
JUMPSEC says the North Korea-linked group uses hijacked Telegram accounts, silent wallet reconnaissance, AI-generated deception and tailored Windows and macOS malware to identify and compromise higher-value cryptocurrency targets.
BlueNoroff, a subgroup in the broader Lazarus Group ecosystem, is using fake Zoom and Microsoft Teams meetings to target cryptocurrency users, with JUMPSEC detailing how the operation silently profiles a victim’s wallet software before deciding whether to escalate to malware deployment. Researchers said the attackers hijack Telegram accounts belonging to real crypto professionals, send trusted contacts meeting invitations through counterfeit Calendly and video-call pages, and check for cryptocurrency wallet extensions such as MetaMask without alerting the target. The campaign then escalates through a fake video call workflow. After victims grant webcam access, operators can stream the live camera feed to a control panel while showing a waiting screen and AI-generated faces over authentic body movements captured from earlier victims. Victims are then told their microphone or camera is not working and prompted to install a fake Zoom SDK update, leading to malware tailored to Windows or macOS. JUMPSEC said the Windows chain downloads a VBScript payload that disables Microsoft Defender protections, searches for Telegram session data and inventories browser extensions for wallet software. On macOS, victims receive a fake Zoom or Teams installer that steals system information, browser credentials and Google Chrome encryption keys stored in iCloud Keychain, with exfiltration routed through a Telegram bot before additional malware can be deployed. Researchers identified five phishing-kit versions released between May 31 and July 14, 2026, said the Teams variant is more advanced than the Zoom version, and linked one Telegram bot to an operator using the handle “John” (@alchemy_john_mac). ZachXBT said on July 26 that similar North Korean social-engineering methods have been used for years and urged users to verify meeting requests before installing software.