BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat players behind ClickFix style campaigns that use professional Zoom and Microsoft Teams platforms have been found to be using a phishing kit to simulate video conferencing platforms in social engineering campaigns designed to deliver malware.
“BlueNoroff exploited trust abuse by combining vulnerable industry contacts, social engineering, wallet discovery and malware delivery into a repeatable victim discovery pipeline,” JUMPSEC said in a detailed report shared with The Hacker News.
Describing the campaign as a user-driven victim discovery platform, the cybersecurity firm noted that the operation involves using vulnerable contacts as the first access vector to create a chain of self-propagating attacks through Telegram.
The details of the operation are documented in detail from the beginning of 2025, when Sekoia tracked the second set of threats associated with North Korea under the moniker ClickFake Interview due to the use of traps such as ClickFix to trick unsuspecting targets into executing malicious commands under the pretext of dealing with camera or audio problems.
According to JUMPSEC, luring links are distributed to the target’s account that he already hopes and meets in real life, with attackers hijacking official Telegram accounts of people in the crypto-currency space to send a message to high-ranking employees of large companies and share a link to a Calendar meeting.
“Every victim carrying a payload with Telegram Web open or Telegram Desktop installed is a potential victim of their Telegram time to be stolen and re-used against their contacts,” JUMPSEC said, explaining the self-sustaining nature of the campaign and how the compromise of one account feeds the next.
The Calendly link takes the victim to what appears to be a Zoom meeting URL, but is, in fact, a fake domain masquerading as a videoconferencing service. Users who land on the phishing page are prompted to enter their name and give them permissions to access the webcam. However, once permissions are granted, the webcam stream is sent to the user panel via mediasoup WebRTC.
![]() |
| Operator panel, with many features |
In the final stage, after the victim joins the meeting, they are shown another page where they appear to be on a Zoom call alone, with the message “waiting for other participants.” This sets the stage for the next phase of the attack.
“Once the victim has joined, the operator can continue to use their panel to control the meeting, send fake ‘your microphone is not working’ messages, and trigger the ‘Zoom SDK Update,’ ultimately resulting in a ClickFix payment,” JUMPSEC said.
At the same time, the kit performs a fingerprinting step in the web browser to merge the cryptocurrency wallets installed in it, after which the “administrator” joins the fake meeting. What has changed here is that the video the victim sees is not a live stream, but a pre-edited video with AI-generated headshots created using OpenAI ChatGPT and recorded over authentic body movements captured during previous meetings.
“Therefore, each successful attack feeds a source of resources into a combination that is used against the next target,” explains JUMPSEC. “This combined with the method of taking over the Telegram account means that the fake meeting shows a very familiar face, which matches the body language of the person captured on camera.”
The cybersecurity company said it captured two different types of lures, one each for Zoom and Microsoft Teams. The Team variant is tested as more polished than the Zoom version, supporting emoji reactions, mobile/tablet blocking, and improved wallet investigation before malware is delivered.
ClickFix attack chains are compatible with both Windows and macOS. A brief description of each of them is as follows:
-
Windows kill chain:
- The ClickFix command uses a PowerShell loader that downloads and executes VBScript, disables Microsoft Defender, adds the “C:Users” folder to the exclusion path, and forcefully restarts Defender to apply the uninstall.
- The VBScript installation checks for the presence of Telegram Web-related files within Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox profile directories, which may determine whether the victim has an active Telegram account and may steal the account’s session cookies to control the account and use it to target other contacts.
- The implant lists extensions installed in all Chrome, Chrome Beta, Chrome Dev, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox, reports their corresponding extension IDs, and then compares them with known wallet extensions such as MetaMask to identify high value targets.
- The implant also supports the ability to deliver next-stage payloads, although its exact nature is unknown.
-
macOS kill chain:
- The ClickFix command uses a shell script, which then downloads the fake groups installer (or Zoom).
- The installer uses a stealth payload to extract and extract sensitive data, including system metadata and Google Chrome master keys from iCloud Keychain, to the attacker via a Telegram channel called “Aurora,” and extract additional payloads.
Further analysis determined that the Telegram extraction function hard-codes the bot token and chat ID within the stealing binary. Asking the Telegram API for a bot token connects it to an operator who goes by the name “John” (@alchemy_john_mac). As recently as May 2026, a person was seen asking the management of the MAIV cryptocurrency group about issuing contracts and withdrawing their funds.
In addition, threat actors’ infrastructure testing resulted in the discovery of five different types of phishing kits from May 31 to July 14, 2026, indicating effective development and remediation efforts.
A notable feature of the campaign is its exclusive focus on topics related to Zoom and Teams, as opposed to, say, Google Meet. Sean Moran, head of threat research and enablement at JUMPSEC, told The Hacker News that there are three possible reasons behind this behavior: ClickFix excuses, Target-application matching, and typosquatting surface –
“The whole hook is an ‘outdated Zoom/Teams SDK’ – which only lives on platforms the victims believe have a heavy desktop client (like Teams and Zoom do). But Google Meet doesn’t have a desktop app and starts in a browser, so it doesn’t make sense there.
Zoom and Teams are the default for many crypto/venture capitalists/founders in the financial world – and Google Meet feels like a platform to pitch to a customer rather than “call an investor/partnership.”
The entire domain name is ‘us.zoom.06webin.us’ and that makes it really easy for someone to fake their links because they are very similar to the real Zoom links and all subdomains, whereas ‘meet.google.com’ is much harder to copy/spoof.”
Moran also pointed out that while the phishing kit currently only ships Zoom and Teams landing pages, there is a Google Meet stub that isn’t used in the source code. This, he added, could be a deliberate choice of the factors listed above and the fact that the current set-up is working diligently.
“The implications go beyond this specific campaign. As Web3 and digital assets continue to mature, threat actors increasingly realize that compromising access control individuals can be just as valuable as attacking the infrastructure itself,” JUMPSEC concluded.
“BlueNoroff’s continued development shows that organizations must consider identity, relationships and communication channels as key components of their security posture.”




