North Korean hacker group launches attack after screening crypto wallets
A North Korean hacker group screens crypto wallets before launching an attack. The gang lured victims with fake Zoom and Microsoft Teams calls. British security company JUMPSEC released relevant source code analysis this week. BlueNoroff's actions target users who hold private keys. Only one person needs to click on the error prompt to trigger an attack.
BlueNoroff chose to infect the target after screening the crypto wallet
JUMPSEC successfully obtained the real source code of the attack tool because its operator exposed the JavaScript source mapping to the online infrastructure. The files describe a workflow: Once a target enters a fake meeting page, the system immediately scans its browser. JUMPSEC found that the tool detects Ethereum connections based on the EIP-6963 standard, as well as traditional browser technology. It also detects non-EVM wallets such as Solana tools. Scan results are pushed directly to the operator panel. Victims during the call will not receive any prompts or warnings.
Malware on Windows computers contains a list of browser extension IDs covering Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. Hackers then used these IDs to match known wallet extensions, such as MetaMask. An attacker can check each wallet one by one to determine which ones are worth a complete breach, and then send payload to those targets. Bait is based on the victim's existing trust in others.
An attacker would take over the Telegram account of a cryptocurrency contact and send an invitation that appeared to be from Calendly pointing to a fake conference domain name. Each hijacked account leads to the contact's own cryptocurrency contacts, who in turn become the next target of attacks. Once the video call starts, the page asks for a name and access to the camera. The camera footage was then sent to the attacker's control panel in the background.
Victims will then see a "waiting for other participants to join" interface. The operator then played a pre-recorded video and said to the victim: "Your microphone cannot be used." After that, a forged "Zoom SDK update" message popped up. According to JUMPSEC, the faces in the call were not real people. The attacker spliced AI-generated head images onto body movements captured in previous meetings.
The fake Teams meeting page contains emoticons, device settings, background effects, and wallet scanning capabilities. JUMPSEC also found an unfinished Google Meet clone in the exposed code.
Each operating system has its own malicious payload
On Windows, the copied ClickFix command launches a small PowerShell loader that downloads VBScript scripts. The script then adds a Microsoft Defender exclusion and restarts Defender to make the changes take effect permanently. This payload collects system information and searches the browser for wallet extensions. It also searches Telegram Web files and is able to receive subsequent payloads-payloads that researchers have been unable to fully restore.
On macOS, hackers drop a fake Zoom or Teams installer while a secret theft program runs silently in the background. The program steals system data and the Chrome master key in Apple Keychain and sends it via Telegram. Security researchers found that four macOS versions appeared between April 22 and July 15. Arctic Wolf and JUMPSEC found five versions of the fishing kit, released between May 31 and July 14, and the full intrusion process was completed in five minutes.
Arctic Wolf research identified more than 100 victims in more than 20 countries, 41% of whom were located in the United States. In April, Arctic Wolf counted more than 80 misspelled conference domain names registered since the end of 2025. About 80% of the target people work in cryptocurrency or blockchain finance, and 45% of them are founders or CEOs. The attack time also corresponds to North Korea's working hours.
BlueNoroff is a subgroup of the Lazarus Group. There have been previous reports that Lazarus used the fileless RemotePE Trojan to attack banks and cryptocurrency companies, and used similar Telegram and fake schedule bait.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
SOL