A North Korean hacking crew screens crypto wallets before it strikes. The group tricks victims into fake Zoom and Microsoft Teams calls.
UK security firm JUMPSEC released the source code analysis this week. BlueNoroff’s operation targets the people who hold private keys. It just needs one person to click the wrong prompt.
JUMPSEC was able to retrieve the kit’s true source code after its operators left JavaScript source maps exposed on live infrastructure.
The files describe a workflow that scans a target’s browser as soon as they land on the fake meeting page. JUMPSEC found that the kit looks for Ethereum connections with the EIP-6963 standard and with legacy browser techniques.
It also probes for non-EVM wallets like Solana tools. The results are pushed directly to an operator dashboard. And the person on the call never gets a prompt or warning.
The malware on Windows computers has a list of browser extension IDs for Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. Hackers then use these IDs to check against known wallet extensions like MetaMask.
Attackers can check each wallet, decide which ones are worth a full break-in, and then send payloads to those targets. The lure is based on the victim’s existing trust in someone else.
Attackers take over a crypto contact’s Telegram account and send a convincing Calendly invite to a fake meeting domain. Each hijacked account leads to that contact’s own crypto contacts, who become the next round of targets.
As soon as the video call starts, the page asks for a name and webcam access. It then sends the camera feed to the attacker’s panel in the background.

Victims then see a screen that says “waiting for other participants.” Then the operator plays a pre-recorded video and says to the victim, “Your mic isn’t working.” After that, a fake “Zoom SDK Update” message pops up.
The face on the call isn’t real, according to JUMPSEC. Attackers stitch AI-generated headshots onto body movements captured in earlier meetings.
The fake Teams meeting page includes emoji reactions, device settings, background effects, and wallet scanning. JUMPSEC also found an incomplete Google Meet clone inside the exposed code.
On Windows, the copied ClickFix command launches a small PowerShell loader that downloads a VBScript. Then it adds a Microsoft Defender exclusion and restarts Defender to make the change permanent.
The payload collects system information and searches for wallet extensions in browsers. It also searches for Telegram Web files. And it can receive later payloads that researchers never quite recovered.
Hackers drop a fake Zoom or Teams installer on macOS while a stealer runs silently. It steals system data and Chrome master keys from Apple’s Keychain and sends them via Telegram.
Security researchers found four macOS versions from April 22 to July 15. Arctic Wolf and JUMPSEC found five phishing kit versions shipped between May 31 and July 14, with full compromise in under five minutes.
Arctic Wolf’s research identified more than 100 victims in over 20 countries, including 41% in the United States. In April, Arctic Wolf tallied more than 80 typosquatted meeting domains registered since late 2025.
About 80% of those targeted work in crypto or blockchain finance, and 45% are founders or CEOs. The timing of the attacks also corresponded with business hours in North Korea.
BlueNoroff is a subgroup of the Lazarus Group. Cryptopolitan reported earlier that Lazarus targeted banks and crypto firms with a fileless RemotePE trojan, using similar Telegram and fake-scheduler lures.
If you’re reading this, you’re already ahead. Stay there with our newsletter.