LIVE NEWS
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
  • 25 Years After 9/11, What Makes a Good Counterterrorism Strategy?
  • Twenty-five years after 9/11, strategic shocks mustn’t cloud strategic thinking
  • Infectious diseases will seed new ground as the planet warms — here’s where they’ll spread
  • India crypto takedowns target 15 platforms
  • NFL’s Rams and 49ers head to Australia in international expansion
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Cybersecurity

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

primereportsBy primereportsJuly 24, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Share
Facebook Twitter LinkedIn Pinterest Email


BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.

“BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline,” JUMPSEC said in a detailed report shared with The Hacker News. “The platform profiles victims’ cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims.”

Describing the campaign as an operator-driven victim acquisition platform, the cybersecurity company noted that the activity involves using compromised trusted contacts as the initial access vector to create a self-propagating attack chain via Telegram.

Details of the activity have been documented in detail since early 2025, with Sekoia tracking a second related North Korea-aligned threat cluster under the moniker ClickFake Interview owing to the use of ClickFix-like lures to deceive unsuspecting targets into running malicious commands under the pretext of addressing camera or audio issues.

Cybersecurity

According to JUMPSEC, the lure links are distributed from an account the target already trusts and has met in real life, with the attackers hijacking legitimate Telegram accounts of individuals in the cryptocurrency space to message high-ranking employees of major companies and share a Calendly meeting link.

“Every victim who runs the payload with Telegram Web open or Telegram Desktop installed is a candidate for their Telegram session to be stolen and reused against their own contacts,” JUMPSEC said, describing the self-sustaining nature of the campaign and how one account compromise feeds the next.

The Calendly link takes the victim to what appears to be a Zoom meeting URL, but, in reality, is a fake domain impersonating the videoconferencing service. Users who land on the phishing page are prompted to enter their name and grant it permissions to access the webcam. However, once the permissions are provided, the webcam stream is stealthily sent to the operators’ panel via mediasoup WebRTC.

The operators panel, with multiple features

In the final stage, after the victim joins the meeting, they are shown another page where they seem to be in a Zoom call all by themselves, along with the message “waiting for other participants.” This sets the stage for the next phase of the attack.

“Once the victim has joined, the operator can then continue to use their panel in order to control the meeting, send fake ‘your mic isn’t working’ messages, and trigger the ‘Zoom SDK Update,’ ultimately resulting in the ClickFix payload,” JUMPSEC said.

Simultaneously, the kit executes a fingerprinting step on the web browser to inventory the cryptocurrency wallets installed on it, after which the “admin” joins the fake meeting. The twist here is that the video the victim sees isn’t a live stream, but rather a pre-edited video that features AI-generated headshots created using OpenAI ChatGPT and superimposed over authentic body movements captured during previous meetings.

“So, each successful attack feeds source material into the composites used against the next target,” JUMPSEC explained. “This combined with the Telegram account takeover method means that the fake meeting shows a plausibly familiar-looking face, moving with the body language of someone who was actually captured on camera.”

The cybersecurity company said it captured two distinct lure variants, each for Zoom and Microsoft Teams. The Teams variant is assessed to be more polished than the Zoom version, supporting emoji reaction, mobile/tablet blocking, and advanced wallet probes prior to malware delivery.

The ClickFix attack chains are compatible with both Windows and macOS. A brief description of each of them is as follows –

  • Windows kill chain:

    • The ClickFix command runs a PowerShell loader that downloads and executes a VBScript, disables Microsoft Defender, adds “C:\Users” folder to the exclusion path, and force-restarts Defender so that the exclusions are applied.
    • The VBScript implant checks for the presence of Telegram Web-related files within Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox profile directories, likely to determine if the victim has an active Telegram account and potentially hijack the account’s session cookies in order to take control of the account and use it to target other individuals of interest.
    • The implant enumerates installed extensions across Chrome, Chrome Beta, Chrome Dev, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox, reports their corresponding extension IDs, which are then matched against known wallet extensions like MetaMask to identify high-value targets.
    • The implant also supports the ability to deliver next-stage payloads, although their exact nature remains unknown.
  • macOS kill chain:

    • The ClickFix command runs a shell script, which then downloads a fake Teams (or Zoom) installer.
    • The installer runs the main stealer payload to extract and exfiltrate sensitive data, including system metadata and Google Chrome master keys from the iCloud Keychain, to the attacker via a Telegram channel named “Aurora,” and deploy additional payloads.

Further analysis has determined that the Telegram exfiltration function hard-codes the bot token and chat ID within the stealer binary. Querying the Telegram API for the bot token has linked it to an operator who goes by the name “John” (@alchemy_john_mac). As recently as May 2026, the individual has been observed asking admins of the MAIV cryptocurrency group about vesting contracts and withdrawing their funds.

On top of that, an examination of the threat actor infrastructure has led to the discovery of five distinct versions of the phishing kit from May 31 to July 14, 2026, indicating active development and fine-tuning efforts.

Cybersecurity

A notable aspect of the campaign is its specific focus on lures related to Zoom and Teams, as opposed to, say, Google Meet. Sean Moran, head of threat research and enablement at JUMPSEC, told The Hacker News that there are three possible reasons behind this behavior: ClickFix pretext, Target-application fits, and the typosquatting surface –

“The whole hook is the ‘Zoom/Teams SDK out of date’ – that only lands on platforms that victims believe have somewhat of a heavyweight desktop client (like Teams and Zoom have). But Google Meet doesn’t have a desktop application and is browser-first, so it doesn’t really make sense there.

Zoom and Teams are the default for a lot of crypto/venture capitalist/founders in the finance world – whereas Google Meet feels more of a customer calling platform rather than an “investor/partnership call.”

The entire domain scheme being ‘us.zoom.06webin.us’ and such makes it really easy for someone to fall for their fake links because they are so similar to real Zoom links with all the sub-domains, whereas ‘meet.google.com’ is harder to typosquat/spoof.”

Moran also pointed out that while the phishing kit currently only ships Zoom and Teams lure pages, there does exist a Google Meet equivalent as an unimplemented stub in the source code. This, he added, is likely a deliberate choice for the above-mentioned factors and the fact that the current set up is actively working.

“The implications extend beyond this specific campaign. As Web3 and digital assets continue to mature, threat actors are increasingly recognising that compromising the individuals who control access can be as valuable as attacking the infrastructure itself,” JUMPSEC concluded.

“BlueNoroff’s continued refinement demonstrates that organisations must consider identity, relationships and communication channels as critical parts of their security posture.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleShortsighted stock market can no longer brush off war, investors say
Next Article The Death of Slow Payments: How Blockchain Is Rewriting Finance
primereports
  • Website

Related Posts

Cybersecurity

Microsoft says September updates fix mouse settings reset issues

September 10, 2026
Cybersecurity

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

September 9, 2026
Cybersecurity

Microsoft Plugs Nearly 1,000 Security Holes – Krebs on Security

September 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026116 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

An $18bn settlement – and Zuckerberg barely blinked. The tech titans must be stripped of their power, and soon | Jonathan Freedland

August 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Crypto
  • Cybersecurity
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.