HackMyIP
← Back to News
2026-07-24 The Hacker News

BlueNoroff Phishing Kit Probes Crypto Wallets Before Zoom Malware Attack

APTPhishingMalware

The North Korean threat actor BlueNoroff has operationalized a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, according to new research from JUMPSEC. The kit, which uses typosquatted Zoom and Microsoft Teams domains, functions as a self-propagating victim acquisition pipeline that blends compromised industry contacts, social engineering, wallet reconnaissance, and payload execution. By inventorying installed wallet extensions on the victim's browser prior to infection, the operators can selectively prioritize high-value targets with confirmed crypto holdings.

The attack chain begins with hijacked Telegram accounts belonging to individuals in the cryptocurrency space. Attackers message high-ranking employees at major companies from these trusted contacts, sharing a Calendly link that redirects to a fake Zoom domain impersonating the videoconferencing service. Once users grant webcam and microphone permissions, the streams are exfiltrated in real time to the operators' panel via mediasoup WebRTC. Victims are then shown a plausible Zoom interface with a "waiting for other participants" message, after which the operator triggers a fake "Zoom SDK Update" prompt that executes the ClickFix-style payload. Defenders can validate suspicious meeting domains using a SSL/TLS checker and a WHOIS lookup to confirm impersonation before staff engage with any link.

JUMPSEC researchers warn that the campaign is uniquely self-sustaining: any victim running the payload with Telegram Web open or Telegram Desktop installed risks having their session stolen and weaponized against their own contacts, creating a chain of account compromises that feeds the next wave of targeting. Sekoia has tracked a related North Korea-aligned cluster known as ClickFake Interview, which uses similar lures disguised as camera or audio troubleshooting prompts. Given the browser-based wallet fingerprinting step that precedes payload delivery, crypto-sector employees are advised to run a browser fingerprint test to audit what their browser reveals about installed extensions and device characteristics, and to verify any unexpected meeting invitations through a separate, trusted channel before clicking.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →