a trusted contact’s Telegram account, which is then used to send plausible meeting invites via Calendly, leading new victims to the fake platform. The attack is designed to exploit trust within cryptocurrency networks, rapidly expanding the pool of victims.
Victims are greeted with requests for their names and webcam access once they join the call, handing the video stream to the hackers without their knowledge.
Mini dictionary: BlueNoroff, a hacking unit tied to North Korea’s Lazarus Group, is known for cyber-attacks targeting banks, cryptocurrency firms, and fintech organizations, with a track record of using advanced social engineering and malware payloads.
Following this, victims typically encounter a “waiting for other participants” screen, after which the attackers play a pre-recorded video message. Attackers exploit additional deception by presenting a message about the victim’s microphone not functioning, followed by a fake “Zoom SDK Update” prompt.
JUMPSEC’s investigation showed that attackers used AI-generated faces stitched onto body movements captured in earlier meetings to further legitimize the fake calls.
The meeting interfaces closely mimic legitimate Zoom and Teams layouts, with options such as emoji reactions and device settings. JUMPSEC also discovered an incomplete Google Meet clone within the attack kit’s codebase.
Dedicated malware for Windows and macOS platforms
BlueNoroff customizes its payloads for different operating systems. On Windows, once victims run the downloaded file, a PowerShell script executes a VBScript, which adds a permanent Microsoft Defender exclusion to evade detection. The malware then collects system details, identifies wallet extensions in web browsers, and harvests Telegram Web data. Security researchers have not recovered all possible payloads, as the loader is designed for additional downloads during the attack.
On macOS, the hackers distribute counterfeit Zoom or Teams installers, which run a hidden infostealer. This malware extracts system data and decrypts Chrome master keys stored in Apple’s Keychain, then transmits the information through Telegram. Multiple macOS versions of the attack have been observed since late April.
Both JUMPSEC and US-based cybersecurity provider Arctic Wolf have identified several versions of BlueNoroff’s phishing kits, finding five new versions shipped between May 31 and July 14. These kits are capable of full compromise in under five minutes. The growing sophistication in targeting and automation is evident from these rapid iterations.
| Operating System | Attack Method | Data Stolen |
|---|---|---|
| Windows | PowerShell/VBScript loader, fake updates | Wallet extensions, system info, Telegram files |
| macOS | Fake installers, hidden stealer | System data, Chrome master keys |
Attack scale and targets
Arctic Wolf’s research found more than 100 victims of BlueNoroff’s campaign across over 20 countries, with 41% located in the United States. Between April and mid-2026, at least 80 typosquatted meeting domains were registered. Approximately 80% of victims work in crypto or blockchain finance, and 45% are identified as founders or CEOs. The timing of phishing attempts was consistent with North Korean working hours, suggesting direct operational links.
Earlier investigations have highlighted BlueNoroff’s connections to broader Lazarus Group operations. Lazarus has previously targeted banks and crypto companies using tailored malware, such as fileless RemotePE trojans, typically deployed through Telegram contacts and fraudulent meeting links.
One victim described how their Telegram account was taken over and used to lure colleagues within the cryptocurrency sector into the same scheme.




