
BlueNoroff scans browser wallets before launching fake Zoom meetings. JUMPSEC recovered the source code after operators left JavaScript maps exposed. Arctic Wolf found 100+ victims in 20+ countries.
A North Korean hacking crew screens crypto wallets before it strikes. The group tricks victims into fake Zoom and Microsoft Teams calls.
UK security firm JUMPSEC released the source code analysis this week. BlueNoroff's operation targets the people who hold private keys. It just needs one person to click the wrong prompt.
JUMPSEC retrieved the kit's true source code after operators left JavaScript source maps exposed on live infrastructure.
The files describe a workflow that scans a target's browser as soon as they land on the fake meeting page. JUMPSEC found the kit looks for Ethereum connections with the EIP-6963 standard and with legacy browser techniques.
It also probes for non-EVM wallets like Solana tools. The results are pushed directly to an operator dashboard. The person on the call never gets a prompt or warning.
The malware on Windows computers has a list of browser extension IDs for Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. Hackers use these IDs to check against known wallet extensions like MetaMask.
Attackers can check each wallet, decide which ones are worth a full break-in, then send payloads to those targets. The lure is based on the victim's existing trust in someone else.
Attackers take over a crypto contact's Telegram account and send a convincing Calendly invite to a fake meeting domain. Each hijacked account leads to that contact's own crypto contacts, who become the next round of targets.
As soon as the video call starts, the page asks for a name and webcam access. It sends the camera feed to the attacker's panel in the background.
Victims see a screen that says "waiting for other participants." The operator plays a pre-recorded video and tells the victim, "Your mic isn't working." A fake "Zoom SDK Update" message pops up.
The face on the call isn't real, according to JUMPSEC. Attackers stitch AI-generated headshots onto body movements captured in earlier meetings.
The fake Teams meeting page includes emoji reactions, device settings, background effects, and wallet scanning. JUMPSEC also found an incomplete Google Meet clone inside the exposed code.
On Windows, the copied ClickFix command launches a small PowerShell loader that downloads a VBScript. Then it adds a Microsoft Defender exclusion and restarts Defender to make the change permanent.
The payload collects system information and searches for wallet extensions in browsers. It also searches for Telegram Web files. And it can receive later payloads that researchers never quite recovered.
Hackers drop a fake Zoom or Teams installer on macOS while a stealer runs silently. It steals system data and Chrome master keys from Apple's Keychain and sends them via Telegram.
Security researchers found four macOS versions from April 22 to July 15. Arctic Wolf and JUMPSEC found five phishing kit versions shipped between May 31 and July 14, with full compromise in under five minutes.
Arctic Wolf's research identified more than 100 victims in over 20 countries, including 41% in the United States. In April, Arctic Wolf tallied more than 80 typosquatted meeting domains registered since late 2025.
About 80% of those targeted work in crypto or blockchain finance, and 45% are founders or CEOs. The timing of the attacks also corresponded with business hours in North Korea.
BlueNoroff is a subgroup of the Lazarus Group. Cryptopolitan reported earlier that Lazarus targeted banks and crypto firms with a fileless RemotePE trojan, using similar Telegram and fake-scheduler lures.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.