North Korea’s BlueNoroff Uses Fake Zoom Calls to Steal Crypto Wallets

1 hour ago 3 sources negative

Key takeaways:

  • Precision-phishing of crypto founders escalates systemic risk of protocol fund drains, potentially destabilizing linked DeFi tokens.
  • Ethereum and Solana wallet scans suggest these ecosystems face the highest immediate theft threat, likely amplifying short-term price volatility.
  • Investors should monitor sudden large transfers from known project wallets, as compromised keys could trigger forced liquidations.

A sophisticated social‑engineering campaign by the North Korea‑linked BlueNoroff group (a sub‑group of Lazarus) is targeting cryptocurrency professionals through weaponized Zoom and Microsoft Teams meeting invitations. Cybersecurity firm JUMPSEC reverse‑engineered the active phishing kit after its operators accidentally exposed JavaScript source maps on live infrastructure, revealing a multi‑stage attack that profiles victims’ browser wallets before delivering malware on Windows and macOS.

How the attack works
The campaign typically starts with a hijacked Telegram account belonging to a trusted crypto contact. The attacker sends a Calendly link that redirects to a lookalike meeting domain. When the victim joins the fake call, the site immediately scans the browser for Ethereum wallet connections (via EIP‑6963 and older methods) and also checks for non‑EVM wallets such as Solana tools. The scan results are sent silently to an operator panel, allowing the attackers to identify high‑value targets and decide whether to proceed with the malware stage.

To build trust, the phishing page requests camera access and streams the video to the attacker’s control panel. The victim sees a “waiting for other participants” screen, while an operator can join with a pre‑recorded video that often combines AI‑generated headshots with body movements captured in earlier meetings. The attacker may then message “your mic isn’t working” and trigger a fake “Zoom SDK Update” prompt. The Teams version is even more polished, including emoji reactions, device settings, and background effects.

Malware payload and dual‑platform threat
On Windows, a ClickFix command runs a PowerShell loader that downloads a VBScript, adds a Microsoft Defender exclusion, and restarts Defender. The implant harvests system details, checks browser extensions (Chrome, Edge, Brave, Opera, Vivaldi, Firefox) for known wallet extensions like MetaMask, and extracts Telegram Web session data. It can also receive additional payloads from operators.

On macOS, the victim downloads a fake Zoom or Teams installer while a stealer runs in the background. JUMPSEC identified four macOS variants between April 22 and July 15, the latest versions collecting system information and Chrome master keys from Apple’s Keychain. The data is exfiltrated via a Telegram bot.

The attack chain gives operators direct control over the timing of the malware prompt, making it far more targeted than typical broad phishing campaigns.

Wider implications
Earlier this year, Arctic Wolf reported over 80 lookalike Zoom and Teams domains and identified 100 additional targets, with 80 % working in crypto, blockchain finance or related investment sectors and 45 % being founders or CEOs. The shift toward precision‑targeting individuals – especially developers, traders, and founders who hold keys or influence treasury decisions – raises the stakes significantly. A single compromised wallet could expose not just personal holdings but also protocol funds or multisig signer keys.

JUMPSEC advises crypto teams to verify any unsolicited meeting invitation through a separate channel, avoid running commands or “updates” presented during a call, revoke exposed Telegram sessions immediately, and thoroughly check affected devices for PowerShell activity, Defender exclusions, Keychain access, and new Telegram logins.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.