BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquatted Zoom and Microsoft Teams domains to deliver malware and steal cryptocurrency wallet information. The campaign employs AI-generated faces superimposed on real body movements to create a more convincing deception, and actively develops multiple versions of the kit, demonstrating ongoing refinement and targeting of specific industries.
North Korean threat actors, operating under the BlueNoroff campaign, are utilizing a complex phishing kit to target crypto investors and venture capitalists. The campaign leverages compromised trusted contacts – individuals met in real life – to spread social engineering attacks via Telegram, impersonating legitimate Zoom and Microsoft Teams domains. The initial lure involves a Calendly link that directs victims to a fake Zoom meeting page, where they are prompted to grant webcam permissions, allowing the attackers to steal video streams via WebRTC.
Following the meeting, the kit executes a fingerprinting step to inventory installed cryptocurrency wallets, using extensions like MetaMask, and then leverages a 'Zoom/Teams SDK out of date' pretext to trick users into updating their software, which ultimately delivers a ClickFix payload. Simultaneously, the campaign employs AI-generated faces superimposed over authentic body movements captured during previous meetings, creating a more convincing deception and making it harder to discern a fake meeting from a legitimate one.
The threat actors are actively developing multiple versions of the phishing kit, indicating ongoing refinement and a targeted approach. The campaign’s success is linked to the fact that Zoom and Teams are the default communication platforms for many crypto/venture capitalist/founders, while Google Meet is primarily used for customer calls. The entire domain scheme – such as ‘us.zoom.06webin.us’ – is designed to mimic real Zoom links, making it easier for victims to fall for the fake links.
Further analysis revealed that the Telegram exfiltration function hard-codes the bot token and chat ID within the stealer binary, and a recent investigation linked the bot token to an operator named "John" (@alchemy_john_mac), who was recently inquiring about vesting contracts and withdrawing funds from the MAIV cryptocurrency group. The campaign’s success highlights the importance of considering identity and relationships as part of an organization’s security posture, as threat actors increasingly recognize that compromising individuals can be as valuable as attacking infrastructure.
