North Korea’s BlueNoroff hacking group is now using fake Zoom and Microsoft Teams invites to profile crypto users. They scan wallet extensions in victims’ browsers before deploying malware.
Cybersecurity firm JUMPSEC uncovered the source code of this phishing kit after threat actors accidentally exposed JavaScript source maps on active infrastructure. The findings revealed that attacks often originate from trusted Telegram accounts. Hackers hijack accounts belonging to crypto contacts, then send Calendly invitations directing targets to fake meeting domains.
Once targets land on the spoofed meeting page, the system immediately scans the browser for Ethereum wallet connections using the EIP-6963 standard and legacy methods, as well as non-EVM wallets including Solana. The scan results are sent directly to the attacker’s operator panel without the victim’s knowledge.
Why Scout Wallet Contents First
From the panel, operators can identify high-value wallets before proceeding with the exploit. On Windows, they enumerate extension IDs across Chrome, Edge, Brave, Opera, Vivaldi, and Firefox, matching them against popular extensions like MetaMask. JUMPSEC noted that profiling wallets prior to malware delivery marks a sharp departure from typical mass phishing campaigns.
The victim’s screen displays a convincing page requesting their name and webcam access, while the video stream is fed into the attacker’s panel. When the victim joins, the screen switches to a waiting room prompt. The operator then joins with pre-recorded video, points out the victim’s muted microphone, and triggers a fake Zoom SDK update prompt.
The counterpart’s video is not a live feed, but an AI-generated face mapped onto body movements from another meeting. The fake Teams version is even more sophisticated, featuring emoji reactions, device settings, background effects, and broader wallet checks. Within the same codebase, JUMPSEC also identified an unfinished Google Meet module.
A Single Fatal Click
If the victim clicks the update button on Windows, a ClickFix command executes a PowerShell loader, downloads a VBScript, manipulates Microsoft Defender exclusions, and restarts the antivirus. On macOS, the system downloads a fake installer while an info-stealer runs in the background to exfiltrate system information and Chrome master keys from Apple Keychain.
JUMPSEC identified four macOS variants between April 22 and July 15, showing that operators actively maintain and update their toolset. Arctic Wolf data from last April revealed over 80 fake domains aimed at 100 targets. Approximately 80% of those targeted work in crypto, blockchain, and related investment sectors, with 45% holding founder or CEO positions.
For those operating in the industry, make it a habit to verify suspicious meeting invitations through secondary channels. Never follow in-call device update prompts, and revoke exposed Telegram sessions immediately. Hackers are no longer casting wide nets blindly; they check the size of your wallet before casting their line.
Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




