EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

North Korea BlueNoroff uses Zoom call hijacking to steal cryptocurrency wallets

2026-07-27 12:11:15
Bookmark

North Korean hacker group launches attack after screening crypto wallets

A North Korean hacker group screens crypto wallets before launching an attack. The gang lured victims with fake Zoom and Microsoft Teams calls. British security company JUMPSEC released relevant source code analysis this week. BlueNoroff's actions target users who hold private keys. Only one person needs to click on the error prompt to trigger an attack.


BlueNoroff chose to infect the target after screening the crypto wallet

JUMPSEC successfully obtained the real source code of the attack tool because its operator exposed the JavaScript source mapping to the online infrastructure. The files describe a workflow: Once a target enters a fake meeting page, the system immediately scans its browser. JUMPSEC found that the tool detects Ethereum connections based on the EIP-6963 standard, as well as traditional browser technology. It also detects non-EVM wallets such as Solana tools. Scan results are pushed directly to the operator panel. Victims during the call will not receive any prompts or warnings.

Malware on Windows computers contains a list of browser extension IDs covering Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. Hackers then used these IDs to match known wallet extensions, such as MetaMask. An attacker can check each wallet one by one to determine which ones are worth a complete breach, and then send payload to those targets. Bait is based on the victim's existing trust in others.

An attacker would take over the Telegram account of a cryptocurrency contact and send an invitation that appeared to be from Calendly pointing to a fake conference domain name. Each hijacked account leads to the contact's own cryptocurrency contacts, who in turn become the next target of attacks. Once the video call starts, the page asks for a name and access to the camera. The camera footage was then sent to the attacker's control panel in the background.

Victims will then see a "waiting for other participants to join" interface. The operator then played a pre-recorded video and said to the victim: "Your microphone cannot be used." After that, a forged "Zoom SDK update" message popped up. According to JUMPSEC, the faces in the call were not real people. The attacker spliced AI-generated head images onto body movements captured in previous meetings.

The fake Teams meeting page contains emoticons, device settings, background effects, and wallet scanning capabilities. JUMPSEC also found an unfinished Google Meet clone in the exposed code.


Each operating system has its own malicious payload

On Windows, the copied ClickFix command launches a small PowerShell loader that downloads VBScript scripts. The script then adds a Microsoft Defender exclusion and restarts Defender to make the changes take effect permanently. This payload collects system information and searches the browser for wallet extensions. It also searches Telegram Web files and is able to receive subsequent payloads-payloads that researchers have been unable to fully restore.

On macOS, hackers drop a fake Zoom or Teams installer while a secret theft program runs silently in the background. The program steals system data and the Chrome master key in Apple Keychain and sends it via Telegram. Security researchers found that four macOS versions appeared between April 22 and July 15. Arctic Wolf and JUMPSEC found five versions of the fishing kit, released between May 31 and July 14, and the full intrusion process was completed in five minutes.

Arctic Wolf research identified more than 100 victims in more than 20 countries, 41% of whom were located in the United States. In April, Arctic Wolf counted more than 80 misspelled conference domain names registered since the end of 2025. About 80% of the target people work in cryptocurrency or blockchain finance, and 45% of them are founders or CEOs. The attack time also corresponds to North Korea's working hours.

BlueNoroff is a subgroup of the Lazarus Group. There have been previous reports that Lazarus used the fileless RemotePE Trojan to attack banks and cryptocurrency companies, and used similar Telegram and fake schedule bait.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP