BlueNoroff targets crypto users through fake Zoom and Teams meetings

BlueNoroff targets crypto users through fake Zoom and Teams meetings

JUMPSEC says the North Korea-linked group uses hijacked Telegram accounts, silent wallet reconnaissance, AI-generated deception and tailored Windows and macOS malware to identify and compromise higher-value cryptocurrency targets.

Fact Check
The primary JUMPSEC report (Inside a DPRK BlueNoroff ClickFix Kit) confirms every element of the claim: BlueNoroff (DPRK Lazarus subgroup) profiles victims' cryptocurrency wallets via browser fingerprinting (EIP-6963, window.ethereum, Solana) before malware delivery; uses hijacked Telegram accounts of trusted contacts as the core delivery vector; deploys fake Zoom/Teams meeting pages; and has full Windows and macOS payload chains. Crypto.news and Cryptobriefing report the same details citing JUMPSEC, and Arctic Wolf independently corroborates the group's ClickFix/AI-Zoom Web3 campaign and attribution. The evidence is consistent across primary and independent sources.
Summary

BlueNoroff, a subgroup in the broader Lazarus Group ecosystem, is using fake Zoom and Microsoft Teams meetings to target cryptocurrency users, with JUMPSEC detailing how the operation silently profiles a victim’s wallet software before deciding whether to escalate to malware deployment. Researchers said the attackers hijack Telegram accounts belonging to real crypto professionals, send trusted contacts meeting invitations through counterfeit Calendly and video-call pages, and check for cryptocurrency wallet extensions such as MetaMask without alerting the target. The campaign then escalates through a fake video call workflow. After victims grant webcam access, operators can stream the live camera feed to a control panel while showing a waiting screen and AI-generated faces over authentic body movements captured from earlier victims. Victims are then told their microphone or camera is not working and prompted to install a fake Zoom SDK update, leading to malware tailored to Windows or macOS. JUMPSEC said the Windows chain downloads a VBScript payload that disables Microsoft Defender protections, searches for Telegram session data and inventories browser extensions for wallet software. On macOS, victims receive a fake Zoom or Teams installer that steals system information, browser credentials and Google Chrome encryption keys stored in iCloud Keychain, with exfiltration routed through a Telegram bot before additional malware can be deployed. Researchers identified five phishing-kit versions released between May 31 and July 14, 2026, said the Teams variant is more advanced than the Zoom version, and linked one Telegram bot to an operator using the handle “John” (@alchemy_john_mac). ZachXBT said on July 26 that similar North Korean social-engineering methods have been used for years and urged users to verify meeting requests before installing software.

Terms & Concepts
  • VBScript: A scripting language used on Windows that can be abused to run malicious code on a victim's device.
  • iCloud Keychain: Apple's password and credential storage system, which can hold sensitive browser encryption material on macOS.
  • private keys: Secret cryptographic credentials that give a holder control over a crypto wallet and its funds.